MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aba0f23ae3b752463217cbe7b2a9fe5657c88efb740bb42bedd8acb1ddc1028f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: aba0f23ae3b752463217cbe7b2a9fe5657c88efb740bb42bedd8acb1ddc1028f
SHA3-384 hash: 60ac4954b3e53a768794802d2b8271c3ebdb3ac627c64f7d6bf00cfc8f52d687c52f03c7c02cece34b34904aa561ebe9
SHA1 hash: 547348b035e08412e3966ad3d0f8e4ea861d7a1e
MD5 hash: 4df0f5f47b53a43078dfeedb91c833df
humanhash: march-robert-artist-river
File name:Payment Confirmation_PDF.img
Download: download sample
Signature NetWire
File size:4'063'232 bytes
First seen:2020-08-14 10:11:16 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 98304:q0vVZRS4k8Y/Do6bMwwnNKNooQoCIhQcBcm2:q0vVZRS4k8Y/Dydo8
TLSH C2165C66BC43729BF84704F00EC6D5E4B1EE352902B05A29AD53192EF90DE573CCE9B6
Reporter abuse_ch
Tags:img NetWire RAT


Avatar
abuse_ch
Malspam distributing NetWire:

HELO: sharedmail4.securehostdns.com
Sending IP: 202.66.173.169
From: NUTECH POLYMERS PVT. LTD <marketing@nutechpolymers.com>
Reply-To: result@hkcostarn.com
Subject: Payment Confirmation Clarification
Attachment: Payment Confirmation_PDF.img (contains "Payment Confirmation_PDF.scr")

NetWire RAT C2:
alkaline.publicvm.com:1777 (198.23.213.38)

Intelligence


File Origin
# of uploads :
1
# of downloads :
273
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-08-14 10:13:04 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

img aba0f23ae3b752463217cbe7b2a9fe5657c88efb740bb42bedd8acb1ddc1028f

(this sample)

  
Dropping
NetWire
  
Delivery method
Distributed via e-mail attachment

Comments