MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5b0eb5664dc373aa5e2c59229bb23e88d02b04f8054cd04a37bf218c4692aada. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5b0eb5664dc373aa5e2c59229bb23e88d02b04f8054cd04a37bf218c4692aada
SHA3-384 hash: a28656da8a2d3d22b0a4a59e0508bca52d23dc0b0d506ea993d12770b83cbc31620db5f44b91ddc2a8df60186278ade0
SHA1 hash: ad67ff04c18fdd5bafa7a1f92a38c8133d1c8327
MD5 hash: f340014c686c3ff40946cab4d3117807
humanhash: speaker-music-steak-maine
File name:PDF.arj
Download: download sample
Signature NanoCore
File size:326'419 bytes
First seen:2020-05-01 11:46:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:JQLnDbixBY8V1Ho3rp3Y8QGceRI4/FSIi4F0RwZVjdCEpPNZfc:JQLixaSCt3Y8QGceFiVoVpCKPc
TLSH 68642338A9F48468AF86FC7ED7893C046853AE772BCE79573675028AFCE03218935345
Reporter abuse_ch
Tags:arj CHE geo NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: dharmajaya.co.id
Sending IP: 103.113.170.147
From: Carabineros de Chile <invitations@carabineros.cl>
Subject: Invitación final de los Carabineros de Chile.
Attachment: PDF.arj (contains "PDF.exe")

NanoCore RAT C2:
172.111.188.199:8829

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-01 12:35:44 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
26 of 48 (54.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 5b0eb5664dc373aa5e2c59229bb23e88d02b04f8054cd04a37bf218c4692aada

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments