MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a4e82447233bb979a8c23c4c28d4e4ec44be91c4c2fff7236114ff8da9995b12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a4e82447233bb979a8c23c4c28d4e4ec44be91c4c2fff7236114ff8da9995b12
SHA3-384 hash: 52c5e51f87e420a3da2df4329e3c95d0a062cf4212c14c033552d3e99919567843fac856742dc4179571a5145dffa83a
SHA1 hash: 906674b14a09c57ad95d1702891ac78d32fb39e4
MD5 hash: 98c84d33c1e814ab946a12dd17f55192
humanhash: winter-video-fish-low
File name:07_06_20_REF1.pdf.zip
Download: download sample
Signature NanoCore
File size:492'070 bytes
First seen:2020-07-06 06:33:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:frQp41f011yytK5AuFCwOCko2EzfPfFMK1YwkfjjQQRNwJ2IlN7:q41s1BKmU4gfPfz12bEdJbv7
TLSH A7A423B711EF22C677399B7B7AD7C4A1E1420A83745D1BED270638CA1783AA7D0648F4
Reporter abuse_ch
Tags:NanoCore nVpn RAT zip


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: fredfootwear.co.za
Sending IP: 45.143.222.167
From: Antony Falcon <accounts@fredfootwear.co.za>
Subject: Re: pending bills details
Attachment: 07_06_20_REF1.pdf.zip (contains "1206_07_07_20_REF1.exe")

NanoCore RAT C2:
izu2128.hopto.org:2128 (185.244.29.131)

Pointing to nVpn:

% Information related to '185.244.29.0 - 185.244.29.255'

% Abuse contact for '185.244.29.0 - 185.244.29.255' is 'abuse@gerber-edv.net'

inetnum: 185.244.29.0 - 185.244.29.255
netname: GERBER-NETWORK
descr: Wonsan, Kangwon-do
descr: Choson Minjujuui Inmin Konghwaguk
country: KP
admin-c: GN5022-RIPE
tech-c: GN5022-RIPE
org: ORG-GN148-RIPE
status: SUB-ALLOCATED PA
mnt-by: GERBER-MNT
created: 2018-01-31T19:41:57Z
last-modified: 2020-04-06T22:16:40Z
source: RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-06 06:35:06 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip a4e82447233bb979a8c23c4c28d4e4ec44be91c4c2fff7236114ff8da9995b12

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments