MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f87574f1f8a4350e1a6ee7dce9df292accc7bc2b5afde7023b7edeba9f6f7a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6f87574f1f8a4350e1a6ee7dce9df292accc7bc2b5afde7023b7edeba9f6f7a6
SHA3-384 hash: a4f6ae6996fc4f52b732a63708e0a18d93a69dde3d2aaacad42d7b7b8e073747d86dd128c8b2ba9761401e1546aad687
SHA1 hash: bd6da36cf375eb74e1cec540f921ae4d713fb90e
MD5 hash: 00f0a4e361554064c9892a8baa38ab63
humanhash: lamp-uniform-july-nineteen
File name:QUOTE873972101.PDF.rar
Download: download sample
Signature NanoCore
File size:379'980 bytes
First seen:2020-08-14 10:10:16 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:DpuKXMolYvN+uKoK9J9E8JP4YHBgVXxNnaj3jMOQ7z9OLH27f+dt+fnqRVE2SCs4:DpuuMolGl8fE8JPVSVhNnajzcX9Orrdp
TLSH 4584236F9A7DFAD44C28CC294AFA602A54FF42170329CD2486617B2C6FD3C75D2198B7
Reporter abuse_ch
Tags:NanoCore rar RAT Yahoo


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: sonic309-49.consmr.mail.ne1.yahoo.com
Sending IP: 66.163.184.175
From: Adonai Agencies <adonaiagencies@yahoo.com>
Reply-To: Adonai Agencies <adonaiagencies@yahoo.com>
Subject: NEW QUOTE INQUIRY
Attachment: QUOTE873972101.PDF.rar (contains "u1rC8zA7y9jIy7m.exe")

NanoCore RAT C2:
mail.memorybasket.co.in

Intelligence


File Origin
# of uploads :
1
# of downloads :
117
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-14 10:12:06 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

rar 6f87574f1f8a4350e1a6ee7dce9df292accc7bc2b5afde7023b7edeba9f6f7a6

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments