MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 02bf16ff2f32d689f47d750e106e87a61b7a0ad26a2823a13b51ee5295a6ae75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
NanoCore
Vendor detections: 13
| SHA256 hash: | 02bf16ff2f32d689f47d750e106e87a61b7a0ad26a2823a13b51ee5295a6ae75 |
|---|---|
| SHA3-384 hash: | ac55fb350eec4eb89a4eeffaf2f843a86f2f21ff342565bde394592a7d57c6bb4d97d9b65405e9c4aaa19be5b43368bf |
| SHA1 hash: | 517282476e12a8c28f72491e8f952ae1c71abeec |
| MD5 hash: | f807e01db1cc13f748e500e52e4ad757 |
| humanhash: | black-pasta-lima-emma |
| File name: | UTYHFG03983765367839837653.exe |
| Download: | download sample |
| Signature | NanoCore |
| File size: | 1'104'896 bytes |
| First seen: | 2021-11-17 15:17:03 UTC |
| Last seen: | 2021-11-17 16:28:45 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'205 x SnakeKeylogger) |
| ssdeep | 24576:Fk/2YpVJXYyPwIpZux6d4jZqNTJXOaUo+:FaVJrwIpCVZyRO7x |
| Threatray | 3'286 similar samples on MalwareBazaar |
| TLSH | T12F35F0253BB99F03C5BD8BF84A65D24803B57A4869A7D71F2DD331CF7EA2B814A42503 |
| File icon (PE): | |
| dhash icon | 18b462e4ecc9c060 (2 x NanoCore) |
| Reporter | Anonymous |
| Tags: | exe NanoCore |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
185.140.53.131:1211
Unpacked files
5a212200f9863805091c9b03bedc0f4145eca4907b8924224e0bf49182752d2f
7fb55c7160ff90700ea1b7258ff4a71037659ee4152a7877efa111ea609190c3
d7cc44c8311a1e7001ca0e85434b068c4421ac3d9f79d080b11548f3eb584c90
3be7eca97e7ba084e0e4d7142b3c6bfdb7a9d32603e58cadb610a5437c177443
02bf16ff2f32d689f47d750e106e87a61b7a0ad26a2823a13b51ee5295a6ae75
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | ach_NanoCore |
|---|---|
| Author: | abuse.ch |
| Rule name: | MALWARE_Win_NanoCore |
|---|---|
| Author: | ditekSHen |
| Description: | Detects NanoCore |
| Rule name: | Nanocore |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Nanocore in memory |
| Reference: | internal research |
| Rule name: | nanocore_rat |
|---|---|
| Author: | jeFF0Falltrades |
| Rule name: | Nanocore_RAT_Feb18_1 |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Nanocore RAT |
| Reference: | Internal Research - T2T |
| Rule name: | Nanocore_RAT_Feb18_1_RID2DF1 |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Nanocore RAT |
| Reference: | Internal Research - T2T |
| Rule name: | Nanocore_RAT_Gen_2 |
|---|---|
| Author: | Florian Roth |
| Description: | Detetcs the Nanocore RAT |
| Reference: | https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
| Rule name: | Nanocore_RAT_Gen_2_RID2D96 |
|---|---|
| Author: | Florian Roth |
| Description: | Detetcs the Nanocore RAT |
| Reference: | https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
| Rule name: | pe_imphash |
|---|
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | win_nanocore_w0 |
|---|---|
| Author: | Kevin Breen <kevin@techanarchy.net> |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.