MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 68b92d885a2b75a1a44e909c4fbb5221c9328161c51bf9982009189cc01e8dec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 2 File information 2 Yara 5 Comments

SHA256 hash: 68b92d885a2b75a1a44e909c4fbb5221c9328161c51bf9982009189cc01e8dec
SHA3-384 hash: 32270e04b097039a64570f84c31b97aae9d6ae26ff9c3619f27753904c80ebb7f3d166264e0471fc7a8c789d0c5f507d
SHA1 hash: d000161e3420fec04cbf61eb3308d7a47110efa9
MD5 hash: ee69793cef8aa3785f18f46fb760550e
humanhash: speaker-idaho-one-batman
File name:NEWSTOCK-SHEET.exe
Download: download sample
Signature NanoCore
File size:339'968 bytes
First seen:2020-06-30 14:37:12 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744
ssdeep 6144:XLs2W5O4rfbWjIY/cw4fChe9n5ID9zchFSpazcORS+LYeetlEZjIQY+bqP:XLs2W5O4ro5F46We6mKHRSHe2lEtCSqP
TLSH 25740239B36ADB64D5F6A3B8157060101FF27A0F5261E61F2E4055CE1A72BA1E722F23
Reporter @James_inthe_box
Tags:exe NanoCore


Mail intelligence
Trap location Impact
IT Italy Low
Global Low
# of uploads 1
# of downloads 37
Origin country FR FR
CAPE Sandbox Detection:n/a
CERT.PL MWDB Detection:nanocore
ReversingLabs :Status:Malicious
Threat name:ByteCode-MSIL.Trojan.Kryptik
First seen:2020-06-30 14:35:07 UTC
AV detection:23 of 31 (74.19%)
Threat level:   2/5
Spamhaus Hash Blocklist :Malicious file
Hatching Triage Score:   10/10
Malware Family:nanocore
Tags:evasion trojan keylogger stealer spyware family:nanocore
VirusTotal:Virustotal results 19.72%

Yara Signatures

Rule name:ach_NanoCore
Rule name:Nanocore
Author:JPCERT/CC Incident Response Group
Description:detect Nanocore in memory
Reference:internal research
Rule name:Nanocore_RAT_Feb18_1
Author:Florian Roth
Description:Detects Nanocore RAT
Reference:Internal Research - T2T
Rule name:Nanocore_RAT_Gen_2
Author:Florian Roth
Description:Detetcs the Nanocore RAT
Rule name:win_nanocore_w0
Author: Kevin Breen <>

File information

The table below shows additional information about this malware sample such as delivery method and external references.

Delivery method