MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6fd3d1e8aed1c9240638a0b36dee8208ea59135018a4c0367f357fcbb89beab2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
NanoCore
Vendor detections: 5
| SHA256 hash: | 6fd3d1e8aed1c9240638a0b36dee8208ea59135018a4c0367f357fcbb89beab2 |
|---|---|
| SHA3-384 hash: | 749ba00f2152bc5e250d1cd0327b4d791de28eb00b2773b25e2c260a3d498479b95a530b783f1883d2972d6bf5a51319 |
| SHA1 hash: | 55fd650cbc313069bc24b22ffe5a7e923473d431 |
| MD5 hash: | 6b36a29482f5932226bf459bff31c8db |
| humanhash: | blossom-ceiling-robert-maryland |
| File name: | 1000011111111299.zip |
| Download: | download sample |
| Signature | NanoCore |
| File size: | 587'692 bytes |
| First seen: | 2021-02-02 09:42:29 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:Am8iMUotj/9AmMlZ9HFjxgCuP2OKRAAFXRincdveTGPFPf:A1JlFElLFNG2nLQncEy |
| TLSH | 4CC4339740C433B6213DA5B28FD6583AA77A5CB5306BCCB35A329EBEC14C1592C2DE1C |
| Reporter | |
| Tags: | NanoCore RAT zip |
abuse_ch
Malspam distributing NanoCore:HELO: vps.helitactica.xyz
Sending IP: 203.159.80.22
From: Ewa Laszcz <ewailp@icloud.com>
Reply-To: Ewa Laszcz <sdmarine861000@gmail.com>
Subject: New order no : 41PU000604 : MRP D5000 WK 3 : Central Worldwide Company Limited
Attachment: 1000011111111299.zip (contains "1000011111111299.exe")
NanoCore RAT C2s:
fgtrert.duckdns.org
qweerreww.duckdns.org
Intelligence
File Origin
# of uploads :
1
# of downloads :
190
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Zmutzy
Status:
Malicious
First seen:
2021-02-02 09:43:07 UTC
AV detection:
13 of 46 (28.26%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
NanoCore
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.