MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b0c22fa717eb03d14472427b1ecff6dc206951b78bf319111cbf3fde5ba916f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7b0c22fa717eb03d14472427b1ecff6dc206951b78bf319111cbf3fde5ba916f
SHA3-384 hash: 05c8efbea662fc4abae03b0599eb70c52669653c7f1ca1dcc3ca65bbaed64e69690f50f4aeb748ef5815bf9490d28518
SHA1 hash: 6cd912d092436a4b20a0d3004ea6950d6a6b8f67
MD5 hash: b64f165b820a627b137d5690f8c8ed9d
humanhash: crazy-november-crazy-lake
File name:January remittance advice.exe
Download: download sample
Signature NetWire
File size:49'152 bytes
First seen:2020-04-27 23:10:29 UTC
Last seen:2020-04-27 23:55:54 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e27b875e96989c5fc0561ce18d0431bb (1 x NetWire)
ssdeep 768:QH/80iDpngm6fd5KZGoiXcoTNdSCmUS1:S/knL1tiXcINdpml
Threatray 127 similar samples on MalwareBazaar
TLSH D523D6139E742132EC0D7A711A5577788039EBFB194CF4879AF03B18A9E4BDA68C2707
Reporter c_APT_ure
Tags:NetWire

Intelligence


File Origin
# of uploads :
2
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaSetSystemError
MSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments