MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f7a8dfe3dfb00982d01ddb1db37a8788c7c52a8e3c86afbd25837cf542b6cbf0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f7a8dfe3dfb00982d01ddb1db37a8788c7c52a8e3c86afbd25837cf542b6cbf0
SHA3-384 hash: c0a75c7ee1426b22c90d65a2cd8dd1a1feb1428d28ff0c86d00d851c2615f7d14aac9148db47cf848bd18d358dd780f2
SHA1 hash: 1c149efca035042b680a404375f577d3bf2fe8b3
MD5 hash: b0b9f90acc47693cefdb0356da5c03f0
humanhash: may-sodium-autumn-timing
File name:QuotationRequest_20202605_20202605_20202605PDF.z
Download: download sample
Signature AveMariaRAT
File size:427'921 bytes
First seen:2020-08-03 11:37:53 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:axvVzwN/TwdHApQps5tr/ZA++RKPDvJcIeNvRpKSlDds:e+/sg2pKtiF0vJd8v6ShG
TLSH 4294231D3E92A8CAA81935C93C8A956660B47C0DED8607C5548B30FF6E7EAD04FC7C97
Reporter abuse_ch
Tags:AveMariaRAT RAT z


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: medpex.com
Sending IP: 210.244.73.74
From: EXPORT <6667hs@naver.com>
Subject: Product Inquiry From CW Singapore Pte Ltd
Attachment: Quotation Request_20202605_20202605_20202605PDF.z (contains "Quotation Request_20202605_20202605_20202605PDF.exe")

Unknown RAT C2:
45.137.22.117:5200

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-03 11:39:04 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

z f7a8dfe3dfb00982d01ddb1db37a8788c7c52a8e3c86afbd25837cf542b6cbf0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments