MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46ac82dfbcb6693163f74b4ec09697894e35bc19882dd54f283f18aae39184db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 46ac82dfbcb6693163f74b4ec09697894e35bc19882dd54f283f18aae39184db
SHA3-384 hash: c76359dfe74a997680c423a973598144b1298819b5cf553de939d55206dd98620add78a475d13d81ad090706bb7ea857
SHA1 hash: ec9b3773ea27547ff93c74036637162e28b0ceb5
MD5 hash: 314ae38de2269e98fb68fc2c6da47464
humanhash: uncle-tango-triple-mexico
File name:shipping order.zip
Download: download sample
Signature NanoCore
File size:525'010 bytes
First seen:2021-01-08 17:28:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:W/IJhTd/scOIoBAx2oUAPXONBHmuedihjK1wjMpKZK2z25vG:WQaSoBC2obPXOSueIjKMTc2z25+
TLSH C2B42328AC1D53FDADD094E5515CB54C1550FF988EFE8F3D43A1C7282B36EBA1A01AE4
Reporter abuse_ch
Tags:Endurance NanoCore RAT zip


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: 142-4-25-22.unifiedlayer.com
Sending IP: 142.4.25.22
From: Pcv Industrial LLC <order@mx2.org.ng>
Subject: purchase order confirmation/invoice Paid#
Attachment: shipping order.zip (contains "shipping order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
367
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-08 12:53:18 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 46ac82dfbcb6693163f74b4ec09697894e35bc19882dd54f283f18aae39184db

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments