MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae1d222c98ee381a766ce7359ac369158917434bb83f0697a0fc0413f7fb0c95. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ae1d222c98ee381a766ce7359ac369158917434bb83f0697a0fc0413f7fb0c95
SHA3-384 hash: 7ca5cf1c1270a1628fde9d96710b0dabb805e87f449efd8be3aca6d861e370de8154f5b7c8c302c6342e56ee99f9ca2a
SHA1 hash: a1c25cc656fcd5407e675c657de8b2c9babbec01
MD5 hash: 09e441499cb03bc3b8d99ac22963f847
humanhash: utah-victor-magnesium-thirteen
File name:862020,pdf.zip
Download: download sample
Signature NanoCore
File size:453'363 bytes
First seen:2020-08-06 06:56:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:i2u9PjN7EqWubU1XOJhLYdE1vrR4gyU1zMdlQ5:i9jNg9roJYdEprrMjQ5
TLSH 43A42353C4766E9D95C219170A68D433F4E28FA7628837DC27C4B9E02D9B623B7F8D84
Reporter abuse_ch
Tags:NanoCore zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: web72.smartstrategies.gr
Sending IP: 88.99.208.204
From: Jaxon Chew Cheng Soon <Jaxon.CHEW@range.com.sg>
Subject: Range Enquiry - Request for Quote
Attachment: 862020,pdf.zip (contains "862020,pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-06 06:58:09 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip ae1d222c98ee381a766ce7359ac369158917434bb83f0697a0fc0413f7fb0c95

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments