NEW | Hunt across all abuse.ch platforms with one simple query - discover if an IPv4 address, domain, URL or file hash has been identified on any platform from a centralized search tool. Test it out here hunting.abuse.ch - and happy hunting 🔍

ThreatFox Database

Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family. The page below gives you an overview on indicators of compromise associated with win.ave_maria.

You can also get this data through the ThreatFox API.

Database Entry


Malware: Ave Maria
Malware alias:AVE_MARIA, AveMariaRAT, Warzone RAT, WarzoneRAT, avemaria
First seen:2021-01-11 10:09:49 UTC
Last seen:2025-05-20 10:26:25 UTC
Number of IOCs:2'809
Malpedia: https://malpedia.caad.fkie.fraunhofer.de/details/win.ave_maria

Indicators Of Compromise


The table below shows all indicators of compromise (IOCs) that are associated with this particulare malware family (max 1000).