MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ed18c6c0eb3e96e1228c8be78d5f955fbc3d882c77496a06f94c28f7053b0f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4ed18c6c0eb3e96e1228c8be78d5f955fbc3d882c77496a06f94c28f7053b0f6
SHA3-384 hash: ed399d239846407fa8e0923632e719ff57c40d0f155c30c9598fbed88fb4fc1b83907011f97848748042c6971baf12d0
SHA1 hash: 99d166c0fcff9bf880b5093e8b6c5aeabf8f509c
MD5 hash: 69c2179bdd88a19700650728757f40a2
humanhash: finch-fourteen-uniform-stairway
File name:Ms_09865787-608098567890.xls.z
Download: download sample
Signature NanoCore
File size:341'161 bytes
First seen:2020-10-08 13:09:34 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:L4NXqzJ1gIOpnPIItRBR4qdvlCijScAHqTYAjW0xUiEDbQpDy:L4NJpPXvn4avGcAHqT7BoDbmDy
TLSH DA74231A26725AE6C60B3078D3118B75E3215C61A3387A57BE25581F01FFFD0FC9E9A4
Reporter abuse_ch
Tags:NanoCore RAT z


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: webmail.cyber.net.pk
Sending IP: 203.101.175.37
From: javaid@cyber.net.pk
Subject: PAYMENT SWIFT COPY
Attachment: Ms_09865787-608098567890.xls.z (contains "Ms_09865787-608098567890.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Stelega
Status:
Malicious
First seen:
2020-10-08 06:11:48 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

z 4ed18c6c0eb3e96e1228c8be78d5f955fbc3d882c77496a06f94c28f7053b0f6

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments