MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b20e945bb53f953bdb02a70e10ea89d5610238269707c789cab3745f14502117. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b20e945bb53f953bdb02a70e10ea89d5610238269707c789cab3745f14502117
SHA3-384 hash: f8831c8f9c7fc4d6aa914fe1fe79e08e245780418dec36f71cc63b0dfe6b659f20fbd4fca36fbad80ff53aa4de427573
SHA1 hash: 6ed3914eae40308eed44756a4872741682082232
MD5 hash: 4269c27ade2de9a38ba2b93c6abc8809
humanhash: grey-summer-oklahoma-cardinal
File name:PO209947873723.tar
Download: download sample
Signature AveMariaRAT
File size:172'285 bytes
First seen:2020-06-29 07:43:16 UTC
Last seen:Never
File type: tar
MIME type:application/x-rar
ssdeep 3072:3MW9F8BY0tW43CZqy2U4AZA5VwyF122os7Mi33chr+COMfyF2hyTX:Z0GeW4E2U4AZAD93cZ+COMfyF2hG
TLSH 5DF32324B7FB0C01A40A2A05D75E1D3EFF677A4280D9C27EAF085A4D5085AF729BC367
Reporter abuse_ch
Tags:AveMariaRAT COVID-19 RAT tar


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: lucky1.263xmail.com
Sending IP: 211.157.147.130
From: Eric Chuan <eric_chuan@hsgeneral.net>
Subject: COVID-19 DELAY PURCHASE ORDER
Attachment: PO209947873723.tar (contains "PO209947873723.exe")

AveMariaRAT C2:
newzone.from-ne.com:5310 (137.63.71.51)

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Spyware.AveMaria
Status:
Malicious
First seen:
2020-06-29 07:45:06 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

tar b20e945bb53f953bdb02a70e10ea89d5610238269707c789cab3745f14502117

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments