MalwareBazaar Database

This page shows some basic information the YARA rule Susp_Indicators_EXE including corresponding malware samples.

Database Entry


YARA Rule:Susp_Indicators_EXE
Author:Florian Roth
Description:Detects packed NullSoft Inst EXE with characteristics of NetWire RAT
Firstseen:2021-10-25 23:26:03 UTC
Lastseen:2023-01-08 12:26:37 UTC
Sightings:3

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter