MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0bee1bc1fbaff816f79e78a31389680fdb23c79bff30168b26e042f793c2a849. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: 0bee1bc1fbaff816f79e78a31389680fdb23c79bff30168b26e042f793c2a849
SHA3-384 hash: 8d715b1c3281f00e22ee1da6771a57b0ec60f4fc6676a259bbf08ff931423fbaf07e75fdeac36bd324986e5987c858ae
SHA1 hash: 5c60e0bd09d869384b7c18739804f3209bb2b902
MD5 hash: 725cca0ed6d921e979761aa1dc3543b5
humanhash: maryland-freddie-winner-seventeen
File name:SPAM.zip
Download: download sample
File size:22'152 bytes
First seen:2026-07-31 06:41:04 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:KhM0gCF9kDwhLG9Xj0z4nyCGA5B+zEPyGN1imr0JZILhMB4FPQCt:VRnDkLUjNyCDazElP9IJZItA4FPQCt
TLSH T148A2D012769D1E70CFA94B3D3A0B8E18A210547F2AE6C393E8AD6B5E5953D735D03043
Magika zip
Reporter JAMESWT_WT
Tags:client32 fiseddaniret1-com ini iseddaniret2-com LIC NetSupport zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
IT IT
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:client32.exe
File size:120'256 bytes
SHA256 hash: 8000ffd1f8b32b4b85be9c3e730874865d949f9359c9a91c4386f4ff32deb180
MD5 hash: 5f35710f5128ddf6eb2c89e724b83d11
MIME type:application/x-dosexec
File name:client32.ini
File size:793 bytes
SHA256 hash: bf4899a45fb4aec3b5d96a0a06246af299acae99bb277f34266357b908f2e3a5
MD5 hash: e0cb52382589169dbb5321815f1ea1ab
MIME type:text/plain
File name:NSM.LIC
File size:262 bytes
SHA256 hash: 88448fa440aeaff2b4c43f9daca92f9948e32d1e42e822695902a870a23173bc
MD5 hash: 35b4ea845eb5d44743a5e68ad8f24c91
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
hacktool microsoft_visual_cc netsupportmanagerrat netsupportmanagerrat packed remoteaccesstool signed
Verdict:
Malicious
File Type:
zip
First seen:
2026-07-31T04:13:00Z UTC
Last seen:
2026-08-01T22:29:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win32.Trojan.Remoteadmin
Status:
Suspicious
First seen:
2026-07-31 06:41:35 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_NetSupportRAT_Config
Author:abuse.ch
Rule name:NetSupport
Author:YungBinary
Description:Detects NetSupport Manager RAT on disk or in memory
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments