MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b00bccfeeec06e55a8b19c1b47de603b0baedc9586401a38bf57048977522baf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b00bccfeeec06e55a8b19c1b47de603b0baedc9586401a38bf57048977522baf
SHA3-384 hash: 04dff0987d83d9c636df550593817ebfc5e8ca4122bb51ce1736d991e86e412e7b1dfc5dc6bb80e05ba033ce9f2395ec
SHA1 hash: 50a10356b9bdf7ccf1298d7c83ce94c48f7a97aa
MD5 hash: 61e201badce314e5ac74f2f27acb88d4
humanhash: nineteen-helium-arizona-shade
File name:Swift Copy.zip
Download: download sample
Signature NanoCore
File size:328'803 bytes
First seen:2020-10-14 15:15:49 UTC
Last seen:2020-10-14 18:42:18 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:HARHhWZg+VTPLyz5s6imm4CoE8gAJ7uUneJ9XPxy8oiG4TdeYG6haT3O085H3:HUhPwTQWn4PElAJxnsX8UXTd+y085H3
TLSH DE6423B747193021C7AFBD2267BE7F9A4752E70A5D9C0B759EE10503C8BAA2101C683F
Reporter abuse_ch
Tags:NanoCore RAT zip


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: ultimatecircle.com.my
Sending IP: 95.211.208.23
From: sales@ultimatecircle.com.my
Subject: RE: PAYMENT INSTRUCTIONS
Attachment: Swift Copy.zip (contains "Swift Copy.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-14 07:45:23 UTC
File Type:
Binary (Archive)
Extracted files:
45
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip b00bccfeeec06e55a8b19c1b47de603b0baedc9586401a38bf57048977522baf

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments