MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f7a8dfe3dfb00982d01ddb1db37a8788c7c52a8e3c86afbd25837cf542b6cbf0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AveMariaRAT
Vendor detections: 3
| SHA256 hash: | f7a8dfe3dfb00982d01ddb1db37a8788c7c52a8e3c86afbd25837cf542b6cbf0 |
|---|---|
| SHA3-384 hash: | c0a75c7ee1426b22c90d65a2cd8dd1a1feb1428d28ff0c86d00d851c2615f7d14aac9148db47cf848bd18d358dd780f2 |
| SHA1 hash: | 1c149efca035042b680a404375f577d3bf2fe8b3 |
| MD5 hash: | b0b9f90acc47693cefdb0356da5c03f0 |
| humanhash: | may-sodium-autumn-timing |
| File name: | QuotationRequest_20202605_20202605_20202605PDF.z |
| Download: | download sample |
| Signature | AveMariaRAT |
| File size: | 427'921 bytes |
| First seen: | 2020-08-03 11:37:53 UTC |
| Last seen: | Never |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 12288:axvVzwN/TwdHApQps5tr/ZA++RKPDvJcIeNvRpKSlDds:e+/sg2pKtiF0vJd8v6ShG |
| TLSH | 4294231D3E92A8CAA81935C93C8A956660B47C0DED8607C5548B30FF6E7EAD04FC7C97 |
| Reporter | |
| Tags: | AveMariaRAT RAT z |
abuse_ch
Malspam distributing unidentified malware:HELO: medpex.com
Sending IP: 210.244.73.74
From: EXPORT <6667hs@naver.com>
Subject: Product Inquiry From CW Singapore Pte Ltd
Attachment: Quotation Request_20202605_20202605_20202605PDF.z (contains "Quotation Request_20202605_20202605_20202605PDF.exe")
Unknown RAT C2:
45.137.22.117:5200
Intelligence
File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 11:39:04 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.