MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 712671f4e32eb1981ffdbbbe3e4d394b24d6e1df9fbdd31c019b3f094061b12c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 712671f4e32eb1981ffdbbbe3e4d394b24d6e1df9fbdd31c019b3f094061b12c
SHA3-384 hash: bee0df8e0a04b9dd4c997f45eec91821abc47aa982d47fb53a15f718939ff819dc5db9fb31482c81f0ced094f32f0565
SHA1 hash: c4e699e648e7748144b6813403c0926b4167335f
MD5 hash: e5d2cb8a1beb7961f5c7799b42acd64d
humanhash: early-undress-carolina-bacon
File name:Project_Purchase_ A02057 NMB TYP PIP SCAN000.pdf.img
Download: download sample
Signature NanoCore
File size:1'245'184 bytes
First seen:2020-10-26 09:08:25 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:rbVzLbJpQwu7yYsymmGZuzbXAN0203Jq8HcD+jrrN:rVbJpHu7lmmGZy7U0P3Uuc6jN
TLSH 1D45F2B0F0D2ACEBF4E586F7086DE92012B1255F5466D60DF1AD7B658BE335202F1A0B
Reporter abuse_ch
Tags:img NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: server.ccamatli.com
Sending IP: 185.104.114.215
From: AZHAR OSMAN <azharosman@ccamatli.com>
Subject: RFQ 33091782773847 (DAHLIA, TERATAI & KANGSAR) - SUPPLY
Attachment: Project_Purchase_ A02057 NMB TYP PIP SCAN000.pdf.img (contains "Project_Purchase_ A02057 NMB TYP PIP SCAN000.pdf.exe")

NanoCore RAT C2s:
engr101.ddns.net:41205 (129.205.112.168)
engr101.hopto.org:41205 (93.161.193.99)

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-25 23:43:40 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

img 712671f4e32eb1981ffdbbbe3e4d394b24d6e1df9fbdd31c019b3f094061b12c

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments