🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5abf9e91cb8ccbaa2cc4ea33ed1af830bc2a480c4d038b53c16ee1b0947dddc4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetSupport


Vendor detections: 16


Intelligence 16 IOCs 1 YARA 6 File information Comments

SHA256 hash: 5abf9e91cb8ccbaa2cc4ea33ed1af830bc2a480c4d038b53c16ee1b0947dddc4
SHA3-384 hash: 1a87a2fd8bd25845f8bdb8cbf98f6b0ba29b4e89c167cbf8f2a95431582683470c49c938e19289a7351e00211a409acb
SHA1 hash: 9ba12c6ca232aecad4de1bd9a3c50453d3db03b7
MD5 hash: 1dcd74504d8668b3bc8298fd550c21bb
humanhash: social-autumn-fillet-autumn
File name:1dcd74504d8668b3bc8298fd550c21bb.exe
Download: download sample
Signature NetSupport
File size:13'413'352 bytes
First seen:2026-02-18 11:45:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash dcaf48c1f10b0efa0a4472200f3850ed (716 x Efimer, 60 x BlankGrabber, 23 x SalatStealer)
ssdeep 196608:414oWUoB9qLZBFslHl7dZgnRMWF3y99TisLkuorne8WcFUurH/P/XRLSq2KKeF:414FSsFl7dCR1C99/Lku8XWcFUuDX8W
TLSH T1E7D633A0A6E821FBF9EAD33DC86199A1C99635673B45C183C3F8D5A02C737C4697E704
TrID 55.7% (.EXE) InstallShield setup (43053/19/16)
21.4% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
8.4% (.EXE) Win64 Executable (generic) (6522/11/2)
6.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
2.6% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
dhash icon c6c2ccc4f4e0e0f8 (49 x PythonStealer, 32 x Adware.Yogi, 29 x SVCStealer)
Reporter abuse_ch
Tags:147-45-60-69 45-93-20-176 exe husa-xyz NetSupport


Avatar
abuse_ch
NetSupport C2:
147.45.60.69:443

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
147.45.60.69:443 https://threatfox.abuse.ch/ioc/1750377/

Intelligence


File Origin
# of uploads :
1
# of downloads :
171
Origin country :
NL NL
Vendor Threat Intelligence
Malware configuration found for:
PyInstaller
Details
PyInstaller
a compiled assembly and a Python version
Malware family:
netsupport
ID:
1
File name:
1dcd74504d8668b3bc8298fd550c21bb.exe
Verdict:
Malicious activity
Analysis date:
2026-02-18 11:46:23 UTC
Tags:
auto-startup netsupport rmm-tool remote python tool

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
vmdetect autorun netsup
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug expand expired-cert fingerprint installer-heuristic keylogger lolbin microsoft_visual_cc overlay packed packed pyinstaller pyinstaller short-lived-cert
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-02-12T02:01:00Z UTC
Last seen:
2026-02-12T18:44:00Z UTC
Hits:
~10
Detections:
BSS:Trojan.Win32.Generic Backdoor.RABased.HTTP.C&C HEUR:Trojan.Script.NetSup.gen RemoteAdmin.NetSup.HTTP.C&C not-a-virus:HEUR:RemoteAdmin.Win32.NetSup.gen
Malware family:
NetSupport Ltd
Verdict:
Suspicious
Result
Threat name:
NetSupport RAT
Detection:
malicious
Classification:
rans.troj.spyw.evad
Score:
84 / 100
Signature
Contains functionality to detect sleep reduction / modifications
Contains functionalty to change the wallpaper
Delayed program exit found
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Suricata IDS alerts for network traffic
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1871119 Sample: 7EBj2vvXdx.exe Startdate: 18/02/2026 Architecture: WINDOWS Score: 84 51 mhusa.xyz 2->51 61 Suricata IDS alerts for network traffic 2->61 63 Multi AV Scanner detection for dropped file 2->63 65 Multi AV Scanner detection for submitted file 2->65 67 Joe Sandbox ML detected suspicious sample 2->67 9 7EBj2vvXdx.exe 41 2->9         started        12 Client.exe 2->12         started        signatures3 69 Performs DNS queries to domains with low reputation 51->69 process4 file5 33 C:\Users\user\AppData\...\win32trace.pyd, PE32+ 9->33 dropped 35 C:\Users\user\AppData\...\win32event.pyd, PE32+ 9->35 dropped 37 C:\Users\user\AppData\Local\...\win32api.pyd, PE32+ 9->37 dropped 39 27 other malicious files 9->39 dropped 14 7EBj2vvXdx.exe 21 9->14         started        process6 file7 41 C:\Users\user\AppData\...\remcmdstub.exe, PE32 14->41 dropped 43 C:\Users\user\AppData\Roaming\...\pcicapi.dll, PE32 14->43 dropped 45 C:\Users\user\AppData\...\msvcr100.dll, PE32 14->45 dropped 47 5 other malicious files 14->47 dropped 17 Client.exe 4 14->17         started        21 tasklist.exe 1 14->21         started        23 tasklist.exe 1 14->23         started        25 cmd.exe 1 14->25         started        process8 dnsIp9 49 mhusa.xyz 147.45.60.69, 443, 49717 FREE-NET-ASFREEnetEU Russian Federation 17->49 53 Multi AV Scanner detection for dropped file 17->53 55 Contains functionalty to change the wallpaper 17->55 57 Delayed program exit found 17->57 59 Contains functionality to detect sleep reduction / modifications 17->59 27 conhost.exe 21->27         started        29 conhost.exe 23->29         started        31 conhost.exe 25->31         started        signatures10 process11
Gathering data
Threat name:
Win64.Trojan.Kepavll
Status:
Malicious
First seen:
2026-02-12 06:49:45 UTC
AV detection:
20 of 37 (54.05%)
Threat level:
  5/5
Result
Malware family:
netsupport
Score:
  10/10
Tags:
family:netsupport discovery pyinstaller rat
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Enumerates processes with tasklist
Drops startup file
Executes dropped EXE
Loads dropped DLL
NetSupport
Netsupport family
Unpacked files
SH256 hash:
5abf9e91cb8ccbaa2cc4ea33ed1af830bc2a480c4d038b53c16ee1b0947dddc4
MD5 hash:
1dcd74504d8668b3bc8298fd550c21bb
SHA1 hash:
9ba12c6ca232aecad4de1bd9a3c50453d3db03b7
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_PyInstaller
Author:Obscurity Labs LLC
Description:Detects PyInstaller compiled executables across platforms
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:PyInstaller
Author:@bartblaze
Description:Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments