MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0f91a022face55458459e23c434b9102cd99bea0c3c7a584ef5965bf0b30bb71. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
NanoCore
Vendor detections: 12
| SHA256 hash: | 0f91a022face55458459e23c434b9102cd99bea0c3c7a584ef5965bf0b30bb71 |
|---|---|
| SHA3-384 hash: | 2bf357bedad55c47cf7cb90c3ddf723b49045ac749f71b9f573e64d87b743749314f3a4c618a46cb126ac5c1865dd444 |
| SHA1 hash: | 02c0aa3a1cb705285049cd8a9fde173dbe9ffcb8 |
| MD5 hash: | f5435da222db2bfd1d30089f6259eb11 |
| humanhash: | east-neptune-kansas-nitrogen |
| File name: | OBL.exe |
| Download: | download sample |
| Signature | NanoCore |
| File size: | 665'088 bytes |
| First seen: | 2022-04-27 12:06:30 UTC |
| Last seen: | 2022-04-27 12:39:06 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:ATuZOnJ/dNsLWJeYJfKVUk5/9KYsKSlo62Wpd3ha4n3PZ:gJrAQjfKVZpSa62ed3r/Z |
| Threatray | 4'866 similar samples on MalwareBazaar |
| TLSH | T14CE4E11CBBBECB16C7DA0732D0E455044BB0EE02A556EB4FAAC522861D03357D953BAF |
| TrID | 64.2% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 11.5% (.SCR) Windows screen saver (13101/52/3) 9.2% (.EXE) Win64 Executable (generic) (10523/12/4) 5.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 3.9% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | 69dca0e8e8e0c448 (22 x AgentTesla, 8 x SnakeKeylogger, 6 x Loki) |
| Reporter | |
| Tags: | exe NanoCore |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
2.56.59.113:1818
Unpacked files
319e4d202d1c0b0a32e8893f182970964dbbf2c55bb6268bfb503f0545a847f0
258450591bf7e9a66670360379423a36a5c4f9c174a4d36cd12158079f55d229
baf8e236476a6b0340139a2b1db14038faa96d8319399f2ef14fef201018e232
3e9e04ae27988abffc50ee2cfad53435ccf72284d50e6efea6c5f0ef541abff3
f61cb6448b00917c426f5b7220a17043f1d3f777550d495031605d31284b824a
821b667c348d7b06a5fc8871bc137ff0248b4e0e5daf604ff6c141b4a2c71455
0f91a022face55458459e23c434b9102cd99bea0c3c7a584ef5965bf0b30bb71
26f85305187d4a525a43932fcb01bad97b248648f584b9cdc2d9ba78fea83f69
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.