MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3360f77209c2a2a5d393eefcb0229f34230fa261199aef2bdf17e8dda0ef540f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
NanoCore
Vendor detections: 11
| SHA256 hash: | 3360f77209c2a2a5d393eefcb0229f34230fa261199aef2bdf17e8dda0ef540f |
|---|---|
| SHA3-384 hash: | fb499fc428d12c36389713e0359a57a8172c0cc9921a475073974060b6a4c93d4d2a0af451d3597699c7646a3d7f56af |
| SHA1 hash: | b386ee8a5faa3890d34916be7dacb8ae164ebbaa |
| MD5 hash: | 7b53dd81534cbd1e8ab438f308818644 |
| humanhash: | bravo-johnny-oscar-utah |
| File name: | Document#20014464370.pdf.exe |
| Download: | download sample |
| Signature | NanoCore |
| File size: | 1'007'616 bytes |
| First seen: | 2021-01-14 16:00:51 UTC |
| Last seen: | 2021-01-14 18:12:04 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'748 x AgentTesla, 19'642 x Formbook, 12'245 x SnakeKeylogger) |
| ssdeep | 12288:MN5NNeuVJ+toczDNj6u3HpTkJ23d9ZSn9VtchtS:i5NsuVncPNjFHpAIZSnbaht |
| Threatray | 40 similar samples on MalwareBazaar |
| TLSH | F625D441F787CA85C5B130BB96C5D63E13C6EDDB1700C5961748BA2AB4FF2C11E8E68A |
| Reporter | |
| Tags: | exe NanoCore nVpn RAT |
abuse_ch
Malspam distributing NanoCore:HELO: vps.osmispee.com
Sending IP: 45.85.90.199
From: alicust7<office@osmispee.com>
Subject: Shipping Documents // 20014464370=949379074856
Attachment: Document20014464370.pdf.rar (contains "Document#20014464370.pdf.exe")
NanoCore RAT C2:
fenixalec.ddns.net:20911 (185.162.88.26)
Pointing to nVpn:
% Information related to '185.162.88.0 - 185.162.88.255'
% Abuse contact for '185.162.88.0 - 185.162.88.255' is 'abuse@privacyfirst.sh'
inetnum: 185.162.88.0 - 185.162.88.255
remarks: This prefix is assigned to The PRIVACYFIRST Project, which
remarks: operates infrastructure jointly used by various VPN service
remarks: providers. We have a very strong focus on privacy and freedom.
remarks: In case of abuse, we encourage all international law enforcement
remarks: agencies to get in touch with our abuse contact. Due to the fact
remarks: that we keep no logs of user activities and only share data when
remarks: it is legally required under our jurisdiction, it is very unlikely
remarks: for a demand of user information to be successful. Still, that
remarks: should not deter you from reaching out.
netname: PRIVACYFIRST-UK2
country: GB
admin-c: TPP15-RIPE
tech-c: TPP15-RIPE
org: ORG-TPP6-RIPE
status: ASSIGNED PA
mnt-by: PRIVACYFIRST-MNT
created: 2019-10-04T21:54:06Z
last-modified: 2020-10-07T21:33:04Z
source: RIPE
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
fenixalec.ddns.net:20911
Unpacked files
02c430c51fa15522e80f952731fabd0f06d968d1205c2249e30a052a4e96d771
c59cec501a6e4d91587afa1e5582838965a61793c9d5d2f70ab4c53f55c05789
c914e1cead39ffb086bb87029bcea3673f8159087ef8cd7c1cf49eceba97ee07
761e77be2bbf6089f04b1901c44548bd4ff5ac873a74b1ca0e0604bb902eff22
4e599dda2d5d0f3cad7ac5451a39cb1c4934ea0f10fd9163e82711455aaf3efd
43bdef53f8ff0d262c2086a46c66d76f8c5e2b9df085959c70a5a3c679474767
618d343a6d7f54a0bfd917555c79c6a777b10a35fc2da0d75f6d85354de40637
1372611a62207431985055ea8ecb4121b3dfb199e615102c06cc38e5aabdd65d
d13eb672da933a88f7ddbc45de31fde1da9479937470f4226ed9e5efff0048b1
942e878db472c9697a7db40c15fcf32878c589bf2d7dc8a96f28d999461df802
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | ach_NanoCore |
|---|---|
| Author: | abuse.ch |
| Rule name: | Nanocore |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Nanocore in memory |
| Reference: | internal research |
| Rule name: | nanocore_rat |
|---|---|
| Author: | jeFF0Falltrades |
| Rule name: | Nanocore_RAT_Feb18_1 |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Nanocore RAT |
| Reference: | Internal Research - T2T |
| Rule name: | Nanocore_RAT_Gen_2 |
|---|---|
| Author: | Florian Roth |
| Description: | Detetcs the Nanocore RAT |
| Reference: | https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
| Rule name: | win_nanocore_w0 |
|---|---|
| Author: | Kevin Breen <kevin@techanarchy.net> |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.