MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd280d9cdda7796cb295b3635fd64eeed3805a4e9a4a5360576eb121303db064. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dd280d9cdda7796cb295b3635fd64eeed3805a4e9a4a5360576eb121303db064
SHA3-384 hash: e9b7a36af5f09a26b52c12ac5f0609aa95315115a68c02a15a552dcb607709de2155898c5251c5cfdba3e64a35eb5401
SHA1 hash: 841c0566d15dd25a78d38244aafabe445991f551
MD5 hash: 1d6702182578276d04bf6bf579a51694
humanhash: asparagus-thirteen-one-kentucky
File name:Anti_ covid19_Iwantani_vietnam_co.arj
Download: download sample
Signature NanoCore
File size:1'599'597 bytes
First seen:2020-03-30 11:29:59 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 49152:RjWSoUuZlXCQk+tohA/YojvL10QUkTt4utmDUoA:MUudk+tcA5vLyQ1TtHmDO
TLSH AC753336B7A3581DC21D209A3EF4BF58D849A5E072E4E25D014BFD8F0474CA779A8D8E
Reporter abuse_ch
Tags:arj COVID-19 NanoCore RAT


Avatar
abuse_ch
COVID-19 themed malspam distributing NanoCore RAT:

HELO: nenk.com
Sending IP: 168.235.82.242
From: Iwatani Vietnam <nhule.iwatani@gmail.com>
Subject: Anti-covid-19 items
Attachment: Anti_ covid19_Iwantani_vietnam_co.arj (contains "Anti_ covid19_Iwantani_vietnam_co.exe")

RemcosRAT C2:
45.125.239.181:4488

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Injector
Status:
Malicious
First seen:
2020-03-30 11:35:54 UTC
File Type:
Binary (Archive)
Extracted files:
75
AV detection:
10 of 47 (21.28%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

arj dd280d9cdda7796cb295b3635fd64eeed3805a4e9a4a5360576eb121303db064

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments