MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3259355435f9e6a9b041b93c2faa1ad8a3867de478a436606702593e4e130dd0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3259355435f9e6a9b041b93c2faa1ad8a3867de478a436606702593e4e130dd0
SHA3-384 hash: 1ca3b92034f0707812857ce77d2e941a71239c3846f818f8e9ca53dd6027c92f85acb459d73ddfe7203d96fb6260cc97
SHA1 hash: 869eb0a8776ad6b2b2e282cf94a8f28c13dc96fa
MD5 hash: 3c0bcb1f1ef3d43ed5965f4482446f71
humanhash: michigan-diet-early-mango
File name:db6ca880c803dfbdec1034838493a332.exe
Download: download sample
Signature NetWire
File size:172'032 bytes
First seen:2020-04-02 01:55:21 UTC
Last seen:2020-04-03 14:05:56 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:VR/VPPMOmvkSZMNqrGzUTmDQxIRFZcO4UVg9SeXz7MX3hxAaRcHM0Z1:FMZZQ4GITmD/HZsmg9Sej8I9L1
Threatray 5'043 similar samples on MalwareBazaar
TLSH 38F3AF36D651C031E1B241B0BA7D077B893E0E34729964E6E3F51AA46FB48A5F42E31F
Reporter abuse_ch
Tags:exe GuLoader NetWire


Avatar
abuse_ch
Payload dropped by GuLoader from the following URL:
https://drive.google.com/uc?export=download&id=1ZOzdSlJwauaSTuazx9U1p6rSrjmzAPyd

Intelligence


File Origin
# of uploads :
3
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

87b706be7fd1eef94890a8dae23b957682d1a8564033ad64945b990406962fd1

NetWire

Executable exe 3259355435f9e6a9b041b93c2faa1ad8a3867de478a436606702593e4e130dd0

(this sample)

  
Dropped by
MD5 db6ca880c803dfbdec1034838493a332
  
Dropped by
MD5 1bdc112ddace85c447fbaed10a06308f
  
Dropped by
GuLoader
  
Dropped by
SHA256 87b706be7fd1eef94890a8dae23b957682d1a8564033ad64945b990406962fd1
  
Dropped by
SHA256 d9e18b32817b0cd8761386154b296114937744d1f45c5721b273afdb189ba64c

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments