MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8480ca9efc47aafdb01f17f33b787141037e36789a31113651aef3f046e9981d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8480ca9efc47aafdb01f17f33b787141037e36789a31113651aef3f046e9981d
SHA3-384 hash: a013bbb5b03dc48d7a81e1d8dff83c1498ef577a8ef6307e70a2d87a1309d5dc6eacd7c1297c69f8338780c63c15956f
SHA1 hash: ea4544e6cd9c758621156d85a81a77876ebc66d6
MD5 hash: 5d52fe8ef8481bf86918c82c7486774a
humanhash: romeo-east-salami-summer
File name:POSE000277,pdf.iso
Download: download sample
Signature NanoCore
File size:387'072 bytes
First seen:2020-05-13 06:16:48 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:mPiyTJ8aLABQjnyLJn8oJOoY1gyT+eF2Fzm2nzpBJJF9:mKqXAtLJn8no+gmaNv
TLSH FB84022E3799655FCFDC01F4912252805BF3819566BEE3C9FC8E54EA9BA3BC001217A7
Reporter abuse_ch
Tags:iso NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: kblind.com.my
Sending IP: 37.49.230.21
From: Sally Khor <purchasing@kblind.com.my>
Subject: SIN SENG HUAT | PO(SE-000277) ETA DATE : 25.05.2020
Attachment: POSE000277,pdf.iso (contains "POSE000277,pdf.exe")

NanoCore RAT C2:
billionaire.ddns.net:3734 (185.19.85.185)

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-14 03:54:52 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
14 of 31 (45.16%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

iso 8480ca9efc47aafdb01f17f33b787141037e36789a31113651aef3f046e9981d

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments