MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d4515ab24efe2786b010dba452a7ea5075b52b7e6dec98ceea3f674ecc0f5aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6d4515ab24efe2786b010dba452a7ea5075b52b7e6dec98ceea3f674ecc0f5aa
SHA3-384 hash: 6ee6455e2d91c565bdb8786bf45fe58d699ef13a016222a99915fd320d9e1ffdc2ad23d0b9a0cf73914f632f572dd1f9
SHA1 hash: e8d1e217fc55886a809d7a1844f47b23b5d0caf4
MD5 hash: 642d2d3e83dd01b550c58ba35bc8effa
humanhash: sink-jersey-shade-romeo
File name:P.O8989.z
Download: download sample
Signature AveMariaRAT
File size:389'033 bytes
First seen:2020-05-18 07:52:44 UTC
Last seen:2020-05-18 07:55:46 UTC
File type: z
MIME type:application/x-rar
ssdeep 6144:rtNd57pStktqJwUzSUHW/XARYewDxl4H4ZDk8FgnKqUPcqQt0B/c/JiP0:nqC6jSUHUTp+H4ZDZmUPd/c/Ji8
TLSH 308423E6C40C7A6A12EA08F819EF40C4137179366CEA57C14D5E44DCEFEFAAE6F85850
Reporter abuse_ch
Tags:AveMariaRAT RAT z


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: web.naijhaspeaks.com
Sending IP: 46.166.176.236
From: Jayshree FLOTECH <customerservice@web.naijhaspeaks.com>
Subject: RE: Delayed Order
Attachment: P.O8989.z (contains "Puchase order.xlsx.exe")

AveMariaRAT payload URL:
http://45.95.168.62/upnp.exe

AveMariaRAT C2:
dimitriv.duckdns.org:1738 (209.58.144.239)

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-18 23:02:00 UTC
File Type:
Binary (Archive)
Extracted files:
16
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

z 6d4515ab24efe2786b010dba452a7ea5075b52b7e6dec98ceea3f674ecc0f5aa

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments