MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e1bbd47f49839b0b992752ec82aa83054b38a5a946304b49bff53b74af00a49b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
NetWire
Vendor detections: 4
| SHA256 hash: | e1bbd47f49839b0b992752ec82aa83054b38a5a946304b49bff53b74af00a49b |
|---|---|
| SHA3-384 hash: | a860bade9fc8c15c191c83cbb779269260b1cd1cb52d397306474859b89ff36c3188d2dd05028b4ba9197e8afd68709b |
| SHA1 hash: | 7b62b59d9b956ae07212c01687b8491a6369114c |
| MD5 hash: | c0ff14c546e21d5425e30aed88feab1e |
| humanhash: | papa-pennsylvania-asparagus-muppet |
| File name: | Proof of Payment.img |
| Download: | download sample |
| Signature | NetWire |
| File size: | 1'507'328 bytes |
| First seen: | 2021-01-15 07:21:04 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:lUeaElE9Yt9gusNqdRZ0MQCC+B5nXEnLRxBF1IYPLfESTbxNy:lUellzt9g5cnQIvnXEnLrBYNSTK |
| TLSH | C2658D7C277BBA4CD0791AB60EE1592707623D0624F8C61E1CDD7ECA0676B401DA9EB3 |
| Reporter | |
| Tags: | img NetWire RAT |
abuse_ch
Malspam distributing NetWire:HELO: infinitymail.dedicated.co.za
Sending IP: 154.0.174.127
From: NedBank <Notification@nedbank.co.za>
Reply-To: No-reply@nedbank.co.za
Subject: Payment Notification
Attachment: Proof of Payment.img (contains "Proof of Payment.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
282
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-15 07:21:28 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
NetWire
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.