MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e1452a3d543a3c2faa74e005c031144c95c79e0cae866d8f4a9453915180354. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6e1452a3d543a3c2faa74e005c031144c95c79e0cae866d8f4a9453915180354
SHA3-384 hash: 16b029c07576f6bd8aef92d4aa259a1cdaddb2c5391c40895d603532bdf50f44d0d85e9139d618963472fe851d4ef92a
SHA1 hash: 4483f9bcb7c5018149be0c3ac98998297d16047b
MD5 hash: 8e1b97a6e3ec72b6b53352e2da79f507
humanhash: london-bluebird-mockingbird-lithium
File name:RFQ List 13052020.zip
Download: download sample
Signature NetWire
File size:505'661 bytes
First seen:2020-05-13 18:40:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Xxg7rwK+8ilKGyKgWrXLDt7XBkFSA3MUBcnl9aWONVqmVb:BqsKcQGrhXLDtbjZQEqVqg
TLSH 66B423D1DC09E2A44D51CD7A6DC2DD602E46C1F283AC2494B6EFA18F2A277F246DDD70
Reporter jarumlus
Tags:NetWire

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-14 04:36:45 UTC
File Type:
Binary (Archive)
Extracted files:
295
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

zip 6e1452a3d543a3c2faa74e005c031144c95c79e0cae866d8f4a9453915180354

(this sample)

  
Dropped by
NetWire
  
Delivery method
Distributed via e-mail attachment

Comments