MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88c93fb2359cc5f0da6886983c67d923955d210daf5a458e382d024124a67458. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 88c93fb2359cc5f0da6886983c67d923955d210daf5a458e382d024124a67458
SHA3-384 hash: f57e5e04a0003104a6aa4948dda94567d190563b1f1a2a022b1ab40db4b9e963322259b3415d50c81575089098e613e6
SHA1 hash: 320130c170648bc9c57ee58a26792ee100d55ead
MD5 hash: d65e36f052e8db95610a2a525b62f7f9
humanhash: friend-august-ten-wisconsin
File name:c9myKLWC.exe
Download: download sample
Signature NanoCore
File size:220'160 bytes
First seen:2020-03-11 15:04:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 6144:MQZIF6k+8X2hXdBonq0THcvcbf6xUtdHfBTQxVqtjre:fmUV8ioqhpkd/FcVqx
Threatray 25 similar samples on MalwareBazaar
TLSH C924ADB863DE5F32DB8F09BBC5E229040B6C9815C987F71F50C908E19C517EEA972827
Reporter johannes
Tags:NanoCore


Avatar
viql
nanocore via https://pastebin.com/raw/c9myKLWC

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments