MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3da5a40330a85a499e5706593908906f2e2df166d713fef626737c3a4472b6c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: d3da5a40330a85a499e5706593908906f2e2df166d713fef626737c3a4472b6c
SHA3-384 hash: a0aff2958966f261cd40b2903589848972a06f889ae0efb7c625db16d8b17f371356496ac1f0d89579a91a0c7c008442
SHA1 hash: 3565e23cec0ee6bf3364bd58c010de539d3eae0d
MD5 hash: 5a8a759da9cde54f967c21f7e32eee98
humanhash: asparagus-uncle-beryllium-golf
File name:INV9938483.7z
Download: download sample
Signature NetWire
File size:329'636 bytes
First seen:2020-07-16 01:04:44 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 6144:dRbx7VhNUBGvDJyvUoL6mNGY6+j7alJ5ru4bfkvjVN6oCA3/uEg285Tf+35qyLqe:BLyGvEUoLv9jSrfQr/6PACHTsee
TLSH BE6423917815402A5794B2CEFC50876EA1A98705DA2A4EC77ECFBEFEA6310F5AC25084
Reporter jarumlus
Tags:NetWire

Intelligence


File Origin
# of uploads :
1
# of downloads :
203
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-16 01:06:06 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

7z d3da5a40330a85a499e5706593908906f2e2df166d713fef626737c3a4472b6c

(this sample)

  
Dropped by
NetWire
  
Delivery method
Distributed via e-mail attachment

Comments