MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fe7b6aeeea82a71d754d61bd2e0edf592248d01e0f81c7bd3e7b1a5be1da2ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetSupport


Vendor detections: 12


Intelligence 12 IOCs YARA 13 File information Comments

SHA256 hash: 2fe7b6aeeea82a71d754d61bd2e0edf592248d01e0f81c7bd3e7b1a5be1da2ab
SHA3-384 hash: 0ebb72990f0fb7047f3514ff27e021f5af5345b5be7df5cd74a1985f70b77543765f4228928de392d3917aaf8d0268ac
SHA1 hash: e8f4b7b65451a8cd3b66018f6707f122b5244886
MD5 hash: 78b06525c6a3c70ab3dfa37b5489609a
humanhash: sodium-indigo-finch-mike
File name:alexwork.exe
Download: download sample
Signature NetSupport
File size:12'434'608 bytes
First seen:2026-06-08 11:24:01 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 608505ff1e7e27ff4a42ea9c4e9f4192 (5 x LummaStealer, 5 x NetSupport, 2 x ConnectWise)
ssdeep 196608:i9upko8Rr6rAHc3LkyjLCUMquQ9oCwBSEfykx/DPlRWq:i9/o8/HcbkG25quQRwBzfyQLXWq
TLSH T18CC6AE21B64AC53AEA6E41B1592CDB6B61797FB20B7144DB73DC39AE0F704C21232E17
TrID 42.7% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
16.8% (.EXE) Win64 Executable (generic) (6522/11/2)
13.0% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.6% (.EXE) Win32 Executable (generic) (4504/4/1)
5.2% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon 6ded69c7b130b2c0 (13 x ValleyRAT, 12 x CryptBot, 7 x NetSupport)
Reporter SquiblydooBlog
Tags:exe NetSupport

Intelligence


File Origin
# of uploads :
1
# of downloads :
137
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
alexwork.exe
Verdict:
No threats detected
Analysis date:
2026-06-08 11:27:28 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
dropper netsup trojan virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Searching for synchronization primitives
Creating a file in the %temp% directory
Deleting a recently created file
Loading a suspicious library
Launching a service
Using the Windows Management Instrumentation requests
Launching a process
Modifying a system file
Creating a file
Creating a file in the Windows subdirectories
Creating a process from a recently created file
Possible injection to a system process
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context advanced_installer anti-debug anti-vm base64 crypto evasive expired-cert fingerprint fingerprint installer installer installer-heuristic lolbin microsoft_visual_cc msiexec obfuscated overlay packed reconnaissance runonce short-lived-cert signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-06-07T08:12:00Z UTC
Last seen:
2026-06-07T08:52:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Script.NetSup.gen not-a-virus:HEUR:RemoteAdmin.Win32.NetSup.gen
Gathering data
Verdict:
malicious
Label(s):
antigravitybackdoor netsupportmanagerrat
Similar samples:
Result
Malware family:
netsupport
Score:
  10/10
Tags:
family:netsupport discovery rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Executes dropped EXE
Loads dropped DLL
Enumerates connected drives
Drops startup file
Family: NetSupport
Unpacked files
SH256 hash:
2fe7b6aeeea82a71d754d61bd2e0edf592248d01e0f81c7bd3e7b1a5be1da2ab
MD5 hash:
78b06525c6a3c70ab3dfa37b5489609a
SHA1 hash:
e8f4b7b65451a8cd3b66018f6707f122b5244886
SH256 hash:
1e08a98780b3e12ef2d353fde3b38c5227490f3461d0455489b2a0c00a020f0d
MD5 hash:
1cfc2d771781d1ffcf15a893b31e4b03
SHA1 hash:
10648a68dda5ac8455f71d898603f032d6150fcc
SH256 hash:
23b7e80d1a18873614ccbea6b489b35b160e9f0cd9b9694e97f198625d494560
MD5 hash:
f8013f76d64595b413a429ad65377167
SHA1 hash:
8c21ea85ad9e2cea90efae14f975095372bd3fec
SH256 hash:
d7361718ceb23b776c207c82eb60e4f24346f4cc2704136c93c76e442c2cba44
MD5 hash:
1fbd0728059f72e0039778740d7e15a8
SHA1 hash:
c1401c5d198386b92f4fbc91cb16e99eb50d3cc8
SH256 hash:
ebfff39fa8065bec55460feffb9646d2e323b2df6aa9924c2e3ed6057d2205b3
MD5 hash:
657568e16a1adba8272e09554ae2e360
SHA1 hash:
d451f965284d662956b5ed01a6fda43dc2825111
SH256 hash:
5c670173b0ca84dafedca8078828c534d08750a29cbb2ae536d1840518f0b306
MD5 hash:
e68bcaab74cf68c772c598801526a96e
SHA1 hash:
dc2005fa55b08092e2d0ba9593cd6e25a549dcb3
SH256 hash:
00f57b9910630a7049df821a39c733ca35763d9b11a58e8c0e52b06066a52643
MD5 hash:
46eacdca48274cc56965e2f11cc63d66
SHA1 hash:
305429533557823d54f1cb1766d080b7249b6d99
SH256 hash:
06a80941ef4d514fc6845f0a82cdae80d5dc23becf53797e45656473aa1e98dc
MD5 hash:
0c8696262850937c0c34da3cd24b2bb0
SHA1 hash:
7dbf638bd24bd19e9d2258f483c7ae244c7b20f1
SH256 hash:
ee4247e2ce3d529ec0e013469467894ff00faf59c632211dc438fba2331ea443
MD5 hash:
5cbabdc06e8034d801ae10b77dc559cb
SHA1 hash:
d275b98afd1d6692f85ab168faee1f85acdcca8f
SH256 hash:
c632a95871871eb8a23cc91ea09a99c04b6c425304955981249740ed9d08b141
MD5 hash:
57e7b5995199ef5f5b0b1a8094b920ab
SHA1 hash:
b3d98c8ff35644073acc194f82ba9b2c12e419db
SH256 hash:
67ff2fc39c6f6c93c3a8237561e254e7ceedbe3da18f0435c7b5528351dd937e
MD5 hash:
62ed50a2c64b9ac5c3bdc2d6f2da805c
SHA1 hash:
cf896586006a8eabd2d5d3a71dea602eea7e0a74
SH256 hash:
f2ff4e42682744b34763c6c78407314281bca1d18e624ae6996d230126e7983c
MD5 hash:
9401ef4e13fdda9c822c015cff6631c9
SHA1 hash:
34daf1c3c072757aeb0a45ae4527c7498680e181
SH256 hash:
1e794382a6e9a65e20a8c5078e3fe0d692fe03fc3f8359e844897f5dfc7394b2
MD5 hash:
5bcc1f8e9e7bc1c141631b02df02bf4f
SHA1 hash:
81cdec7a2c8578dda3c6b3bdddd20f48f5ef2298
SH256 hash:
2e1dbf571c72f7ee0e584486c5441dab16c8c868bdeb86ef24dfebe84fc68d6b
MD5 hash:
0584ff3d92f50d11143d0ea4ba4b3253
SHA1 hash:
0dc56c9d09d2749098c36f2faf88fb966d540166
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_Sandworm_ArguePatch_Apr_2022_1
Author:Arkbird_SOLG
Description:Detect ArguePatch loader used by Sandworm group for load CaddyWiper
Reference:https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments