MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d27912f5594adcf580dd98a2cb9a3f684c98c3bf2d5eaea1452fa33e687df1f9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: d27912f5594adcf580dd98a2cb9a3f684c98c3bf2d5eaea1452fa33e687df1f9
SHA3-384 hash: 1ee8fc9f6f504e9fd876c4487a25df559414b03397131beb2bea1ba920c001031c82c2cddeb4436b4dace568cbc323e9
SHA1 hash: 3529caf0aa43eddf371a29f978960c90585ceeb4
MD5 hash: 7ee688c5071c5f8abf8994e6d98d3b81
humanhash: lamp-idaho-steak-vegan
File name:BANK SLIPS-pdf.gz
Download: download sample
Signature NetWire
File size:424'196 bytes
First seen:2020-05-28 10:40:19 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:MmZHHtz044JshSQyvEQM6bxIYs5MbebL9terk:MoHHtloQyv7LepCM9td
TLSH FA942340B6BF478EDDB7662518D5BC021513D7E28ECC3D08F3A589D07EB427AA46C782
Reporter jarumlus
Tags:NetWire

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-28 09:43:37 UTC
File Type:
Binary (Archive)
Extracted files:
229
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

zip d27912f5594adcf580dd98a2cb9a3f684c98c3bf2d5eaea1452fa33e687df1f9

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments