MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 449f0daf3e6ba6effaf3b94a89d297626fc5d07541dfd3d59e08264953542d3e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 449f0daf3e6ba6effaf3b94a89d297626fc5d07541dfd3d59e08264953542d3e
SHA3-384 hash: ad2918ca4513f6f0c3f98b2b4f8402449432ba61abe3d1bae328abd59e2c68b246827e8197dc30554bbc3d97652744fe
SHA1 hash: dc605963ae9570efd9205a4c66d9657b432c109d
MD5 hash: 3ffd8292a926826d753a78b7a3989623
humanhash: ink-glucose-nebraska-victor
File name:Payment Notification.cab
Download: download sample
Signature NetWire
File size:863'989 bytes
First seen:2020-06-04 09:01:13 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 24576:Km9vvaLdQpiG2sEvUs3IGG3GDOue9F8g9KCwP:Km9vvIQptAvU/pWKuen8rJ
TLSH C30533E132096E6DE5EBBE762DB3C68E50C3E084803D7B776E3215879D46466A43B0D3
Reporter abuse_ch
Tags:cab MailChannels NetWire RAT


Avatar
abuse_ch
Malspam distributing NetWire:

HELO: buffalo.elm.relay.mailchannels.net
Sending IP: 23.83.212.24
From: Paymentsemail@fnb.co.za
Reply-To: No-repIy@fnb.co.za
Subject: Payment Notification from AM SYSTEMS INTEGRATIONS_8GB5SKLG
Attachment: Payment Notification.cab (contains "Payment Notification.exe")

NetWireRAT C2:
154.16.93.179:3364

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.NetWired
Status:
Malicious
First seen:
2020-06-04 09:36:21 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

cab 449f0daf3e6ba6effaf3b94a89d297626fc5d07541dfd3d59e08264953542d3e

(this sample)

  
Dropping
NetWire
  
Delivery method
Distributed via e-mail attachment

Comments