MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 243695e7081c87c1a14cfef0f89b75bd326edef6e651ef8b124fa8052dbee7a3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
NanoCore
Vendor detections: 14
| SHA256 hash: | 243695e7081c87c1a14cfef0f89b75bd326edef6e651ef8b124fa8052dbee7a3 |
|---|---|
| SHA3-384 hash: | ab3ca192b9b3ff53dba74483f8253a6c1924fae544def99403e496c8d89bf842ab03c526c125897d94921f17bede7b99 |
| SHA1 hash: | 49e92c99c8b0777dc93ec4f3b13fdc6de99e80b0 |
| MD5 hash: | 617a5e683eb9f142139a860b9fb84959 |
| humanhash: | delta-fix-oregon-coffee |
| File name: | gunzipped.exe |
| Download: | download sample |
| Signature | NanoCore |
| File size: | 207'872 bytes |
| First seen: | 2022-06-21 03:44:10 UTC |
| Last seen: | 2022-07-06 11:22:37 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'661 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger) |
| ssdeep | 6144:MLV6Bta6dtJmakIM5UUBPnGZd3wwMi5T5:MLV6BtpmknMOhwwMi15 |
| Threatray | 4'149 similar samples on MalwareBazaar |
| TLSH | T15314CF5677A9892FE2CE86BD612241539379C2E3D8C3F3DE28D415B69F263E146070E3 |
| TrID | 69.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 9.9% (.EXE) Win64 Executable (generic) (10523/12/4) 6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.7% (.EXE) Win16 NE executable (generic) (5038/12/1) 4.2% (.EXE) Win32 Executable (generic) (4505/5/1) |
| Reporter | |
| Tags: | exe NanoCore RAT |
Indicators Of Compromise (IOCs)
Below is a list of indicators of compromise (IOCs) associated with this malware samples.
| IOC | ThreatFox Reference |
|---|---|
| 188.127.231.93:3425 | https://threatfox.abuse.ch/ioc/717662/ |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
21281c48dd7beeb19d22aef27f4d77f79c550fc32acc69d4c3b91966cc8a048b
02558d43b82050ac649bd7eff62a663dd98d141033f6cca56bc99bc811a059b8
0289b5c2829170ad4bb04daedbd3db5e56474415aee109a91a66ba9fa8a7a179
999c19bb669363e626ff41024ebe756e82a200fd874f8099dfbf8776360ccba2
0090148371c3a92d98212cda20209ca8d7b4e50c0c7829e6d17501d85c826743
c7e6e4337c88f196926b8833aac8b3c9b1759b657128da161ec2d279f1ef613e
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | ach_NanoCore |
|---|---|
| Author: | abuse.ch |
| Rule name: | malware_Nanocore_strings |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Nanocore in memory |
| Reference: | internal research |
| Rule name: | MALWARE_Win_NanoCore |
|---|---|
| Author: | ditekSHen |
| Description: | Detects NanoCore |
| Rule name: | nanocore_rat |
|---|---|
| Author: | jeFF0Falltrades |
| Rule name: | Nanocore_RAT_Feb18_1 |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Nanocore RAT |
| Reference: | Internal Research - T2T |
| Rule name: | Nanocore_RAT_Feb18_1_RID2DF1 |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Nanocore RAT |
| Reference: | Internal Research - T2T |
| Rule name: | Nanocore_RAT_Gen_2 |
|---|---|
| Author: | Florian Roth |
| Description: | Detetcs the Nanocore RAT |
| Reference: | https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
| Rule name: | Nanocore_RAT_Gen_2_RID2D96 |
|---|---|
| Author: | Florian Roth |
| Description: | Detetcs the Nanocore RAT |
| Reference: | https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | win_nanocore_w0 |
|---|---|
| Author: | Kevin Breen <kevin@techanarchy.net> |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.