MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 31b39849e3b268460351fdd6c616417cce18d61b8fbab248c5f4bfdf27d9a7ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetSupport


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: 31b39849e3b268460351fdd6c616417cce18d61b8fbab248c5f4bfdf27d9a7ca
SHA3-384 hash: ded570ad11fee26c25ebdfce580e590227944d7560cdfd486d2964b5f84c0a7512fbd58d222bc325c38410bee0552a4d
SHA1 hash: 56048df630737598e0eda077594a1b598c7f2fda
MD5 hash: 957dff63016e88b0821255fb6ca974a8
humanhash: connecticut-mountain-steak-seven
File name:Downloads.zip
Download: download sample
Signature NetSupport
File size:17'176 bytes
First seen:2025-12-31 06:47:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:dlsCYEe35gfQDnNQ1lYOYWY9Z1TeghW2Joevrc4O/1jEmg:ICYZJgyNQ1WVj1bhZzgoH
TLSH T19B72CF36E308995EC0E5C4370EBA350692F2C81C62B2739C7565C118B1B6FB684EE75F
Magika zip
Reporter JAMESWT_WT
Tags:client32 growthcatalystone-com ini LIC NetSupport stratosphereventuresgo-com zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
IT IT
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:client32.ini
File size:932 bytes
SHA256 hash: bb98a337c35005ce7fd57fb1783ff5a13f7828921e88635f82c3fb02592dc836
MD5 hash: 69fd71031174fc9260851073c0795c6b
MIME type:text/plain
Signature NetSupport
File name:NSM.LIC
File size:253 bytes
SHA256 hash: 83a6feb6304effcd258129e5d46f484e4c34c1cce1ea0c32a94a89283ccd24f9
MD5 hash: 14ca8f4ee0dd828ecfd0c566dce00f06
MIME type:text/plain
Signature NetSupport
File name:client32.exe
File size:107'384 bytes
SHA256 hash: 168f1b974b31df0889e6dbe75f0fe8486cf932d72f0d6ad8348c97a2e537a738
MD5 hash: 8bdcbba121984169948dfd09c629d6ae
MIME type:application/x-dosexec
Signature NetSupport
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
expired-cert microsoft_visual_cc netsupport packed remoteadmin signed virus
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win32.Trojan.NetSupport
Status:
Malicious
First seen:
2025-12-31 06:48:14 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_NetSupportRAT_Config
Author:abuse.ch
Rule name:MALWARE_Win_NetSupport
Author:ditekSHen
Description:Detects NetSupport client
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments