MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a1944905387dda414fd6e9b8d459958bf9a1d433cf317e4214494eafe1c6f1c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AveMariaRAT
Vendor detections: 3
| SHA256 hash: | a1944905387dda414fd6e9b8d459958bf9a1d433cf317e4214494eafe1c6f1c3 |
|---|---|
| SHA3-384 hash: | a656fcec0822c3466502211279ab83136de4b335b8ff3e80ebcd78adbab0791096dc15cf73eb42727c3808a5c8ce7995 |
| SHA1 hash: | e0cb772e01c42e7eb7695a146e04905b1f1f0a89 |
| MD5 hash: | 1dd0f7c966c2e9c36937f91d4c41f061 |
| humanhash: | oregon-hawaii-louisiana-oven |
| File name: | new order.r01 |
| Download: | download sample |
| Signature | AveMariaRAT |
| File size: | 225'175 bytes |
| First seen: | 2021-01-18 07:14:19 UTC |
| Last seen: | 2021-01-18 07:34:50 UTC |
| File type: | r01 |
| MIME type: | application/x-rar |
| ssdeep | 3072:RuQ2FNVORRi+N6U4YmqsFM8uDJjPNVRnccb8vSsZzvzf894TzU4MNLFr:RurgRkY4Y0FaGsRsNrf8B465 |
| TLSH | 9024230DDA72A650CA9B55D14082F2B6993E9D60D393F4144ECE9D12AEEFE35DCC42F0 |
| Reporter | |
| Tags: | AveMariaRAT r01 RAT |
abuse_ch
Malspam distributing AveMariaRAT:HELO: rdns0.greatgrovp.com
Sending IP: 5.230.22.29
From: Sales<contacts@greatgrovp.com>
Subject: Re:New Order
Attachment: new order.r01 (contains "new order.exe")
AveMariaRAT C2:
mykassa.zapto.org:5200 (194.127.179.183)
Intelligence
File Origin
# of uploads :
2
# of downloads :
102
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-01-18 07:15:07 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AveMariaRAT
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.