General

  • Target

    8fb7ba35ba5fb5f59a4c6eb8edd8aef3d45492898640dee3488fbb8880d0bc56

  • Size

    1.3MB

  • MD5

    9d891a8f4f11245ccd5c4fa5f51b0f14

  • SHA1

    e970b504704bfdb452a287e5e16734dd516fbcde

  • SHA256

    8fb7ba35ba5fb5f59a4c6eb8edd8aef3d45492898640dee3488fbb8880d0bc56

  • SHA512

    5a7c4602b09bb0c9ccc0dea3f637c266a9559c7d6d169899c6f610def0acd8b3486007074ccf6ed4a945928509d589811c1c581bfb4270fc0e67c8514f7e01e8

  • SSDEEP

    24576:Ku6J33O0c+JY5UZ+XC0kGso6Fa720W4njUprvVcC1f2o5RRfgUWYZ:8u0c++OCvkGs9Fa+rd1f26RaYZ

Score
10/10

Malware Config

Signatures

  • NetWire RAT payload 1 IoCs
  • Netwire family
  • AutoIT Executable 1 IoCs

    AutoIT scripts compiled to PE executables.

  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 8fb7ba35ba5fb5f59a4c6eb8edd8aef3d45492898640dee3488fbb8880d0bc56
    .exe windows:5 windows x86 arch:x86

    eb97e4fc5518ac300a92a11673825e0b


    Headers

    Imports

    Sections