MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 06e6812b532aa2534c5e148ca2d680f65eaa9ab6a3ac495ab7f69bb74c2f6aec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 06e6812b532aa2534c5e148ca2d680f65eaa9ab6a3ac495ab7f69bb74c2f6aec
SHA3-384 hash: 15e84e843449a94ce6d2d07488ed2e68a2a8f3a4f53f45512329cff0d8bdf72c656b5b05d315ab095120cae07e1f2f71
SHA1 hash: f0e712ef5f4d39c042edcaa81c80132ac28c1f66
MD5 hash: 36fbd9d44ef3f474f3eceaacf1658f96
humanhash: seven-mexico-shade-mexico
File name:Absa.cab
Download: download sample
Signature NetWire
File size:407'531 bytes
First seen:2020-06-26 07:17:06 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:CXIxUpyfax2BPAN7pUNr/UC6UbwCt16EEg:au/AEiGNzf6UbwW1jH
TLSH 3084231EE2A8CA2FC1A42DFCF4766AC127490271899C24D6BC0DBD8F15650FB772EE15
Reporter abuse_ch
Tags:cab NetWire RAT


Avatar
abuse_ch
Malspam distributing NetWire:

HELO: host19.axxesslocal.co.za
Sending IP: 197.242.145.93
From: Absa <ibreply@absa.co.za>
Reply-To: noreply@absa.co.za
Subject: Proof of Payment
Attachment: Absa.cab (contains "Absa.exe")

NetWire RAT C2:
154.16.93.182:3361

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-26 07:19:04 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

cab 06e6812b532aa2534c5e148ca2d680f65eaa9ab6a3ac495ab7f69bb74c2f6aec

(this sample)

  
Dropping
NetWire
  
Delivery method
Distributed via e-mail attachment

Comments