MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e81f5ae64a272d9f99d1ceea0cac073f6d773efb2e9505850f9cdb6356421e5a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AveMariaRAT
Vendor detections: 6
| SHA256 hash: | e81f5ae64a272d9f99d1ceea0cac073f6d773efb2e9505850f9cdb6356421e5a |
|---|---|
| SHA3-384 hash: | 7e418fc62515cfb8fcf883f17268953679b851ed5f691531633fa8370548ff1c22ab247a1773e2609d487ddbe4ac6522 |
| SHA1 hash: | 50ce1ba6725b7c806082ad18c95e909de81e5a7e |
| MD5 hash: | 5dbf0e4acb0d2a53f5113d1cab6f6b70 |
| humanhash: | mountain-white-two-lithium |
| File name: | Quotation.zip |
| Download: | download sample |
| Signature | AveMariaRAT |
| File size: | 200'393 bytes |
| First seen: | 2022-10-31 14:36:01 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:hKDguB1ZM32221wUWQPlp5uU8EsWc/FRT3odvy:h2fB1Om2KWa5uqtct+q |
| TLSH | T1081412E68E94E93F53835E2032AD55DD8239FAF6F23C53D9600C4C8014925AABE5B7CC |
| TrID | 80.0% (.ZIP) ZIP compressed archive (4000/1) 20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1) |
| Reporter | |
| Tags: | AveMariaRAT QUOTATION zip |
cocaman
Malicious email (T1566.001)From: ""=?UTF-8?B?UnVixI1pbnNrYXM=?=" <andrius@interautomatika.lt?" (likely spoofed)
Received: "from [185.222.58.52] (unknown [185.222.58.52]) "
Date: "31 Oct 2022 08:20:32 +0100"
Subject: "QUOTATION # FA0670/89901"
Attachment: "Quotation.zip"
Intelligence
File Origin
File Archive Information
This file archive contains 3 file(s), sorted by their relevance:
| File name: | mpxitlspvs.fcd |
|---|---|
| File size: | 194'048 bytes |
| SHA256 hash: | fc2c61275f5e138bb243ca6d880654285b25146d63b9035219e012fec7fe186d |
| MD5 hash: | 5ce630485aa3fd7dee0cc244fdc655d6 |
| MIME type: | application/octet-stream |
| Signature | AveMariaRAT |
| File name: | axrlbs.a |
|---|---|
| File size: | 7'645 bytes |
| SHA256 hash: | b86270e9db608f2a32b67de1de6dd0a7a850012a77793da1a74fe36814f30adc |
| MD5 hash: | b37a939a83dbe06519592528f5cb296b |
| MIME type: | application/octet-stream |
| Signature | AveMariaRAT |
| File name: | cbfgzi.exe |
|---|---|
| File size: | 6'144 bytes |
| SHA256 hash: | 0be639a2b07d8f92d62c57dd104d13ff79d5d8cf1851be794d8e36a8e4a6d531 |
| MD5 hash: | c7e1db4985ccd7002c419959c5459ca9 |
| MIME type: | application/x-dosexec |
| Signature | AveMariaRAT |
Vendor Threat Intelligence
Result
Behaviour
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
AveMariaRAT
zip e81f5ae64a272d9f99d1ceea0cac073f6d773efb2e9505850f9cdb6356421e5a
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.