MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 86fc159edf7d8f3e2606c3e92d9d0966cccf902650a24e21693f40f9abeb60f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 86fc159edf7d8f3e2606c3e92d9d0966cccf902650a24e21693f40f9abeb60f8
SHA3-384 hash: 24a7e5e1dc91d184fdf71de8d031dfb8a3c561237fe830a7fc2bf19f04844ef63080c5c9edfdd9f90e4e50bbff514e20
SHA1 hash: 0207ed57f8c0489a5d33098b5a8f809c96bdc180
MD5 hash: 44128549b089848ee8350416d3f5e016
humanhash: twelve-stream-cola-earth
File name:ewrgqaerf.exe
Download: download sample
Signature NanoCore
File size:207'360 bytes
First seen:2020-04-05 13:26:45 UTC
Last seen:2020-04-05 13:35:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 6144:QLV6Bta6dtJmakIM5Jr8cCqESuheKLJcyfFo3Z:QLV6BtpmkrcbgvfyZ
Threatray 1'353 similar samples on MalwareBazaar
TLSH DC14C0653BA9893FE2DF8579612212138379C2E3A8C3F3EE58D455B24F263E5460B1D3
Reporter JoulK
Tags:NanoCore

Intelligence


File Origin
# of uploads :
2
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Nanocore
Status:
Malicious
First seen:
2020-04-05 13:35:25 UTC
File Type:
PE (.Net Exe)
Extracted files:
1
AV detection:
30 of 30 (100.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

NanoCore

Executable exe 86fc159edf7d8f3e2606c3e92d9d0966cccf902650a24e21693f40f9abeb60f8

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments