MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0532df0f1c10101ed3e063a588a9a2b3612ee0b592dbf6f68460dc6579a0050. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d0532df0f1c10101ed3e063a588a9a2b3612ee0b592dbf6f68460dc6579a0050
SHA3-384 hash: a5a83307fbb3f0fb0d5d6ecc3ef88f4ff535d82047262238d7a8de0fe521be33d5398a980681848fc903d3fa7a4744b7
SHA1 hash: ddc0427fd4092fd779e2b801016e9a179662e62a
MD5 hash: e9751c5408fa0554fea2802795bff9d0
humanhash: jupiter-mirror-ink-leopard
File name:Quotation for soundproof Gensets.rar
Download: download sample
Signature NanoCore
File size:824'784 bytes
First seen:2020-06-11 05:50:41 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:3TCnDE/Hy5xphZq+kxZgNGxnMTiP4AYgtp+G34:jSDE/HythgtZFxn0iP4zg/I
TLSH AF0533D1ECD9A2EBBE28C5DD82EB4D23281CA205396667906773F7630077E812D1E356
Reporter abuse_ch
Tags:NanoCore nVpn rar RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: sp-di-sf02.direct.co.kr
Sending IP: 223.130.85.12
From: DIY POWER SYSTEM (CHINA) CO.,LIMITED <noel@diypowers.com>
Reply-To: account@diypowers.com
Subject: Deposit received//DIYPOWER quotation for Cummins standby 1000KVA 20200611
Attachment: Quotation for soundproof Gensets.rar (contains "nrwe.exe")

NanoCoreRAT C2:
socket-controller.ddns.net:8417 (185.244.30.216)

Pointing to nVpn:

% Information related to '185.244.30.0 - 185.244.30.255'

% Abuse contact for '185.244.30.0 - 185.244.30.255' is 'abuse@FOS-VPN.org'

inetnum: 185.244.30.0 - 185.244.30.255
netname: Freedom_Of_Speech_VPN
remarks: Before you contact us, please read:
remarks: 185.244.30.0/24 belongs to a NON-LOGGING VPN service.
remarks: We don't log any user activities.
remarks: We believe that the right to informational self-determination and the
remarks: right to privacy are essential to all citizens of all countries.
remarks: We don't host anything else on our servers than VPN software and our
remarks: customers can open a fixed number of Ports.
remarks: Like Public WiFi or Tor Exit Node Operators we cannot be held responsible
remarks: for the actions of our customers, because we simply can't (and to be
remarks: honest: don't want) to control them.
country: EU
org: ORG-SL751-RIPE
admin-c: SL12644-RIPE
tech-c: SL12644-RIPE
status: ASSIGNED PA
mnt-by: FOS-VPN-MNT
created: 2019-10-29T14:10:27Z
last-modified: 2020-06-03T09:20:12Z
source: RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-06-11 05:52:07 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

rar d0532df0f1c10101ed3e063a588a9a2b3612ee0b592dbf6f68460dc6579a0050

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments