MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 70ae9f204352242faa28e2d090c2ea16297dd2b1066d5e3c37ac04425a2e7967. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 70ae9f204352242faa28e2d090c2ea16297dd2b1066d5e3c37ac04425a2e7967
SHA3-384 hash: e12b33820252be69b39093a46750e5a936263d6920ab6abef0f53593fa941f3ee46d1b7406a13f1282b8962cbdd70613
SHA1 hash: e80e8e94c4a37f7b2aa22219c228dd7ba157fb24
MD5 hash: ba5abbbfa3dc48e37cfb4811e98447cf
humanhash: lithium-california-emma-quiet
File name:HLCUJK1200426084 INV 2097430962.zip
Download: download sample
Signature NanoCore
File size:412'493 bytes
First seen:2020-06-11 06:03:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:gMTgsp7KK4wKx/z4TdlHUjX3dMDoNleeuszf:rpN4wMKHUjX2gleRc
TLSH CE9423594FB2E3648905DF032D1918A7186F50F6230E999C6F1E68933FF89D35D2B8CA
Reporter abuse_ch
Tags:MailChannels NanoCore nVpn RAT zip


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: bonobo.birch.relay.mailchannels.net
Sending IP: 23.83.209.22
From: YIKUN INDUSTRY COMPANY LIMITED <sunny@yikungroup.com>
Reply-To: sunny@yikungroup.com
Subject: Request for pending payment
Attachment: HLCUJK1200426084 INV 2097430962.zip (contains "HLCUJK1200426084 INV 2097430962.exe")

NanoCore RAT C2:
adikaremix.linkpc.net:1790 (185.140.53.13)

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-11 06:05:06 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 70ae9f204352242faa28e2d090c2ea16297dd2b1066d5e3c37ac04425a2e7967

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments