MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ba289a34a66466bf9fd869e8fb2868dfc95809cb2435aa911f1d228ecb69f3ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ba289a34a66466bf9fd869e8fb2868dfc95809cb2435aa911f1d228ecb69f3ae
SHA3-384 hash: a41a8e7344502d4513415e0719c8050bb63175bcb0df5627209ccda8e9ff3732b512602395527b6aa091ecd4cc2c3cd7
SHA1 hash: f43e8ace2dce88f20be9ba576917a329f68858e4
MD5 hash: e4e2cca6e868bd0a9f533a6d4ff6b17e
humanhash: coffee-ohio-lima-fruit
File name:Payment details.rar
Download: download sample
Signature AveMariaRAT
File size:234'819 bytes
First seen:2020-07-09 14:38:55 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:Up/7qdDaYYY0ERT9I/o5LPfdCy+h15575QTIvfNrhVy5S45j:IO9rYU9sULdCxbJ1rX45j
TLSH EA3413928FA7B5656AA5C45EF3B0ECBE5F0447C22DC90F4FA9D16B8B294A91C048CC53
Reporter abuse_ch
Tags:AveMariaRAT rar RAT


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: poydorus.t.mk
Sending IP: 195.26.152.36
From: aleksandra@bomi10.com.mk <aleksandra@bomi10.com.mk>
Subject: RE: Delayed Payment Due To COVID-19 Situation
Attachment: Payment details.rar (contains "Payment details.exe")

AveMariaRAT C2:
graceland.ddns.net:3720 (46.38.151.248)

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-09 14:40:07 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

rar ba289a34a66466bf9fd869e8fb2868dfc95809cb2435aa911f1d228ecb69f3ae

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments