MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f4846a6f5b3122080ec0cc8bd6b2fd4045938d4e3e4d6caeaa62be79c1a67a3d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
NanoCore
Vendor detections: 4
| SHA256 hash: | f4846a6f5b3122080ec0cc8bd6b2fd4045938d4e3e4d6caeaa62be79c1a67a3d |
|---|---|
| SHA3-384 hash: | d1d0bafa6b30863444c8304175067fdded7bfdb2d4530c2e0863b175198446784e39eecc6664282078f209562c059ac5 |
| SHA1 hash: | 4215c3c843c2d99e2dcbbf80987d174efc6c09f9 |
| MD5 hash: | 9538f63bd71c8139b818f4c145a66446 |
| humanhash: | double-friend-one-dakota |
| File name: | PO 2604195144.rar |
| Download: | download sample |
| Signature | NanoCore |
| File size: | 444'993 bytes |
| First seen: | 2020-08-03 13:06:51 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:Y4k5mwW8bjfFdhwdiI6euCr1WDZkqO5s0khEuItjRCBhH0sb+mI:rymr0jB0teXJtIl1sb9I |
| TLSH | EC942387D9FC4320B5447BD6B4C639604FFF86AB15EBAE1D71A60C8F1E27ADA1361180 |
| Reporter | |
| Tags: | NanoCore rar |
abuse_ch
Malspam distributing NanoCore:From: Jazz <composite@icomis.com>
Subject: SCG - PO #2604195144 / 08.03.2020
Attachment: PO 2604195144.rar (contains "PO #2604195144.exe")
NanoCore RAT C2:
178.124.140.145:1604
Intelligence
File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Strictor
Status:
Malicious
First seen:
2020-08-03 13:08:07 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
NanoCore
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
NanoCore
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.