MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f3d1c917468f3dab1db9c697a29ad894c34e0f43c2f31cfaf745abe1ed0cb62. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6f3d1c917468f3dab1db9c697a29ad894c34e0f43c2f31cfaf745abe1ed0cb62
SHA3-384 hash: ccc768a117d8c2f018cbc751488f94de16db5ab80f43f0c3f608c45de93d4da7d91a2d52bc5111b2a97d5bdc4d8fe49c
SHA1 hash: c53728c27dde492942ed02b9c46cc5bfe5928ee0
MD5 hash: bc26f990c197ba8b8d8c90d7977153d5
humanhash: vegan-uranus-maine-hamper
File name:Scan22520.rar
Download: download sample
Signature AveMariaRAT
File size:141'830 bytes
First seen:2020-05-27 05:05:18 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:Bb+tpUfSAnwuuNWWlJPW/m8m7rL+XrHnhMdmYLjzspD9xcSO4i:lpfRwuu0WlJ9R7raXrHnW4s8pBxcSdi
TLSH 56D322324CC615D59BCA348E635BD751430C8F8B8EF3DEB4BB6A1D98DE81C051D6A90E
Reporter jarumlus
Tags:AveMariaRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-26 23:42:39 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
13 of 48 (27.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

rar 6f3d1c917468f3dab1db9c697a29ad894c34e0f43c2f31cfaf745abe1ed0cb62

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments