MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b655f06dfe4aacd02f54ed88702099fcb1f7b28e439948fccd5d1b4e67a9b681. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b655f06dfe4aacd02f54ed88702099fcb1f7b28e439948fccd5d1b4e67a9b681
SHA3-384 hash: a48ad51400e3c33842903cbe58a8dcfeae0eaff1805a9214f5e5841e9c16901d50d2e079516194af00816781c4044100
SHA1 hash: f221f00e847bc50d31e186bddd2a8e98a2eb22ed
MD5 hash: f419aedebf1e130ec3b5786ab3e2bfef
humanhash: queen-comet-berlin-eighteen
File name:Jordan offer.arj
Download: download sample
Signature AveMariaRAT
File size:17'484 bytes
First seen:2020-10-11 16:39:41 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 384:PkHqahOG8jiYByTOgEbXX8Q6LmdnjJGECoJhyCnf5lYIS:PxlISgEbH8DyFQErhzVS
TLSH BF72E1D7A443B40DCC4361F8D49C277F67EAF1AAD4A65A15EA067EDA83D0F590C02BC4
Reporter abuse_ch
Tags:arj AveMariaRAT RAT


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: slot0.globalsproducts.net
Sending IP: 45.95.169.130
From: info@globalsproducts.net
Subject: Jordan Order
Attachment: Jordan offer.arj (contains "Jordan offer.exe")

AveMariaRAT C2:
172.111.210.207:2829

Intelligence


File Origin
# of uploads :
1
# of downloads :
106
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-11 13:56:23 UTC
AV detection:
4 of 48 (8.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

arj b655f06dfe4aacd02f54ed88702099fcb1f7b28e439948fccd5d1b4e67a9b681

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments