MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 250710541be43b011b0b5d4acd0c7f9df14f29c491ddb4e3edb77e2fa2121eaf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 250710541be43b011b0b5d4acd0c7f9df14f29c491ddb4e3edb77e2fa2121eaf
SHA3-384 hash: 281c4fdfabcc59887a3a3483177a5cdc51508b102a1cc76a2b0e103f2da23bafa191df60d6b20c2a80a0d189c2c5c26f
SHA1 hash: 24e86cfbdc79f9883d707f60e87a7a0fc92a50ff
MD5 hash: 64e42487472e4438e98338bdec1ad90f
humanhash: oklahoma-ceiling-fix-artist
File name:DOC.rar
Download: download sample
Signature NanoCore
File size:754'623 bytes
First seen:2020-11-18 12:53:25 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:j8rlSz1G1U/i9P2ISXH8xRUJCzzTBYiIoVOQ06SxRxmw298qMRtXrBvwQSgZo:j8rIz2USP2IS+UJCntYWVnUxfmw2qqMM
TLSH B3F423C9460958DAF7C1421990EE20298EC4A2C29277B13FA5F21F15712B3CDF9D6EB7
Reporter abuse_ch
Tags:NanoCore rar RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: ricohogar.com
Sending IP: 185.222.57.247
From: Alan Li <quierovendermicasa@ricohogar.com>
Subject: Re: Shipping Documents – Packing List & Commercial Invoice
Attachment: DOC.rar (contains "DOC.exe")

NanoCore RAT C2:
23.105.131.162:4040

Intelligence


File Origin
# of uploads :
1
# of downloads :
173
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

rar 250710541be43b011b0b5d4acd0c7f9df14f29c491ddb4e3edb77e2fa2121eaf

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments