MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79cfffb4d6f556083fe9b8057490a9cbc22c2aef4c1deb591ccd54e19846a0c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 79cfffb4d6f556083fe9b8057490a9cbc22c2aef4c1deb591ccd54e19846a0c0
SHA3-384 hash: 2a6bab45baec15d7d103a4c5db48c47d71fdcdab2db516d4a65d03487a7c44525d16644ad322e12bc817bff4127d37b4
SHA1 hash: f02c945276d456d8e397efbc5fece133addf56f3
MD5 hash: 40b531df68a461f51f88e2d1ec674e4d
humanhash: magnesium-victor-six-ten
File name:PO4018-308875.rar
Download: download sample
Signature NanoCore
File size:374'239 bytes
First seen:2021-01-21 06:16:33 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:8mNmqAsnH392mUbesau1r8GU8kW/lrVyRSHF+ExTvz+xjc7B6n91/FMs:9NmqAIHt+l8GSOlrVyEH9T7+xpnTNz
TLSH 698423692264883ACF6413F7799633D49E160C05A211FC700AFF9DC96316EA6FFD53A8
Reporter abuse_ch
Tags:NanoCore rar RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: bornsun.com
Sending IP: 104.129.26.159
From: 业务部(外)-罗秀兰 <sales312@bornsun.com>
Subject: Carlos Valdez Mato PO#4018-308875
Attachment: PO4018-308875.rar (contains "PO#4018-308875.exe")

NanoCore RAT C2:
fenixalec.ddns.net:20911 (185.162.88.26)

Intelligence


File Origin
# of uploads :
1
# of downloads :
157
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-21 06:17:11 UTC
AV detection:
9 of 46 (19.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

rar 79cfffb4d6f556083fe9b8057490a9cbc22c2aef4c1deb591ccd54e19846a0c0

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments