MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 718b8c3293604c3626d2051074cd810f3d0b6508ff165f7363eaefbda8234322. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 718b8c3293604c3626d2051074cd810f3d0b6508ff165f7363eaefbda8234322
SHA3-384 hash: 13a410efdc908854422a64857614286e259d3b28e19e9dba78ce7562a73dd911b6516ae219c94fc01a0c308092a671e8
SHA1 hash: b8d1d812c57a415151fb7620134c808e604dc7c9
MD5 hash: 1748747aebd8c7ab9baece491da1e34b
humanhash: sodium-summer-north-delaware
File name:wire transfer2.img
Download: download sample
Signature NanoCore
File size:1'245'184 bytes
First seen:2021-02-18 14:31:57 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:BUSME+vHKKB9YP2BFc+2zgjSrN5bkab6zp8cDYd5AynZNE7y9toRSuFcUrlq:5cfKLv+2zgkiVCqCvZNdoEuFcUQ
TLSH ED45013971691D97CFAC81FAE20551663F60D349249FF3F02EA9A1EC62C7F4095D28A3
Reporter abuse_ch
Tags:img NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: west.seedhost.eu
Sending IP: 37.48.89.179
From: Account dept<account@webmail.co.za>
Reply-To: <hjfanels@gmail.com>
Subject: WIRE TRANSFER
Attachment: wire transfer2.img (contains "wire transfer2.exe")

NanoCore RAT C2:
amechi.duckdns.org:4190

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.Pwsx
Status:
Malicious
First seen:
2021-02-18 14:32:06 UTC
AV detection:
9 of 47 (19.15%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

img 718b8c3293604c3626d2051074cd810f3d0b6508ff165f7363eaefbda8234322

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments