x75059acbe335e1941fa86f8359165592e3474aa03963fab11777a5d2d33130a0.exe
Classification: Malicious
x75059acbe335e1941fa86f8359165592e3474aa03963fab11777a5d2d33130a0.exe is a malicious file sample. Linked to Netwire malware. Detected by 35 antivirus engines.
Detection summary
- 35 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 1 contacted hosts
- 3 DNS requests
MITRE ATT&CK associations
Malware families: NETWIRE (S0198)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-05-25 02:45:03 | 2026-05-25 02:45:03 | ||
| Netwire | Triage | 2026-05-25 02:36:39 | 2026-05-25 02:36:39 | malicious-activity | S0198 NETWIRE |
Tags
malicious netwire warzonerat botnet discovery execution infostealer persistence rat stealerSample information
- Filenames
- x75059acbe335e1941fa86f8359165592e3474aa03963fab11777a5d2d33130a0.exe, 75059acbe335e1941fa86f8359165592e3474aa03963fab11777a5d2d33130a0.bin
- File type
- PE32 executable for MS Windows 5.01 (GUI), Intel i ...
- MD5
e268cde418b00b1509cfdbca6600ed98- SHA-1
f04db41ada007cc37255bd8932136b57a836de36- SHA-256
75059acbe335e1941fa86f8359165592e3474aa03963fab11777a5d2d33130a0- First indexed
- 2026-05-25 02:36:39
- Last updated
- 2026-09-02 12:00:47
Antivirus detections
| Engine | Detection |
|---|---|
| APEX | Malicious |
| Alibaba | TrojanSpy:Win32/NetWire.ce7b80ba |
| Antiy-AVL | Trojan/Win32.NetWire |
| Avira | TR/Spy.Gen |
| Bkav | W32.Malware.6DBA1EF2 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| Elastic | Windows.Trojan.Netwire |
| F-Secure | Trojan.TR/Spy.Gen |
| Detected | |
| Gridinsoft | Trojan.Heur!.03006021 |
| Ikarus | Trojan-PSW.Delf |
| K7AntiVirus | Trojan ( 005c86201 ) |
| K7GW | Trojan ( 005c86201 ) |
| Kingsoft | Win32.Trojan.NetWire.bh |
| Lionic | Trojan.Win32.NetWire.4!c |
| Malwarebytes | Weecnaw.Spyware.Stealer.DDS |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfeeD | Trojan:Win/AveMaria.OX |
| MicroWorld-eScan | Trojan.Generic.39506427 |
| Microsoft | Trojan:Win32/NetWire!pz |
| Paloalto | generic.ml |
| Sangfor | Virus.Win32.Save.a |
| Tencent | Trojan.Win32.Autoit_new.404661 |
| Trapmine | malicious.high.ml.score |
| TrendMicro | TSPY_WEECNAW.SMC |
| TrendMicro-HouseCall | TSPY_WEECNAW.SMC |
| ViRobot | Trojan.Win.Z.Netwire.1461058.BP |
| VirIT | Backdoor.Win32.Wirenet.CCS |
| Webroot | W32.Backdoor.Gen |
| Zoner | Trojan.Win32.124944 |
| alibabacloud | Trojan:Win/Weecnaw |
| huorong | Trojan/Injector.blh |
| tehtris | Generic.Malware |
Network contacts
DNS requests
Wealthy2019.com.strangled.net wealth.warzonedns.com wealthyme.ddns.net