MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca4e45191fc62b63108675de4823860226223847df719b4d4f93914ab8faebd6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ca4e45191fc62b63108675de4823860226223847df719b4d4f93914ab8faebd6
SHA3-384 hash: 766a07a56d85af584120b37b101daa9511ee998eaefc8a6417ba04bf1626a3ac9cc3a5ef84ed8b3b685e73ede81d6ad7
SHA1 hash: 444336c9435d0307100b92b2233feda669785c37
MD5 hash: d5a559dcff962cf8071b7d578f9d4391
humanhash: floor-spring-alaska-leopard
File name:168900#.zip
Download: download sample
Signature AveMariaRAT
File size:367'367 bytes
First seen:2020-11-24 12:06:49 UTC
Last seen:2020-11-27 09:46:50 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:rGHu2v1QWTVoXimq5kQPuWD0tWqxljeJ+w/K9RAix09rWY0hAVb4Kp8P:rGHLv1QHymp/WD0tZ3j+n/KUix+qngKP
TLSH CC74235269F7B3944DC342B3EB5F6048D68E5FC804B80FF36011D4647B99BF9A80AD9A
Reporter GovCERT_CH

Intelligence


File Origin
# of uploads :
11
# of downloads :
175
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Streamer
Status:
Malicious
First seen:
2020-11-24 03:25:57 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

zip ca4e45191fc62b63108675de4823860226223847df719b4d4f93914ab8faebd6

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments