MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 02440937e66c0970cd03367c5098d43c65aaca13cb521e6be79661a78742d935. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 02440937e66c0970cd03367c5098d43c65aaca13cb521e6be79661a78742d935
SHA3-384 hash: 60afe3602b6e8186e59395386b0edf53b6eea1f80b14d9df06c688052110171260a9685dc78659c3471660bafa138cfb
SHA1 hash: 0c34823109c35ccb1a17ca1543693895f420bfe3
MD5 hash: 31125f80072e5db3e7c8ccd816ee2f2a
humanhash: minnesota-one-wyoming-north
File name:PROOF OF PAYMENT.IMG
Download: download sample
Signature NanoCore
File size:1'310'720 bytes
First seen:2020-10-14 15:55:33 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:1pdoGag0ngko955zCaaB2FFPjAz67ytdgKqiEVhQOnT/f4XktlLScK2oUwsMXv:N59rzvFlAzRtd/2yuT/g0
TLSH 7055CFAC326075DFC45BCD769AA82C24AA207076971BC203A45715ADDB0EBDBDF205F3
Reporter abuse_ch
Tags:img NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

From: loansdepartmentda@mail2world.com
Reply-To: loansdepartmentda@mail2world.com
Subject: proof of payment
Attachment: PROOF OF PAYMENT.IMG (contains "PROOF OF PAYMENT.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Stelega
Status:
Malicious
First seen:
2020-10-14 10:52:49 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

img 02440937e66c0970cd03367c5098d43c65aaca13cb521e6be79661a78742d935

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments