MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 74178276aaa12c81f17a7f95747c5595cb41e45147a342a06d23b373e8ad7ceb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetSupport


Vendor detections: 4


Intelligence 4 IOCs 1 YARA File information Comments

SHA256 hash: 74178276aaa12c81f17a7f95747c5595cb41e45147a342a06d23b373e8ad7ceb
SHA3-384 hash: 18d40e0dc72a6a272c578ab5bb7db03f67ec3c3abaafa898bb5ff0fb959095e61d936eb1fba079764e8b740211f01d4e
SHA1 hash: 7c73d7783441d0457a9c48cc76cf337af84c367c
MD5 hash: 701a3f2d613092afcd177b491e1fb843
humanhash: delaware-oven-echo-helium
File name:booking.ps1
Download: download sample
Signature NetSupport
File size:39 bytes
First seen:2026-03-17 10:30:30 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 3:WIJmcLIQxdTzZFM4:WIocnu4
TLSH TNULL
Magika txt
Reporter JAMESWT_WT
Tags:booking ClickFix FakeCaptcha NetSupport ps1

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
152.89.244.70:443 https://threatfox.abuse.ch/ioc/1769070/

Intelligence


File Origin
# of uploads :
1
# of downloads :
107
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
97.4%
Tags:
vmdetect autorun netsup madi
Gathering data
Result
Malware family:
netsupport
Score:
  10/10
Tags:
family:netsupport discovery execution rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
System Location Discovery: System Language Discovery
Drops startup file
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Downloads MZ/PE file
NetSupport
Netsupport family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments