🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 731fd579215854a21fecfef924ec88ba75601ca0348eb85b63b871a6722ecbf7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NWHStealer


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 731fd579215854a21fecfef924ec88ba75601ca0348eb85b63b871a6722ecbf7
SHA3-384 hash: 1d731fc213c081832bd3e90357d0c8a5d268962607122a211c7b509be4a1d1a8f74cce2503ea4d9f98cfd495c9a39492
SHA1 hash: 0e494b824241842973a611c4cc0cac53e917f1c1
MD5 hash: a5ac42ca614a490edb564dd11817c9a0
humanhash: freddie-autumn-virginia-juliet
File name:file
Download: download sample
Signature NWHStealer
File size:97'978'368 bytes
First seen:2026-09-29 01:09:04 UTC
Last seen:2026-09-29 01:10:23 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash fd6f6d07cc33ee9a2b65bda58a07bb94 (19 x NWHStealer)
ssdeep 1572864:WZa7hmguP2nG0/Vyv7UhgxIabc/97Awb0:WZa7hmguP2nUOTAwb0
TLSH T198286C43A2E751D8F0BBD17496E65323E933BC490B3469EF12944B312F72AE0A779B11
TrID 55.7% (.WLX) Total Commander Lister extension (plugin) (21500/1/6)
16.9% (.EXE) Win64 Executable (generic) (6522/11/2)
11.6% (.EXE) Win32 Executable (generic) (4504/4/1)
5.2% (.EXE) OS/2 Executable (generic) (2029/13)
5.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 9170cc9296cc7001 (19 x NWHStealer, 1 x XWorm)
Reporter Bitsight
Tags:54e64e dropped-by-amadey exe NWHStealer


Avatar
Bitsight
url: http://91.92.242.236/files-129312398/files/file_7c23b7b64f4c1870.exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
195
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-29 01:24:32 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
DNS request
Connection attempt
Sending a custom TCP request
Connection attempt to an infection source
Launching a process
Creating a window
Query of malicious DNS domain
Sending a TCP request to an infection source
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug fingerprint obfuscated overlay packed reconnaissance rust
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-28T23:35:00Z UTC
Last seen:
2026-09-30T08:39:00Z UTC
Hits:
~10
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Enumerates system info in registry
Reads the TCP/IP host and domain name from the registry
Enumerates connected drives
Maps connected drives based on registry
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

NWHStealer

Executable exe 731fd579215854a21fecfef924ec88ba75601ca0348eb85b63b871a6722ecbf7

(this sample)

  
Dropped by
Amadey
  
Delivery method
Distributed via web download

Comments