MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 97849d2e405235c5d0f42f028fcd373d81fca19e27e64395d182e55e4322e6f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 97849d2e405235c5d0f42f028fcd373d81fca19e27e64395d182e55e4322e6f6
SHA3-384 hash: a90ec065f4d1f43400c0a9c3dec0d8b6a0271e9c39bca4eef5a05f3411fac6156bb9332579043696f0ba84c5dba7c4a7
SHA1 hash: eb770ff17a971803258fd50734b4ccad60a02219
MD5 hash: 513bdd50098582d6fd3ece13d5da6bcb
humanhash: fanta-failed-golf-network
File name:New PO 64739 (UK).zip
Download: download sample
Signature NanoCore
File size:637'701 bytes
First seen:2020-11-26 06:52:45 UTC
Last seen:2020-11-27 09:36:44 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:YfCQKCf3oSA5vLu1/5eOZUHCfLsSI57LPrXqcpJTXo:YfC+QS+vy4OWifLsBtqcX8
TLSH 3AD4237ED55DFBB5FCA07984EF1C81EE92924C5D0B032F08AC399C0D25C6AB191B6A94
Reporter GovCERT_CH
Tags:NanoCore

Intelligence


File Origin
# of uploads :
5
# of downloads :
210
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-11-26 06:53:09 UTC
AV detection:
20 of 28 (71.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 97849d2e405235c5d0f42f028fcd373d81fca19e27e64395d182e55e4322e6f6

(this sample)

  
Dropped by
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments