MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b45455ee4e32285ab60bf8ebc88adf9ae658def683af413f84c4eb0b033439a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4b45455ee4e32285ab60bf8ebc88adf9ae658def683af413f84c4eb0b033439a
SHA3-384 hash: 755a41d2666e2b42ba131cd0b2655894c6f76078e845e61f1a9c7d01167fd5b17eb8f6105cb38f7865cc3fe37b08379b
SHA1 hash: 45b5263053872b8a97600378e0d9b2e457d19861
MD5 hash: 46ee8df4af4675da8069fd26db9b7bce
humanhash: quebec-nevada-burger-bacon
File name:BANK DETAILS FOR TRANSFWEWISE.GZ
Download: download sample
Signature NanoCore
File size:621'885 bytes
First seen:2020-10-09 06:28:36 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:0nc70IKBWhTGbEB9f+GAfAw7/cozxm0mHe1X1IixP:XQjghiAojnCHe1Xai5
TLSH 0CD423BE84D165F72F6813A6656AECFF540820572B1F49072B3B3E867784F306D0A52E
Reporter abuse_ch
Tags:gz NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: outlook.com
Sending IP: 209.58.149.66
From: Vivian Zhang <eniitcogen.trading@outlook.com>
Subject: CONFIRM BANK DETAILS FOR PAYMENT
Attachment: BANK DETAILS FOR TRANSFWEWISE.GZ (contains "2fv6UIeN63gPAdd.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
106
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-09 04:18:41 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

gz 4b45455ee4e32285ab60bf8ebc88adf9ae658def683af413f84c4eb0b033439a

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments