MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 801b4609436a3aef2dcda639a6bc9d09f23bb30f9b659d7d671f1a2f377c7719. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: 801b4609436a3aef2dcda639a6bc9d09f23bb30f9b659d7d671f1a2f377c7719
SHA3-384 hash: 7f9add6acba245cb07852658484dd39f627d3d47acbf02c53d488cdd5eef603f8d2dcd53312483a9cd511898a14fa240
SHA1 hash: 16b3d699e584a456ac934f0bed9ffc93974dd0a1
MD5 hash: b5a7644b4d5ddd73c82897c9aaf273a3
humanhash: cola-washington-johnny-item
File name:LONESTAREXHIBIT PO No. 23455.IMG
Download: download sample
Signature AveMariaRAT
File size:1'245'184 bytes
First seen:2023-03-10 08:59:45 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 3072:YeuTdDOgYy1I0Wr/GOtg1LMz0Fzs+4MHyuxWoL9bWg4B7KQEWnnBQt3ol9EKJ3Fw:/wHrq0Wr/vtg6ze4J0zYgRHgF1gPP
TLSH T18045CF1A5AD245A5C4A8CE30FBF851ED46F4A31F6562ABE7309C43F9CF1274A68021F7
TrID 99.4% (.NULL) null bytes (2048000/1)
0.2% (.ISO) ISO 9660 CD image (5100/59/2)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
Reporter cocaman
Tags:AveMariaRAT img


Avatar
cocaman
Malicious email (T1566.001)
From: ""LTH Purchasing" <dean@rauldeckow.ml>" (likely spoofed)
Received: "from mail.rauldeckow.ml (unknown [159.89.33.135]) "
Date: "Thu, 09 Mar 2023 20:07:19 +0000"
Subject: "[MESSAGE ENCRYPTED] Purchase order sent to info@letempsmedia.ch on Thursday,
March 9, 2023 4:27 PM"
Attachment: "LONESTAREXHIBIT PO No. 23455.IMG"

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:LONESTAR.EXE
File size:288'568 bytes
SHA256 hash: 7582fcf573ff933d5e7a8f4677b05c84cc645c10ffabcd1b223cec2530c61028
MD5 hash: 8b8e3f69cb7e717338075f48e0b2b601
MIME type:application/x-dosexec
Signature AveMariaRAT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
context-iso overlay packed snake
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2023-03-09 13:51:40 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_KB_CERT_04f131322cc31d92c849fca351d2f141
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

img 801b4609436a3aef2dcda639a6bc9d09f23bb30f9b659d7d671f1a2f377c7719

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments