76c07ebf7036fbee5f2916959c85c9616d679e031785a33eadba5c6db79f079a.bin
Classification: Malicious
76c07ebf7036fbee5f2916959c85c9616d679e031785a33eadba5c6db79f079a.bin is a malicious file sample. Linked to Netwire malware. Detected by 62 antivirus engines.
Detection summary
- 62 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 1 contacted hosts
- 3 DNS requests
MITRE ATT&CK associations
Malware families: NETWIRE (S0198)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-04-25 03:45:04 | 2026-04-25 06:45:07 | ||
| Netwire | Triage | 2026-04-25 03:09:50 | 2026-04-25 03:09:50 | malicious-activity | S0198 NETWIRE |
Tags
malicious trojan netwire warzonerat botnet discovery execution infostealer persistence rat stealerSample information
- Filenames
- 76c07ebf7036fbee5f2916959c85c9616d679e031785a33eadba5c6db79f079a.bin, x76c07ebf7036fbee5f2916959c85c9616d679e031785a33eadba5c6db79f079a.exe
- File type
- PE32 executable for MS Windows 5.01 (GUI), Intel i ...
- MD5
7823eb7d5eab462607525020fe16a2a8- SHA-1
a6251294f4dc2c28de388843e6b8ce66ba9f060b- SHA-256
76c07ebf7036fbee5f2916959c85c9616d679e031785a33eadba5c6db79f079a- First indexed
- 2026-04-25 03:09:50
- Last updated
- 2026-09-03 01:04:55
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Generic.39407064 |
| APEX | Malicious |
| AVG | Win32:MalwareX-gen [Rat] |
| Alibaba | TrojanSpy:Win32/NetWire.3bd96114 |
| Antiy-AVL | Trojan/Win32.NetWire |
| Arcabit | Trojan.Generic.D2594DD8 |
| Avast | Win32:MalwareX-gen [Rat] |
| Avira | TR/AVI.Agent.tfeey |
| BitDefender | Trojan.Generic.39407064 |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.netwire |
| ClamAV | Win.Trojan.Ulise-7135679-1 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.Wirenet.543 |
| ESET-NOD32 | Win32/Spy.Weecnaw.O trojan |
| Elastic | Windows.Trojan.Netwire |
| Emsisoft | Trojan.Generic.39407064 (B) |
| F-Secure | Trojan.TR/AVI.Agent.tfeey |
| Fortinet | AutoIt/Injector.DUY!tr |
| GData | Trojan.Generic.39407064 |
| Detected | |
| Gridinsoft | Trojan.Heur!.03006021 |
| Ikarus | Trojan-PSW.Delf |
| K7AntiVirus | Trojan ( 005c86201 ) |
| K7GW | Trojan ( 005c86201 ) |
| Kaspersky | Trojan.Win32.NetWire.bh |
| Kingsoft | Win32.Trojan.NetWire.bh |
| Lionic | Trojan.Win32.NetWire.4!c |
| Malwarebytes | Weecnaw.Spyware.Stealer.DDS |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfeeD | Trojan:Win/AveMaria.OX |
| MicroWorld-eScan | Trojan.Generic.39407064 |
| Microsoft | Trojan:Win32/NetWire.GMT!MTB |
| NANO-Antivirus | Trojan.Win32.Dapato.fbcjkw |
| Paloalto | generic.ml |
| Panda | Trj/Genetic.gen |
| Rising | Backdoor.NetWire!1.B84F (CLASSIC) |
| Sangfor | Virus.Win32.Save.a |
| Skyhigh | BehavesLike.Win32.Generic.th |
| Sophos | Troj/Netwire-MS |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.Win32.Autoit_new.404661 |
| Trapmine | malicious.high.ml.score |
| TrellixENS | Artemis!7823EB7D5EAB |
| TrendMicro | TSPY_WEECNAW.SMC |
| TrendMicro-HouseCall | TSPY_WEECNAW.SMC |
| VBA32 | BScope.TrojanSpy.Loyeetro |
| VIPRE | Trojan.Generic.39407064 |
| Varist | W32/Trojan.BIA.gen!Eldorado |
| ViRobot | Trojan.Win.Z.Netwire.1462050.X |
| VirIT | Backdoor.Win32.Wirenet.CCS |
| Webroot | W32.Backdoor.Gen |
| Xcitium | TrojWare.Win32.TrojanSpy.Loyeetro.A@8lofxp |
| Yandex | Trojan.GenAsa!wuPhUbOs0XU |
| ZoneAlarm | Mal/AuItInj-A |
| Zoner | Trojan.Win32.124944 |
| alibabacloud | Trojan:Win/Weecnaw |
| huorong | Trojan/Injector.blh |
| tehtris | Generic.Malware |
Network contacts
DNS requests
Wealthy2019.com.strangled.net wealth.warzonedns.com wealthyme.ddns.net