MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8943d0c481100b198b4b33692a8118d9b6d460ddb164ba0eae470b336560b5b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f8943d0c481100b198b4b33692a8118d9b6d460ddb164ba0eae470b336560b5b
SHA3-384 hash: fca01cbc0c67cc0679d4ba1556a05e3c1e5cdbeada30cf097da5942841f36654df113efafd454b745fa33aee89b1445a
SHA1 hash: 59a1021807f76a4860d6a08150038f7114534ebd
MD5 hash: 0730f20a40ec7f40ed4f0265d0ed5112
humanhash: quebec-avocado-nine-yellow
File name:OEM Purchase order and drawing.rar
Download: download sample
Signature AveMariaRAT
File size:204'083 bytes
First seen:2020-05-01 10:28:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:xqc7enJq0Y5epvSOBmCfNZM5DB0STj5O2R:xqc7KnY0VSOBZFZYB0SnXR
TLSH 381423EAF7586C73900B786B545932BCEDE7DFB0293E3A052F85235534B99E4268D880
Reporter abuse_ch
Tags:AveMariaRAT rar RAT


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: qq.com
Sending IP: 183.3.226.209
From: 黄蕊-3C <sales3@goldsunhk.com>
Subject: Item Purchase Inquiry
Attachment: OEM Purchase order and drawing.rar (contains "OEM Purchase order and drawing.exe")

AveMariaRAT C2:
216.38.8.163:40951

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Zenpak
Status:
Malicious
First seen:
2020-05-01 10:36:00 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

rar f8943d0c481100b198b4b33692a8118d9b6d460ddb164ba0eae470b336560b5b

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments