MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0232fe4b3256a6a4700de482e5e9074baf4548d7604cf4404182be73353ee32f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0232fe4b3256a6a4700de482e5e9074baf4548d7604cf4404182be73353ee32f
SHA3-384 hash: 319d4003f541301bec828f4f63fc4ee0c9017a3540f99c1a0e16c58dfec39fe057e289df07f9e9f268db1c741411116c
SHA1 hash: 85c5b30ebe711953857cc6d5e5c52dc51786c518
MD5 hash: f3657fe3d3aa2264fc487d7d2e35a06a
humanhash: twenty-hawaii-victor-sixteen
File name:MailPrintDhlTrackingBL.pdf.exe
Download: download sample
Signature NetWire
File size:3'728'384 bytes
First seen:2020-03-31 14:00:02 UTC
Last seen:2020-04-02 10:03:49 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c5ec5ad249a6e024a6de2f8a5ba5a918 (1 x NetWire)
ssdeep 49152:tRQKN4sLOIr0KLOGtCfepXj/489nrjUYv13ROMK9Fx:AKN4sLtr0K6J2V/r9nrjUnMK9X
Threatray 3 similar samples on MalwareBazaar
TLSH 8E067B26F3429877C1531A30DE0782EE9A35BF106E3495877BB43E0CAF797927539292
Reporter cocaman
Tags:COVID-19 exe NetWire

Intelligence


File Origin
# of uploads :
2
# of downloads :
96
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Xaparo
Status:
Malicious
First seen:
2020-03-31 14:35:58 UTC
File Type:
PE (Exe)
Extracted files:
172
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

NetWire

Executable exe 0232fe4b3256a6a4700de482e5e9074baf4548d7604cf4404182be73353ee32f

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
ole32.dll::CreateStreamOnHGlobal
SHELL_APIManipulates System Shellshell32.dll::ShellExecuteA
shell32.dll::SHGetFileInfoA
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.DLL::CloseHandle
KERNEL32.DLL::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.DLL::LoadLibraryA
KERNEL32.DLL::LoadLibraryExA
KERNEL32.DLL::GetDriveTypeA
KERNEL32.DLL::GetSystemInfo
KERNEL32.DLL::GetStartupInfoA
KERNEL32.DLL::GetDiskFreeSpaceA
WIN_BASE_IO_APICan Create FilesKERNEL32.DLL::CopyFileA
KERNEL32.DLL::CreateDirectoryA
KERNEL32.DLL::CreateFileA
KERNEL32.DLL::DeleteFileA
KERNEL32.DLL::GetFileAttributesA
KERNEL32.DLL::FindFirstFileA
WIN_BASE_USER_APIRetrieves Account InformationKERNEL32.DLL::GetComputerNameA
advapi32.dll::GetUserNameA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegCreateKeyExA
advapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
advapi32.dll::RegQueryValueExW
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::AppendMenuA
user32.dll::CreateMenu
user32.dll::EmptyClipboard
user32.dll::FindWindowExA
user32.dll::FindWindowA

Comments