MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5c9cc3265818b3221ebf207e50802ccd25661c175d04c9b3fc0a55be07b62123. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5c9cc3265818b3221ebf207e50802ccd25661c175d04c9b3fc0a55be07b62123
SHA3-384 hash: 0f16b02b9f4c7b9c447890bdbcc4ea6b8088c94fc85215adfcc97cb36de57da9e79d944c0814d469edf804bafd4fe686
SHA1 hash: a32e466074bf50194bbc056044d6a68fe0367b6a
MD5 hash: 71af37bc2fa1a2cde17fcc6407cb1ce5
humanhash: white-solar-johnny-pennsylvania
File name:DOC-03082175453465667686557.iso
Download: download sample
Signature NanoCore
File size:141'312 bytes
First seen:2021-03-09 11:32:53 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 1536:5RQhqTz+V6ihNi1yLfYO10YO1fYR1zYO10n0tYibP3kJ9:OfYO10YO1fYR1zYO10n0tYibP3kJ9
TLSH CAD3F194744ACCBFD52F89780E9C77022595501F80B3486AB26E2526BFE310A1F9DDFB
Reporter abuse_ch
Tags:iso NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: slot0.ge-ticaret.com
Sending IP: 203.159.80.130
From: "Ronald Rina" <rrina@smediasys.com>
Reply-To: rrina-smediasys@post.com
Subject: Request For QUOTE (INNOVATION PROJECT)
Attachment: DOC-03082175453465667686557.iso (contains "DOC-03082175453465667686557.exe")

NanoCore RAT C2:
nanocore1.publicvm.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
165
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Fsysna
Status:
Malicious
First seen:
2021-03-09 11:33:05 UTC
AV detection:
11 of 28 (39.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

iso 5c9cc3265818b3221ebf207e50802ccd25661c175d04c9b3fc0a55be07b62123

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments