MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6887fa9f10ad20a3a78cd33335a065ac9266cd2709ffa56d9f60877cbf3170a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6887fa9f10ad20a3a78cd33335a065ac9266cd2709ffa56d9f60877cbf3170a6
SHA3-384 hash: 74c14a7e192f48628e254e33ab015d4cc609c80e69066d4847a9abe8644c282c74224d6012c64b18bde494ae4c305298
SHA1 hash: b7eccb1ae13ec3eaf7b568535c5d4b1540ef6a85
MD5 hash: c27bbc3c8d5b15546356fbc7412dde5d
humanhash: purple-nebraska-cardinal-helium
File name:ransomware netwalker.ps1
Download: download sample
File size:930'839 bytes
First seen:2020-07-10 09:26:10 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 12288:n/TyqBmx5ScFCGNs0pdHj3+4Kzzf6RCscFIIJVHVAPoECDLiPVtDi4JX4o/0Q6I9:e
TLSH 3A15A5D37A72A64F00454B72394916F6C8AECF05C6CB6145B88CEAAEF1DCD763589BC0
Reporter JAMESWT_WT
Tags:NetWalker Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
2'503
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-PowerShell.Ransomware.Netwalker
Status:
Malicious
First seen:
2020-06-26 19:02:44 UTC
File Type:
Text (PowerShell)
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments