MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 37486f1c3da726488dd5f596da267bb21d4975dd86229b3141866e3cb92a16a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 37486f1c3da726488dd5f596da267bb21d4975dd86229b3141866e3cb92a16a2
SHA3-384 hash: 0970cfec047763529a99d1624f47a9f81726377a05ecab6d734527f308751070ca1209eb8cfa30905961441c51381f37
SHA1 hash: 028bdc5a579f338b4c7aa5038e047d35ab0c904e
MD5 hash: 827d385a87bc20f1cab398376f0ba840
humanhash: wisconsin-autumn-west-potato
File name:Order List.arj
Download: download sample
Signature NanoCore
File size:958'690 bytes
First seen:2020-04-02 18:06:23 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 24576:Ts6a3YqGkiuY14zbOZ+mTKVISQW+sG96JFLPy:TsjGnB14HmHTvSQW+XYJFLPy
TLSH D5153381F83A191E0295010E72C54AE883D5ECA4FC1C2EE7F57D3D92F2C959BBB9166C
Reporter cocaman
Tags:arj NanoCore

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Agensla
Status:
Malicious
First seen:
2020-04-03 04:10:48 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
17 of 31 (54.84%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

arj 37486f1c3da726488dd5f596da267bb21d4975dd86229b3141866e3cb92a16a2

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments