MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc4124a761c1c0106ca9a47b872acd5aa3a71a44a8ef2a6ab67d94a7b2ee1799. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dc4124a761c1c0106ca9a47b872acd5aa3a71a44a8ef2a6ab67d94a7b2ee1799
SHA3-384 hash: ea35a666edfb6fee194d32e89d7595bf08e6b6bf01ce6f938b52b9582bb8601dc0b21a663b9e46682f597e7f6f58874e
SHA1 hash: 4700f5006abfd22266bf9d4a73f866f3206bf590
MD5 hash: 6fbbd6d4eabd97c08eda558b65ad9d2c
humanhash: jupiter-cardinal-high-colorado
File name:NEW PRICE FOR QUOTATION.Z
Download: download sample
Signature NanoCore
File size:400'205 bytes
First seen:2020-05-06 08:12:08 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:e/+MtdgOlWr5t7SvhAUOydxIzlu+ypfZeTcfi+7NdsOto5OaHiTzI/Lh4Q:e/lgHlhS5prIzoLpfkFEfho5OlnElT
TLSH DA842334156E39CF3AFDABA2CA28E184E15D7597983D1FCF91DBB9A610C3FD41081868
Reporter abuse_ch
Tags:NanoCore nVpn RAT z


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: smtp.safemail.it
Sending IP: 147.123.1.124
From: Zann KWOK <zkwok@gattefosse.sg>
Subject: New offer-price confirmation
Attachment: NEW PRICE FOR QUOTATION.Z (contains "NEW PRICE FOR QUOTATION.exe")

NanoCore RAT C2:
185.244.29.216:4050

Hosted on nVpn:

% Information related to '185.244.29.0 - 185.244.29.255'

% Abuse contact for '185.244.29.0 - 185.244.29.255' is 'abuse@gerber-edv.net'

inetnum: 185.244.29.0 - 185.244.29.255
netname: GERBER-NETWORK
descr: Wonsan, Kangwon-do
descr: Choson Minjujuui Inmin Konghwaguk
country: KP
admin-c: GN5022-RIPE
tech-c: GN5022-RIPE
org: ORG-GN148-RIPE
status: SUB-ALLOCATED PA
mnt-by: GERBER-MNT
created: 2018-01-31T19:41:57Z
last-modified: 2020-04-06T22:16:40Z
source: RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-06 04:12:06 UTC
File Type:
Binary (Archive)
Extracted files:
39
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

z dc4124a761c1c0106ca9a47b872acd5aa3a71a44a8ef2a6ab67d94a7b2ee1799

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments