MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a713aec7f14d8b3dbbee6b7c919473df492a3e9c56efcad2048c68b18fffd43e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a713aec7f14d8b3dbbee6b7c919473df492a3e9c56efcad2048c68b18fffd43e
SHA3-384 hash: dd514e329806482ba5cb46aa59d795740b1a70e8418537472ddb56f34b85733ac5b219b85f70beee3ff7b26bdcc7d756
SHA1 hash: 08f583729905e45dc97783ae0a3eaf87dc68193d
MD5 hash: 1fd3ea7a9f018deaedf6d2bb364d63e7
humanhash: sweet-venus-hydrogen-snake
File name:factura_00018963.bz2
Download: download sample
Signature AveMariaRAT
File size:254'221 bytes
First seen:2020-05-13 06:09:58 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:6oqewSmUIAyyZKwo8q396N0hC1ZvBbTBVogiFwsjyIIzJ:k5XFV38Niav5B+ginyIU
TLSH 844422668079023F98EC8DE5BC8721FEBBD6B448D949F8118BF63F19D99C638429D305
Reporter abuse_ch
Tags:AveMariaRAT bz2 COL geo Outlook RAT


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: NAM12-DM6-obe.outbound.protection.outlook.com
Sending IP: 40.92.22.47
From: Recuperacion de Carteras S.A.S <cobranzascolombia@hotmail.com>
Subject: Notificación de Embargo Urgente Su(s) obligación(es) se encuentra(n) en mora con nuestra entidad financiera
Attachment: factura_00018963.bz2 (contains "factura_00018963.exe")

AveMariaRAT C2:
demoledor.duckdns.org:1689

Intelligence


File Origin
# of uploads :
1
# of downloads :
137
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Avemaria
Status:
Malicious
First seen:
2020-05-13 06:37:13 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

rar a713aec7f14d8b3dbbee6b7c919473df492a3e9c56efcad2048c68b18fffd43e

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments