MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 34e4e7e93772ae641e3af2bb6024a416bc008845822a3a54733003ab308c5fad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 34e4e7e93772ae641e3af2bb6024a416bc008845822a3a54733003ab308c5fad
SHA3-384 hash: 6a485191456398a94d91658534d0d5ff2d034a2e8d0f5402fa1aad549270949a4b650f5bad8970bae6722fa23df5ad0f
SHA1 hash: 4d99e9cfaab9b76632c9c1db29d74693e6238982
MD5 hash: c5b765cd8b6cc1a0150ee343bf6ffe46
humanhash: fruit-nine-quiet-orange
File name:PO763g.rar
Download: download sample
Signature NanoCore
File size:757'200 bytes
First seen:2020-06-15 05:43:58 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:X/x/7mcxP+6CYw9Ociw8xAcPgM9j3VZEg9g0aMxwqo4MSZgRbaTpqCf5NJfOljP5:X/nhKOPgEjz601xwqo4Mx0T5ONPKZ5tc
TLSH DBF4339BC032B4EC115C89D6B2C8759D57980DE1A74E464CE4230A3EDFEAB448CDEE5B
Reporter abuse_ch
Tags:NanoCore nVpn rar RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: server0.web-login.xyz
Sending IP: 192.236.179.151
From: Thao <thaontn@hansollvina.com>
Subject: PO#763g
Attachment: PO763g.rar (contains "PO#763g.exe")

NanoCore RAT C2:
infit.ddns.net:1989 (172.93.161.53)

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Backdoor.NanoBot
Status:
Malicious
First seen:
2020-06-15 05:45:06 UTC
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

rar 34e4e7e93772ae641e3af2bb6024a416bc008845822a3a54733003ab308c5fad

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments