🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4b2cfa2a3d348c8a316186ad65d0554804e9c87d7dc4a9d85a714ab9e9f037f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 20


Intelligence 20 IOCs YARA 11 File information Comments

SHA256 hash: e4b2cfa2a3d348c8a316186ad65d0554804e9c87d7dc4a9d85a714ab9e9f037f
SHA3-384 hash: b0ac9bd0032156040a942a9b4aa3f0d69bcf2f968f4aae960059d0a8d0e50582142b74d54763ed27a852f9e03ecd7fdd
SHA1 hash: 3262b85236a171685d71a01b0b74f902bb60823a
MD5 hash: c464d743248ede83c611a5e7b7e318ee
humanhash: snake-butter-arkansas-timing
File name:Host.exe
Download: download sample
Signature NetWire
File size:64'512 bytes
First seen:2026-05-21 11:41:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 88b0919ed28ca0b55b54bf4d61eef789 (2 x NetWire)
ssdeep 1536:wrxauuIvLJ8gNoWhVDkKrCy+wFqcyPeiBT29nh:fIv18So4IKmy+XPeiBeh
TLSH T1A053E61AF60BE0F2ED5D0A3121CFF5EF47357930E8398F48EB890D01EA639566219B95
TrID 38.7% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.5% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
8.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
8.0% (.EXE) Win64 Executable (generic) (6522/11/2)
6.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
Reporter Anonymous
Tags:exe NetWire

Intelligence


File Origin
# of uploads :
1
# of downloads :
168
Origin country :
BE BE
Vendor Threat Intelligence
No detections
Malware family:
netwire
ID:
1
File name:
Host.exe
Verdict:
Malicious activity
Analysis date:
2026-05-21 04:37:32 UTC
Tags:
netwire

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
netwiredrc autorun
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %AppData% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Сreating synchronization primitives
Creating a window
DNS request
Connection attempt
Launching a service
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug backdoor cmd crypto evasive keylogger lolbin mingw packed rat rat reconnaissance stealer
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-21T08:48:00Z UTC
Last seen:
2026-05-22T19:58:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.NetWire.sb Trojan-PSW.Win32.Stealer.sb HEUR:Trojan.Win32.Generic Backdoor.Win32.NetWiredRC.aue
Gathering data
Threat name:
Win32.Backdoor.NetWire
Status:
Malicious
First seen:
2026-05-21 11:42:27 UTC
File Type:
PE (Exe)
AV detection:
22 of 24 (91.67%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
netwirerc
Similar samples:
Result
Malware family:
netwire
Score:
  10/10
Tags:
family:netwire botnet discovery persistence rat stealer
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Adds Run key to start application
Checks computer location settings
Deletes itself
Executes dropped EXE
Boot or Logon Autostart Execution: Active Setup
Family: Netwire
NetWire RAT payload
Malware Config
C2 Extraction:
myany.gb.net:3360
www.myany.gb.net:3360
Unpacked files
SH256 hash:
e4b2cfa2a3d348c8a316186ad65d0554804e9c87d7dc4a9d85a714ab9e9f037f
MD5 hash:
c464d743248ede83c611a5e7b7e318ee
SHA1 hash:
3262b85236a171685d71a01b0b74f902bb60823a
Detections:
win_netwire_w0 win_netwire_auto win_netwire_g0 triage_netwire_rat
Malware family:
NetWiredRC
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CredentialStealer_Generic_Backdoor
Author:Florian Roth (Nextron Systems)
Description:Detects credential stealer byed on many strings that indicate password store access
Reference:Internal Research
Rule name:CredentialStealer_Generic_Backdoor_RID347C
Author:Florian Roth
Description:Detects credential stealer byed on many strings that indicate password store access
Reference:Internal Research
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:malware_netwire_strings
Author:JPCERT/CC Incident Response Group
Description:detect netwire in memory
Reference:internal research
Rule name:netwire
Author:JPCERT/CC Incident Response Group
Description:detect netwire in memory
Reference:internal research
Rule name:NetWiredRC_B
Author:Jean-Philippe Teissier / @Jipe_
Description:NetWiredRC
Rule name:RAT_NetWire
Author:Kevin Breen <kevin@techanarchy.net> & David Cannings
Description:Detects NetWire RAT
Reference:http://malwareconfig.com/stats/NetWire
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_Netwire_1b43df38
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/netwire-dynamic-configuration-extraction
Rule name:win_netwire_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.netwire.
Rule name:win_netwire_w0
Author:Jean-Philippe Teissier / @Jipe_
Description:NetWiredRC

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments