MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f29b766cdda03589257301ac3cb44d7bbafbd2e16835b424715869b701ee6288. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetWire


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f29b766cdda03589257301ac3cb44d7bbafbd2e16835b424715869b701ee6288
SHA3-384 hash: 95543f16ba0aa8cd04fbb8e174e0138b7e11b426baafb1cdf6d1ae059fdc79f75fd912dd1a5365efdd1757bffc384541
SHA1 hash: 4a90d5e4ec56770b74ef76e2e4952be6374af5aa
MD5 hash: 2c98557dc9bc1836e11e16d252161ded
humanhash: potato-finch-salami-west
File name:Discount Offer From oceanbd@aptctg_com.img
Download: download sample
Signature NetWire
File size:2'621'440 bytes
First seen:2020-11-06 07:14:38 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 3072:+FiSY3Y/IVHoKMf/G395YL4LtlPdU+w4gkmiuHR6qbZd3E3cD5sCVDdSFjWJ5Jc/:2iSYo/MstvLGyELbMUTKZ
TLSH 89C57A22A0B67F2CE2C335B7342086758FFDFC66416DAE44D2D17A71BD92D2919B031A
Reporter abuse_ch
Tags:img NetWire RAT


Avatar
abuse_ch
Malspam distributing NetWire:

HELO: slot0.barblcas.com
Sending IP: 185.144.28.202
From: oceanbd_aptctg.com <oceanbd@aptctg.com>
Reply-To: oceanbd_aptctg.com <barblcas@rhinotank-tr.site>
Subject: Discount Offer from aptctg.com
Attachment: Discount Offer From oceanbd@aptctg_com.img (contains "Discount Offer From oceanbd@aptctg_com.exe")

NetWire RAT C2:
alkaline.publicvm.com:1177

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NetWiredRc
Status:
Malicious
First seen:
2020-11-06 06:50:11 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NetWire

img f29b766cdda03589257301ac3cb44d7bbafbd2e16835b424715869b701ee6288

(this sample)

  
Dropping
NetWire
  
Delivery method
Distributed via e-mail attachment

Comments