MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ac47aacf3ec3e74b0a165aa5ba5397f0fbc477bbc9061fec24579da1569d1e0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4ac47aacf3ec3e74b0a165aa5ba5397f0fbc477bbc9061fec24579da1569d1e0
SHA3-384 hash: 6ca7fa3e707648adee527741596b5afa5640eaf5a9b36d6c082f3447d2966b8c25405c9144dc6cfc34380833f44e1327
SHA1 hash: 6af054a3ad45d07b184c8f1da2853c60128b8793
MD5 hash: 9eb7cfc30e1b1cf93497898964ca11d7
humanhash: august-iowa-eighteen-jersey
File name:PO PDF.z
Download: download sample
Signature NanoCore
File size:263'564 bytes
First seen:2020-06-15 05:29:32 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:T2ey0Xj1V3TksGztWHnfICTeLSDul4Rt71sG14m0o0lm5eFW50X:T2bQ3TStYnA4kSy6JF3M1t
TLSH 5F44230ACBEE2F8CE284B1B12552D6F3B7D41B607B05A28547607B8270FF3B7851D65A
Reporter abuse_ch
Tags:NanoCore RAT Yahoo z


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: sonic312-46.consmr.mail.ir2.yahoo.com
Sending IP: 77.238.178.133
From: Andrea Phelps <andreainternational33@yahoo.com>
Subject: Purchase order
Attachment: PO PDF.z (contains "PO PDF.exe")

NanoCore RAT C2:
fackrul.ddns.net:6674 (95.211.208.59)

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Ransomware.WannaCry
Status:
Malicious
First seen:
2020-06-15 05:31:04 UTC
AV detection:
22 of 31 (70.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

z 4ac47aacf3ec3e74b0a165aa5ba5397f0fbc477bbc9061fec24579da1569d1e0

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments