MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 989f797cd2fdf4a061dffaab1f1e15194221a3fe0a1d9e1372d32dcd331b9f27. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 989f797cd2fdf4a061dffaab1f1e15194221a3fe0a1d9e1372d32dcd331b9f27
SHA3-384 hash: f91acd1187fc3c431cf8444bc4173ff31793b41b41ddd28a1bc4599e3326bf7e220a97329241b1a3d19b360ccfeef2d6
SHA1 hash: c8980839874288e4d92be2c6ff275bf2aea0c78b
MD5 hash: 49e1854598850d51da096aa44d4f586b
humanhash: lima-twelve-one-speaker
File name:halkbank,pdf.z
Download: download sample
Signature NanoCore
File size:331'915 bytes
First seen:2020-06-16 13:55:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:RZz+BcJvxqU51PBjQsARCIEjB4Bco2ipuj2P1H9ySIftNiC/1MC4Zzq/KahgkeCI:mwvxBFQoIEjBgcPYTPlA1ftoU10zEKp
TLSH CA64231C1A672A1734795F2A8BC7C9216EFF6C91B716BEB8D0D026430067B24FC94AC7
Reporter abuse_ch
Tags:geo Halkbank NanoCore RAT TUR z


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: halkbank.com.tr
Sending IP: 156.96.62.208
From: HALKBANK.E-EKSTRE@halkbank.com.tr
Reply-To: HALKBANK.E-EKSTRE@halkbank.com.tr <samlog427@gmail.com>
Subject: T.HALK BANKASI A.S. 16.06.2020 Hesap Ekstresi
Attachment: halkbank,pdf.z (contains "halkbank,pdf.exe")

NanoCore RAT C2:
jfncghc.ddns.net:4040 (156.96.62.208)

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-16 13:57:03 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip 989f797cd2fdf4a061dffaab1f1e15194221a3fe0a1d9e1372d32dcd331b9f27

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments