MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 52d3edb02e0df6bcd3fccd7afb5bb0a467fe750db3e27c869297a1536a72806b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 52d3edb02e0df6bcd3fccd7afb5bb0a467fe750db3e27c869297a1536a72806b
SHA3-384 hash: 980016b7dadf0feee9727c6ad9887e2135bed9b5cbca2ca9e884e35bc37fd0be8d2d6a9247d3c20f6de8b4fd530f5b20
SHA1 hash: a26b96ec9760949bc5c07eef1bd7ea18b7f93076
MD5 hash: 4c2a44a3d8ca2b203e12c8a491476285
humanhash: quebec-connecticut-florida-alpha
File name:190408_CoC_list.zip
Download: download sample
Signature NanoCore
File size:451'859 bytes
First seen:2021-01-30 19:45:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:2l6h12a+OvLWrOb3Iaouy3chAUY19hDaBeV:2M12abqibYduy3chAUw
TLSH 3BA42382560B3D4B215116F6E6971F78B4ED3EF02CFE260444E5F2B5AE8082EFC9E119
Reporter abuse_ch
Tags:NanoCore RAT zip


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: vps.helitactica.xyz
Sending IP: 203.159.80.22
From: Ewa Laszcz <ewailp@icloud.com>
Reply-To: Ewa Laszcz <sdmarine861000@gmail.com>
Subject: New Order Request for PI..
Attachment: 190408_CoC_list.zip (contains "190408_CoC_list.exe")

NanoCore RAT C2s:
fgtrert.duckdns.org
qweerreww.duckdns.org

Intelligence


File Origin
# of uploads :
1
# of downloads :
266
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Packed.Generic
Status:
Suspicious
First seen:
2021-01-30 19:46:06 UTC
AV detection:
14 of 46 (30.43%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 52d3edb02e0df6bcd3fccd7afb5bb0a467fe750db3e27c869297a1536a72806b

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments