MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cd1675dfc58d83207ba48ecb51207feb63aaac4fb4355c8eb49505dcfaea562b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetSupport


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: cd1675dfc58d83207ba48ecb51207feb63aaac4fb4355c8eb49505dcfaea562b
SHA3-384 hash: ce062d9ed49ca4239eb02b5c516ea1be2f1bcffd5c4bdb08f821ae833ac5cd7b7acc2d065619cc68d52e04f7a4257a1f
SHA1 hash: 74940a0ac2f298153376e48745ff1b3ab03c54bd
MD5 hash: 4a25c0fdb8364340222e697da995093b
humanhash: nevada-magazine-lima-muppet
File name:WinSupportUp.zip
Download: download sample
Signature NetSupport
File size:2'263'645 bytes
First seen:2022-07-26 08:24:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:DvzA85waN88kAFRHhzoC+B4zxUzQhNxTXT:DvN6aKl0HhzH849UzsLT
TLSH T135A533B93EC534E3DC1A3532F1FD5284626CBD3196D5912BD356EE718827EA233884E2
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter srujankumar_k
Tags:NetSupport zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
201
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
overlay packed remoteadmin
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.NetSup
Status:
Malicious
First seen:
2022-07-26 08:25:19 UTC
File Type:
Binary (Archive)
Extracted files:
455
AV detection:
6 of 40 (15.00%)
Threat level:
  5/5
Result
Malware family:
netsupport
Score:
  10/10
Tags:
family:netsupport rat
Behaviour
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via drive-by

Comments