MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 249918922ac123157deb21f176139e79c1002dc76cc72379b0d922b16432e0d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 249918922ac123157deb21f176139e79c1002dc76cc72379b0d922b16432e0d3
SHA3-384 hash: e47e70f39b8545ac8062560fe02857abd734b340f4226a4930adb50602c25b4ff8c49898fb484b207216fc47e4fcdab1
SHA1 hash: e0247086b7fab1d764b481e76b6618a8b0d39865
MD5 hash: b5eea6b332f97773e7d6b4ab7a359785
humanhash: vegan-shade-ten-november
File name:Dintec Order PDF.z
Download: download sample
Signature NanoCore
File size:335'756 bytes
First seen:2021-01-27 15:42:24 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:j+NzhUIMlaL7ERmYje1U5iqgfWAfdIdLcQjQKGepCxaxGpspA0Pm+WZEEovPBNou:j+ZhUq7EBe1U5i4CIthTP/rPmZmEoHR
TLSH BC6423156B3A9EDDFD1ED9B1F93C32E89DC47A64530D34B44AA50084B026849B7ACAFC
Reporter cocaman
Tags:NanoCore z


Avatar
cocaman
Malicious email (T1566.001)
From: "DINTEC <Accounts@dintec.co.kr>" (likely spoofed)
Received: "from joy.joyasha.com (joy.joyasha.com [185.38.45.130]) "
Date: "27 Jan 2021 23:24:47 -0800"
Subject: "Re: DINTEC New Order"
Attachment: "Dintec Order PDF.z"

Intelligence


File Origin
# of uploads :
1
# of downloads :
179
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-27 15:43:05 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
19 of 46 (41.30%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

z 249918922ac123157deb21f176139e79c1002dc76cc72379b0d922b16432e0d3

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
NanoCore

Comments