{"id":4203,"date":"2022-06-02T13:05:41","date_gmt":"2022-06-02T18:05:41","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4203"},"modified":"2022-06-02T13:05:42","modified_gmt":"2022-06-02T18:05:42","slug":"avemariarat-is-not-as-good-as-its-name-suggests","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/","title":{"rendered":"AveMariaRat is not as good as its name suggests"},"content":{"rendered":"\n<p>AveMariaRat, as its name says, is a modular RAT with an advanced design. When first discovered, researchers believed that the malware was quite simple and would not follow the story of Ryuk ransomware but\u2026 After further analysis, it was revealed that this virus had advanced features under its hood, such as privilege escalation and remote camera control.<\/p>\n\n\n\n<p>AveMaria is capable of stealing a wide range of data from machines infected by this threat that even if this information is well protected, such as the credentials protected in Mozilla Firefox, it is not secure despite the PK11 encryption used.<\/p>\n\n\n\n<p>However, some parts of the malware appear to be unfinished. And it seems that the authors are still working to further expand its functionality. Considering how effective this RAT is already this can be concerning. Unfortunately, the malware is also capable of avoiding detection on many target machines which can further complicate things.<\/p>\n\n\n\n<p>Currently, this threat is being targeted by phishing at Windows users in which they are infected, by opening an apparently Excel file, with the AveMariaRAT malware, but this is not all, since it also infects with BitRAT and PandoraHVNC.<\/p>\n\n\n\n<p>This threat is fairly new and, at this time, there is limited information about the Ave Maria RAT. All the more reason to use the advanced features provided by the ANY.RUN malware search service to analyze and dissect the available samples. Unfortunately, we must admit that we are likely to hear about this malware again, and the more prepared we are, the better.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, we will talk about AveMariaRat, a threat that is not as good as its name suggests and we will see why&#8230;&#8230;..<\/p>\n","protected":false},"author":1,"featured_media":4204,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4203","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AveMariaRat is not as good as its name suggests - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today, we will talk about AveMariaRat, a threat that is not as good as its name suggests and we will see why........\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AveMariaRat is not as good as its name suggests - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today, we will talk about AveMariaRat, a threat that is not as good as its name suggests and we will see why........\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-06-02T18:05:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-06-02T18:05:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/AveMariaRat.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"737\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"AveMariaRat is not as good as its name suggests\",\"datePublished\":\"2022-06-02T18:05:41+00:00\",\"dateModified\":\"2022-06-02T18:05:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/\"},\"wordCount\":263,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/AveMariaRat.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/\",\"name\":\"AveMariaRat is not as good as its name suggests - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/AveMariaRat.jpg\",\"datePublished\":\"2022-06-02T18:05:41+00:00\",\"dateModified\":\"2022-06-02T18:05:42+00:00\",\"description\":\"Today, we will talk about AveMariaRat, a threat that is not as good as its name suggests and we will see why........\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/AveMariaRat.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/AveMariaRat.jpg\",\"width\":737,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/avemariarat-is-not-as-good-as-its-name-suggests\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AveMariaRat is not as good as its name suggests\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AveMariaRat is not as good as its name suggests - Truxgo Server Blog","description":"Today, we will talk about AveMariaRat, a threat that is not as good as its name suggests and we will see why........","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/","og_locale":"es_MX","og_type":"article","og_title":"AveMariaRat is not as good as its name suggests - Truxgo Server Blog","og_description":"Today, we will talk about AveMariaRat, a threat that is not as good as its name suggests and we will see why........","og_url":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-06-02T18:05:41+00:00","article_modified_time":"2022-06-02T18:05:42+00:00","og_image":[{"width":737,"height":450,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/AveMariaRat.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"AveMariaRat is not as good as its name suggests","datePublished":"2022-06-02T18:05:41+00:00","dateModified":"2022-06-02T18:05:42+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/"},"wordCount":263,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/AveMariaRat.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/","url":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/","name":"AveMariaRat is not as good as its name suggests - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/AveMariaRat.jpg","datePublished":"2022-06-02T18:05:41+00:00","dateModified":"2022-06-02T18:05:42+00:00","description":"Today, we will talk about AveMariaRat, a threat that is not as good as its name suggests and we will see why........","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/AveMariaRat.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/06\/AveMariaRat.jpg","width":737,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/avemariarat-is-not-as-good-as-its-name-suggests\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"AveMariaRat is not as good as its name suggests"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4203","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4203"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4203\/revisions"}],"predecessor-version":[{"id":4208,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4203\/revisions\/4208"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4204"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4203"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4203"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4203"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}