GridinSoft Threat Intelligence

Netwtw08.sys file report

Under review File reputation report
MD5 7d32728ccf51b40dda202a3a4e6f5b57
Latest seen 2021-01-03 05:25:57 (5 years ago)
First seen 2020-12-19 15:41:32 (5 years ago)
Size 8 MB
Publisher Intel Corporation

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2020-12-19 15:41:32 (5 years ago); latest analysis 2021-01-03 05:25:57 (5 years ago).

Publisher context

Company metadata: Intel Corporation. Product metadata: Intel® Wireless WiFi Link Adapter.

Digital signature

Signed by Intel Wireless Driver;Microsoft Windows Hardware Compatibility Publisher. The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

Netwtw08.sys is a Windows file recorded in the ThreatInfo database. It is associated with Intel® Wireless WiFi Link Adapter. The reported company name is Intel Corporation. The current detection status is Undefined, based on the latest analysis from 2021-01-03 05:25:57 (5 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: Intel® Wireless WiFi Link Adapter
Company Name: Intel Corporation
MD5: 7d32728ccf51b40dda202a3a4e6f5b57
Size: 8 MB
First Published: 2020-12-19 15:41:32 (5 years ago)
Latest Published: 2021-01-03 05:25:57 (5 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2021-01-03 05:25:57 (5 years ago)

The signature on Netwtw08.sys is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%system%\driverstore\filerepository
%system%

ThreatInfo has observed Netwtw08.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for Netwtw08.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

Netwtw08.sys is identified as pe for 64-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Native
Entry point 0x00057890
Image base 0x0000000140000000

PE Sections:

Sections 34
Raw data 8797184

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 4640768 bytes · 52.8% of section data
MD5 a2b641291140f6ae22ee0ad4f52521fc
.rdata 750592 bytes · 8.5% of section data
MD5 e6d77bb9f1832ee334719698abb80401
.data 319488 bytes · 3.6% of section data
MD5 46306fdd3314429a49b73298f9a2b005
.pdata 200704 bytes · 2.3% of section data
MD5 c98d229af53507b7c2d2fd7195237727
PAGEcsrv 68608 bytes · 0.8% of section data
Uncommon name
MD5 94918a7c6c88079e9de960a790d812d8
PAGE 6656 bytes · 0.1% of section data
Uncommon name
MD5 c9b5e171c815aac6a0284bb1d456c233
PAGEcjaw 77312 bytes · 0.9% of section data
Uncommon name
MD5 851c2b78d77543c987c89a2a80ee7607
PAGEcsec 512 bytes · 0.0% of section data
Uncommon name
MD5 146332e2228a961a409e01e940921431
PAGEcwfd 99840 bytes · 1.1% of section data
Uncommon name
MD5 2d46eb0131d5dbe862482c55ee09d587
PAGEccln 87040 bytes · 1.0% of section data
Uncommon name
MD5 a06aef05c8e0be53e5c19bea24e40cc6
PAGEcsv_ 41984 bytes · 0.5% of section data
Uncommon name
MD5 617b1de8265d7fa8a373ccad7848b629
PAGEcimg 11776 bytes · 0.1% of section data
Uncommon name
MD5 348f5dd2e88404f6c6493304d888e6c9
PAGEcctw 512 bytes · 0.0% of section data
Uncommon name
MD5 cf0701714441ebdd56b32b308eb71f6d
PAGEdoid 13824 bytes · 0.2% of section data
Uncommon name
MD5 ee3636ee7d1b0cbb1f7759f66bd40a29
PAGEdcln 4608 bytes · 0.1% of section data
Uncommon name
MD5 3013a40439e41c62082d600bfcc85ae2
PAGEdsv_ 4608 bytes · 0.1% of section data
Uncommon name
MD5 0121a761f8898bc0b19231b479af5349
PAGEdreg 260608 bytes · 3.0% of section data
Uncommon name
MD5 0f8a6b51aac3d052b6c9abaf82971bd8
PAGEdSnF 512 bytes · 0.0% of section data
Uncommon name
MD5 6bb311a1d7dc11122e9710b89fc4180c
PAGEdWsP 512 bytes · 0.0% of section data
Uncommon name
MD5 5f80133364656d13d8822b13dbf53af5
PAGEdPsr 1536 bytes · 0.0% of section data
Uncommon name
MD5 b31f6e31cd9984f7a0ceebbe677b66cd
PAGEdThP 512 bytes · 0.0% of section data
Uncommon name
MD5 ca00e289208f13f4902b3b9c84a1916c
PAGEdQua 1536 bytes · 0.0% of section data
Uncommon name
MD5 f19e180ed4b712270505dbb48a8f9c8b
PAGEdSun 1536 bytes · 0.0% of section data
Uncommon name
MD5 c676dc162841cafd65e9970d927e6c7c
PAGEdSlr 1536 bytes · 0.0% of section data
Uncommon name
MD5 c676dc162841cafd65e9970d927e6c7c
PAGEdCcl 1024 bytes · 0.0% of section data
Uncommon name
MD5 9ad567cb683d5bfaafc4a17abcb3d908
PAGEdSim 512 bytes · 0.0% of section data
Uncommon name
MD5 8700c89b3205de4a3c0ba31f2ae0eddd
PAGEdFpg 512 bytes · 0.0% of section data
Uncommon name
MD5 bb6f27a5749c7a97c289cfe24ae1dd3b
PAGEdSle 512 bytes · 0.0% of section data
Uncommon name
MD5 08b298f71ef6da0efc079dcbd38fbd33
PAGEdjaw 1024 bytes · 0.0% of section data
Uncommon name
MD5 738a536ca7e0d6ed8ed9b14b9194dee1
PAGEdimg 512 bytes · 0.0% of section data
Uncommon name
MD5 75bb75a495bd04a74923700c3850684a
PAGEdrlg 2097152 bytes · 23.8% of section data
Uncommon name
MD5 b2d1236c286a3c0704224fe4105eca49
INIT 6144 bytes · 0.1% of section data
Uncommon name
MD5 3cc3ad7c7d4c77ed0faf9a9f9e420516
.rsrc 47104 bytes · 0.5% of section data
MD5 1953a248ed5d9fd9a86c5fc807258b77
.reloc 45568 bytes · 0.5% of section data
MD5 2c77de4a901ebaf6dcb84beffb457cfa

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

This file is still under review

ThreatInfo has not assigned a final verdict yet. Compare the file hash, location, signature, and publisher before trusting the file on a production system.

Scan with GridinSoft Anti-Malware Use a local scan if the file origin or behavior is unclear. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with 7d32728ccf51b40dda202a3a4e6f5b57.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan if the source, path, or behavior looks unusual.