MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d79536202660c5f64dac143d481aa91374cd2281c593bd2e4573d90df1f9369. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0d79536202660c5f64dac143d481aa91374cd2281c593bd2e4573d90df1f9369
SHA3-384 hash: 1845dc8b1dde5c792ca205d8e758302aeafb5741b87fb54a5b976a9c32e526139eed2e97935b4fa5ae4dd655753b063f
SHA1 hash: c59335a35d893e2f6114a6ad4ba1b8b4cb279a73
MD5 hash: e1f9fad8b52daa102fc3c4c797048f6f
humanhash: king-gee-crazy-ceiling
File name:Documents AWB 5-5-2020.PDF.z
Download: download sample
Signature NanoCore
File size:355'379 bytes
First seen:2020-05-06 08:25:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:cvAjYKwj9srzI9DygUymooNNqrGTjrhU3whrHHpW1SLegj6GIhtk7wJjS86:LcN9sI9mwJKsGb1BJ1hotRjS86
TLSH F87423AD0C40E92D7E28E879A930D7BA34347E6F52BD97A73A4F443B11145F6DE23068
Reporter abuse_ch
Tags:Maersk NanoCore RAT z


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: maratheb2.interactivedns.com
Sending IP: 146.88.26.46
From: Maersk Line <verification@maersk.com>
Subject: AWB Documents /Factura Infomacion
Attachment: Documents AWB 5-5-2020.PDF.z (contains "Documents AWB 5-5-2020.exe")

NanoCore RAT C2:
atallatall.ddns.net:5355 (173.209.43.61)

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Grp
Status:
Malicious
First seen:
2020-05-06 08:35:46 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 0d79536202660c5f64dac143d481aa91374cd2281c593bd2e4573d90df1f9369

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments