MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1bbd47f49839b0b992752ec82aa83054b38a5a946304b49bff53b74af00a49b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e1bbd47f49839b0b992752ec82aa83054b38a5a946304b49bff53b74af00a49b
SHA3-384 hash: a860bade9fc8c15c191c83cbb779269260b1cd1cb52d397306474859b89ff36c3188d2dd05028b4ba9197e8afd68709b
SHA1 hash: 7b62b59d9b956ae07212c01687b8491a6369114c
MD5 hash: c0ff14c546e21d5425e30aed88feab1e
humanhash: papa-pennsylvania-asparagus-muppet
File name:Proof of Payment.img
Download: download sample
Signature NetWire
File size:1'507'328 bytes
First seen:2021-01-15 07:21:04 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:lUeaElE9Yt9gusNqdRZ0MQCC+B5nXEnLRxBF1IYPLfESTbxNy:lUellzt9g5cnQIvnXEnLrBYNSTK
TLSH C2658D7C277BBA4CD0791AB60EE1592707623D0624F8C61E1CDD7ECA0676B401DA9EB3
Reporter abuse_ch
Tags:img NetWire RAT


Avatar
abuse_ch
Malspam distributing NetWire:

HELO: infinitymail.dedicated.co.za
Sending IP: 154.0.174.127
From: NedBank <Notification@nedbank.co.za>
Reply-To: No-reply@nedbank.co.za
Subject: Payment Notification
Attachment: Proof of Payment.img (contains "Proof of Payment.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
282
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-15 07:21:28 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

img e1bbd47f49839b0b992752ec82aa83054b38a5a946304b49bff53b74af00a49b

(this sample)

  
Dropping
NetWire
  
Delivery method
Distributed via e-mail attachment

Comments