MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e2b09b042b5d3ef3e60311c3a0950b85977eb0f786830fe97c6bef460b357d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetSupport


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 1e2b09b042b5d3ef3e60311c3a0950b85977eb0f786830fe97c6bef460b357d5
SHA3-384 hash: eaf78874fde6f98aa0b00721c07a43970c030b9f367dd856635d653559e64cb8fb5fdc889cbe012233a1d464d135fe40
SHA1 hash: edfbff487e767178dde5d5373549c54543fb963d
MD5 hash: 4140e18b79ba35de747108781bb557c0
humanhash: five-oscar-berlin-florida
File name:fl1775.js
Download: download sample
Signature NetSupport
File size:52'062 bytes
First seen:2023-07-08 08:27:13 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 1536:oEdD5bLOlMQppS/qQaSv47gPyfbsSjDEg:oEdD5bLkaBac4/bsCt
TLSH T1AD3374CD36D2FA5A52430371375671A9D63ACC4154895C8CF014FCACF6ACA3DBBAA58C
Reporter abuse_ch
Tags:deperekanuki1-com deperekanuki2-com js NetSupport

Intelligence


File Origin
# of uploads :
1
# of downloads :
296
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
88%
Tags:
obfuscated powershell
Result
Verdict:
MALICIOUS
Threat name:
Script-JS.Backdoor.Heuristic
Status:
Malicious
First seen:
2023-07-07 12:58:34 UTC
File Type:
Text (JavaScript)
AV detection:
3 of 38 (7.89%)
Threat level:
  2/5
Result
Malware family:
netsupport
Score:
  10/10
Tags:
family:netsupport rat
Behaviour
Download via BitsAdmin
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
NetSupport
Malware Config
Dropper Extraction:
https://turvavalaisin.fi/loco.zip
https://turvavalaisin.fi/files/
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments