MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 68e1b0c8a841409963a7681a3d164b737ab3f051cfa1de3ef9a9ac3e4d499452. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 68e1b0c8a841409963a7681a3d164b737ab3f051cfa1de3ef9a9ac3e4d499452
SHA3-384 hash: f0e4c374e7e65b65944674370f6225c36306b5dde64d83980a72a4b69973e0f7ed4f6dab3d896f1fcf56a8e0e1e4acaa
SHA1 hash: 67ceedd4631831ee558e2cf3ecfa952120511105
MD5 hash: d54b0b5bb775223d447f20943250b825
humanhash: september-orange-undress-ack
File name:DEALER REQUIREMENT.pdf.zip
Download: download sample
Signature NetWire
File size:391'554 bytes
First seen:2020-06-26 15:38:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:KMKfoV/AqVaKjrBmdA3AbvwFdNxgKSOm1xtYeVo6KJYkKrgcIXm/oPXGXr2n:BRAwBmq3GUdAKpm10vluimiG72
TLSH 95842394F46E701BF2070923D073B82316DB89FB197896DFA48145A9FE1FA7F90D2609
Reporter abuse_ch
Tags:MailChannels NetWire nVpn RAT zip


Avatar
abuse_ch
Malspam distributing NetWire:

HELO: bisque.elm.relay.mailchannels.net
Sending IP: 23.83.212.18
From: Okopi Amedu <Okopi.Amedu@ng.multichoice.com>
Subject: SUPER DEALER AND BRANDED STORES
Attachment: DEALER REQUIREMENT.pdf.zip (contains "DEALER REQUIREMENT.pdf.exe")

NetWire RAT C2:
indigo22.ddns.net:3478 (79.134.225.69)

Pointing to nVpn:

% Information related to '79.134.225.64 - 79.134.225.127'

% Abuse contact for '79.134.225.64 - 79.134.225.127' is 'abuse@your-vpn.network'

inetnum: 79.134.225.64 - 79.134.225.127
netname: YOUR_VPN_NETWORK
country: DE
remarks: ****************************************************
remarks: This subnet belongs to a VPN service provider.
remarks: We protect the right to privacy, which means
remarks: we don't log the activities of our users.
remarks: ****************************************************
admin-c: EH4074-RIPE
tech-c: YVN10-RIPE
status: ASSIGNED PA
abuse-c: YVN10-RIPE
org: ORG-YVN1-RIPE
mnt-by: AF15-MNT
created: 2019-07-19T18:26:38Z
last-modified: 2019-07-19T18:51:28Z
source: RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
102
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Delf
Status:
Malicious
First seen:
2020-06-26 15:40:06 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

zip 68e1b0c8a841409963a7681a3d164b737ab3f051cfa1de3ef9a9ac3e4d499452

(this sample)

  
Dropping
NetWire
  
Delivery method
Distributed via e-mail attachment

Comments