MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 67b10001ec5c141e48e61d73c2c4d8c2c1170eecfbe8732ea5b3069d6cd333b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 15


Intelligence 15 IOCs 1 YARA 4 File information Comments

SHA256 hash: 67b10001ec5c141e48e61d73c2c4d8c2c1170eecfbe8732ea5b3069d6cd333b0
SHA3-384 hash: 757f77690603654f1b6801a1352a074cb99523df0479bf8f7f35793e05981df984bc0a77d2bcb3b682a2a817e3f1fe3f
SHA1 hash: f98e3e3a0f5fc735f7167367fa272b5365595548
MD5 hash: 3f153b9bfc044bb0c370cabd0496c8a6
humanhash: july-tennis-lion-pluto
File name:3f153b9bfc044bb0c370cabd0496c8a6.exe
Download: download sample
Signature NetWire
File size:1'105'048 bytes
First seen:2022-09-29 20:31:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash fcf1390e9ce472c7270447fc5c61a0c1 (907 x DCRat, 118 x NanoCore, 94 x njrat)
ssdeep 24576:MAOcZXgZd9/37Y0W8AHei8Jluw0ixrZYZj7w84cKSVlioyvt1qztey4ZodO:a3X7DLJYLilZYZjUcKsscey4Z7
Threatray 1'949 similar samples on MalwareBazaar
TLSH T1C8351221B7F2C872D0771930393966156D7D78201F2BEADEB3A409EDEE771912124BA3
TrID 91.0% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
3.6% (.EXE) Win64 Executable (generic) (10523/12/4)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
1.5% (.EXE) Win32 Executable (generic) (4505/5/1)
0.6% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 30e2d0a8d2d8e830 (3 x NetWire)
Reporter abuse_ch
Tags:exe NetWire RAT


Avatar
abuse_ch
NetWire C2:
212.193.30.230:3368

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
212.193.30.230:3368 https://threatfox.abuse.ch/ioc/858553/

Intelligence


File Origin
# of uploads :
1
# of downloads :
286
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
netwire
ID:
1
File name:
3f153b9bfc044bb0c370cabd0496c8a6.exe.vir
Verdict:
Malicious activity
Analysis date:
2022-09-30 02:52:49 UTC
Tags:
autoit trojan netwire

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file in the %AppData% subdirectories
Enabling the 'hidden' option for recently created files
Creating a process from a recently created file
Creating a file
Sending a custom TCP request
Adding an access-denied ACE
Launching a process
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Unauthorized injection to a system process
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
EvasionQueryPerformanceCounter
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware overlay packed setupapi.dll shdocvw.dll shell32.dll
Result
Threat name:
NetWire
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Drops PE files with a suspicious file extension
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: NetWire
Writes to foreign memory regions
Yara detected AntiVM autoit script
Yara detected NetWire RAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 713043 Sample: NyLJAI1P9J.exe Startdate: 29/09/2022 Architecture: WINDOWS Score: 100 39 Multi AV Scanner detection for domain / URL 2->39 41 Malicious sample detected (through community Yara rule) 2->41 43 Antivirus detection for URL or domain 2->43 45 6 other signatures 2->45 7 NyLJAI1P9J.exe 68 2->7         started        11 iblekdu.pif 1 2->11         started        13 iblekdu.pif 2->13         started        15 iblekdu.pif 2->15         started        process3 file4 27 C:\Users\user\AppData\Roaming\...\iblekdu.pif, PE32 7->27 dropped 47 Drops PE files with a suspicious file extension 7->47 17 iblekdu.pif 1 2 7->17         started        49 Writes to foreign memory regions 11->49 51 Allocates memory in foreign processes 11->51 53 Injects a PE file into a foreign processes 11->53 20 RegSvcs.exe 11->20         started        22 RegSvcs.exe 13->22         started        signatures5 process6 signatures7 31 Antivirus detection for dropped file 17->31 33 Multi AV Scanner detection for dropped file 17->33 35 Writes to foreign memory regions 17->35 37 2 other signatures 17->37 24 RegSvcs.exe 2 17->24         started        process8 dnsIp9 29 212.193.30.230, 3368 SPD-NETTR Russian Federation 24->29
Threat name:
Win32.Backdoor.NetWiredRc
Status:
Malicious
First seen:
2022-09-26 00:32:34 UTC
File Type:
PE (Exe)
Extracted files:
394
AV detection:
22 of 26 (84.62%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
d03069a01f3d3a4562284fec1e2e2fc381e9d4d7907689f29101148e2de73388
MD5 hash:
21db7c8be358e75b21fe651fcf7cafb9
SHA1 hash:
819319e675f460057c4982d0819d217e3f88db1c
Detections:
Netwire win_netwire_g1
SH256 hash:
12a30aefbd01da12f2721125f5a1b656573e1388f3ccf78495dfa4a8437757c2
MD5 hash:
b92d9c1519befad3a014ca94795fd568
SHA1 hash:
7b43c372973ff91d17131f9329cd2af271bab4d8
SH256 hash:
67b10001ec5c141e48e61d73c2c4d8c2c1170eecfbe8732ea5b3069d6cd333b0
MD5 hash:
3f153b9bfc044bb0c370cabd0496c8a6
SHA1 hash:
f98e3e3a0f5fc735f7167367fa272b5365595548
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pdb_YARAify
Author:@wowabiy314
Description:PDB
Rule name:RansomwareTest8
Author:Daoyuan Wu
Description:Test Ransomware YARA rules
Rule name:sfx_pdb
Author:@razvialex
Description:Detect interesting files containing sfx with pdb paths.
Rule name:sfx_pdb_winrar_restrict
Author:@razvialex
Description:Detect interesting files containing sfx with pdb paths.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments