MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a5242c3e2661f04e61017cbb2eda4f8e1ae13ed7737a6e2e0eb278eb40cb81d9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetSupport


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: a5242c3e2661f04e61017cbb2eda4f8e1ae13ed7737a6e2e0eb278eb40cb81d9
SHA3-384 hash: 7cb4984ee67951e099e76e66f97400e3dabc526b76b5aacd2ccb4979df0498a2b7b1da20586f753da187ab8e5c3c9103
SHA1 hash: 3b62ba464f769096cce57800eba0b685eec18289
MD5 hash: 60b39f28c41cc8035edf6c0314e1dfcf
humanhash: jig-montana-hawaii-yankee
File name:notepad4331.js
Download: download sample
Signature NetSupport
File size:46'923 bytes
First seen:2023-07-08 08:27:11 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:PKWcsh4p0PqGBCgnSQRFmgY7Dz6RAunjulNc8+aLnqAIUGj1:PKWcS4cqGBCgnSQH1Yfz6RZ3Rin901
TLSH T19B2395CA33E6F811596723B23E57A2E6E53DAD81D4C898CCF051B84CF59CE2CF664648
Reporter abuse_ch
Tags:deperekanuki1-com deperekanuki2-com js NetSupport

Intelligence


File Origin
# of uploads :
1
# of downloads :
294
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated
Result
Verdict:
MALICIOUS
Threat name:
Script-JS.Backdoor.Heuristic
Status:
Malicious
First seen:
2023-07-07 12:58:34 UTC
File Type:
Text (JavaScript)
AV detection:
3 of 38 (7.89%)
Threat level:
  2/5
Result
Malware family:
netsupport
Score:
  10/10
Tags:
family:netsupport rat
Behaviour
Download via BitsAdmin
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
NetSupport
Malware Config
Dropper Extraction:
https://virvatulishop.eu/costa.zip
https://virvatulishop.eu/files/
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments