MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e35d9f8e7ffcb2cee435aace101123f0ac93a0bbe7e615d029fdcb4adcf3819c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e35d9f8e7ffcb2cee435aace101123f0ac93a0bbe7e615d029fdcb4adcf3819c
SHA3-384 hash: e962db0e424831a3bc5bcb07434d73be2ad2e71027aa48dfb600ffa785eaf79a073e400e44b4b7a5f58c2d79d8db080f
SHA1 hash: 2dc949812b601e4c876c31f15d242bfe10cf5bfc
MD5 hash: e1a0b7ebfb5374e99fee23fda3f2ce5a
humanhash: friend-island-timing-island
File name:sample order.zip
Download: download sample
Signature AveMariaRAT
File size:571'930 bytes
First seen:2020-10-13 07:39:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:YPS5UcAYpNKOrgndWaf428LYBij9b7EVywrg9lsvHZxHrF/cB:Y6DrNZIWa5CYBij90M4g4vHzrFE
TLSH 6BC423A8B6827F70ED54D64D1710395B8D031EB4AF4698216ECA386BCEFC9E6343C15B
Reporter abuse_ch
Tags:AveMariaRAT Endurance RAT zip


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: gproxy10-pub.mail.unifiedlayer.com
Sending IP: 69.89.20.226
From: kfl2.lab@kemsltd.com
Reply-To: CynthiaChcn0801@outlook.com
Subject: sample order
Attachment: sample order.zip (contains "SNMx8yA6u0ERiq8.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Generic
Status:
Suspicious
First seen:
2020-10-13 04:52:55 UTC
AV detection:
2 of 48 (4.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

zip e35d9f8e7ffcb2cee435aace101123f0ac93a0bbe7e615d029fdcb4adcf3819c

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments