MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ab6edf67b90c3a7dee2674be1a28bfdab79a6bad05cec53b344aec3ac69113b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments 1

SHA256 hash: 8ab6edf67b90c3a7dee2674be1a28bfdab79a6bad05cec53b344aec3ac69113b
SHA3-384 hash: 67b9835ab93a567a9acf4a1a76e217fc5578654c305c23c6138ed0a948e40ebbf1dd5971a078091544ffe41abf6e37c0
SHA1 hash: 44c17ef5a76a85ba2cbe2295daa0ff421766f5ed
MD5 hash: b856fe90b38b0f029898dcca8e979b16
humanhash: oscar-charlie-yellow-lake
File name:b856fe90b38b0f029898dcca8e979b16.exe
Download: download sample
Signature NetWire
File size:31'491 bytes
First seen:2021-04-23 06:13:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 384:/xXdPmL7S3B8dBQeTPojFm3f3fCKiKSKBZhJhJhE8E80sz7zbTr+9IIGXdKwzW6G:5teL+ad9EjFrIIGXO6G8TSwInU4BFt
TLSH 9DE2F8265AF80F74F0B64B710AF281359B23B8769E92CF6710893E1D1E35980DD52B7A
Reporter abuse_ch
Tags:exe NetWire RAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
422
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
b856fe90b38b0f029898dcca8e979b16.exe
Verdict:
No threats detected
Analysis date:
2021-04-23 06:23:12 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Raccoon Stealer
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
Machine Learning detection for sample
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Graftor
Status:
Malicious
First seen:
2021-04-23 06:14:09 UTC
AV detection:
11 of 47 (23.40%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
8ab6edf67b90c3a7dee2674be1a28bfdab79a6bad05cec53b344aec3ac69113b
MD5 hash:
b856fe90b38b0f029898dcca8e979b16
SHA1 hash:
44c17ef5a76a85ba2cbe2295daa0ff421766f5ed
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

NetWire

Executable exe 8ab6edf67b90c3a7dee2674be1a28bfdab79a6bad05cec53b344aec3ac69113b

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-04-23 07:17:45 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [C0026.002] Data Micro-objective::XOR::Encode Data