MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e17ef91c83677181bed9cf9d362f37a4ada8180cd5386490bd50dd5b5c362e88. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e17ef91c83677181bed9cf9d362f37a4ada8180cd5386490bd50dd5b5c362e88
SHA3-384 hash: 11879834c665d0db47cf63fdf2f47626435f46bdf41bbaf1eafdf94876d67c1984adbf0ca37dc2c705452ed01d495c6f
SHA1 hash: 6338596e0b9a6defd7575994aa1dc6f6d0febba1
MD5 hash: d65c8b2196f88697e6169d6676f86a5f
humanhash: jupiter-salami-arizona-oregon
File name:BISSELL INT - PO200513DCC025R-1.Z
Download: download sample
Signature NanoCore
File size:402'113 bytes
First seen:2020-08-05 16:07:55 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:h8J0rEIZYmL5UNgN9ndo4YukuFedrTk8Zj1gw0iNU0Hu8HrzSRjg4Ci+R8fnRZ8D:CardvqgNxpFFCr8uNnHf+g4CL8fRZs
TLSH 89842352C40518ED4E66CFCEB6E6F322E0878F8E2B9144E6CF65C6D208E70F606DD959
Reporter abuse_ch
Tags:NanoCore nVpn RAT z


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: [37.49.229.235]
Sending IP: 37.49.229.235
From: Angeles Ureta <angeles.ureta@airesgifts.cl>
Subject: BISSELL INTERNATIONAL - PO#200513DCC025R-1
Attachment: BISSELL INT - PO200513DCC025R-1.Z (contains "BISSELL INT - PO#200513DCC025R-1.exe")

NanoCore RAT C2:
jbbalboamonark.ddns.net:29890 (91.192.100.25)

Pointing to nVpn:

% Information related to '91.192.100.1 - 91.192.100.63'

% Abuse contact for '91.192.100.1 - 91.192.100.63' is 'abuse@privacyfirst.sh'

inetnum: 91.192.100.1 - 91.192.100.63
netname: LIBERTAS_NETWORK
remarks: ----------------------------------------------
remarks: Libertas Network is a VPN service provider.
remarks: We have a strict non-logging policy, therefore
remarks: we don't record any logs on our servers.
remarks: ----------------------------------------------
country: CH
admin-c: LNAD1-RIPE
org: ORG-LNVS1-RIPE
tech-c: LNAD1-RIPE
status: ASSIGNED PA
mnt-by: MNT-DA327
created: 2019-12-12T08:51:11Z
last-modified: 2020-02-10T07:01:46Z
source: RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

z e17ef91c83677181bed9cf9d362f37a4ada8180cd5386490bd50dd5b5c362e88

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments