MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 38fd11bb13f8df92b479907bcf8e886e665c233187c7bb69f736567c830dd04c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 38fd11bb13f8df92b479907bcf8e886e665c233187c7bb69f736567c830dd04c
SHA3-384 hash: 9e220d7e0bc54ea17f08c81e335dc66805ce06590964006c531465560b5eecc7b3b6cabfdd5b37a4edd6323f0536b98e
SHA1 hash: fd1075e5f6e5709294fbc83f89c3ebcc29b6671a
MD5 hash: 20e2f369a98f8c9e9d3159fb78c310df
humanhash: sixteen-maine-robert-wolfram
File name:5420201232.gz
Download: download sample
Signature NanoCore
File size:323'548 bytes
First seen:2020-05-04 21:40:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:HqdcVVQ4XCCU91ym4qWkugKbIzSbtnhowd0Dhx9kb1oZwSGKbFDOa6z3mrxl:HLjJSfym3Wkmb1awd0txOb1ewSGUDC2v
TLSH B064234E9AE7F5783D893A0EE547AF4A94F3810531B674309E423A87AECD1F71839D06
Reporter abuse_ch
Tags:gz NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: cranetrucks.co.za
Sending IP: 37.49.230.247
From: Tender Thakur <swapnil@nutrisgroup.com>
Subject: PAYMENT DEPOSIT SLIP
Attachment: 5420201232.gz (contains "5420201232.exe")

NanoCore RAT C2:
harri2gud.hopto.org:2177 (69.65.7.130)

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-04 23:57:32 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
24 of 31 (77.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 38fd11bb13f8df92b479907bcf8e886e665c233187c7bb69f736567c830dd04c

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments