MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a5215b92e33d7c26e43655ac7374af7bf284a6f8e6fd2d6a25b9f128440c2f7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a5215b92e33d7c26e43655ac7374af7bf284a6f8e6fd2d6a25b9f128440c2f7a
SHA3-384 hash: a1b13128032df172dd231dd9544a50d85544ad37e58df7b2d0504321c7a408ff58e321a4a6a1544f30418b57f177e44d
SHA1 hash: 93c6f1301830e27683c565dafaa0c3ce95c5ed50
MD5 hash: 19102a6217905b6c0677ccf0cf01c53d
humanhash: sixteen-wisconsin-lactose-hamper
File name:PO.gz
Download: download sample
Signature NanoCore
File size:778'666 bytes
First seen:2020-06-04 06:51:40 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:NN+vvXnCUpFKO2JGo0Clu/2ueHM2YIl9wqRjbYNNt+1qO4NwSz:zgyUpFKOGGo02G2Fss9NbY+SNVz
TLSH 33F42336E7148DBAC33CD22D1B9610AFFB9960044E0E84FCB2536293EF5FDA69584B54
Reporter abuse_ch
Tags:gz NanoCore nVpn RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: pmrelo.com
Sending IP: 103.240.91.86
From: Ravindra <sjrkintluea@gmail.com>
Reply-To: sjrkintluea@gmail.com
Subject: Purchase Order-030620
Attachment: PO.gz (contains "PO.exe")

NanoCore RAT C2:
185.244.29.132:1985

Hosted on nVpn:

% Information related to '185.244.29.0 - 185.244.29.255'

% Abuse contact for '185.244.29.0 - 185.244.29.255' is 'abuse@gerber-edv.net'

inetnum: 185.244.29.0 - 185.244.29.255
netname: GERBER-NETWORK
descr: Wonsan, Kangwon-do
descr: Choson Minjujuui Inmin Konghwaguk
country: KP
admin-c: GN5022-RIPE
tech-c: GN5022-RIPE
org: ORG-GN148-RIPE
status: SUB-ALLOCATED PA
mnt-by: GERBER-MNT
created: 2018-01-31T19:41:57Z
last-modified: 2020-04-06T22:16:40Z
source: RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-04 07:37:31 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

gz a5215b92e33d7c26e43655ac7374af7bf284a6f8e6fd2d6a25b9f128440c2f7a

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments