MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9660d46a2ceda67a0eb38cee7d4f26a271ce51a2470cd71008fc20ef05698f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b9660d46a2ceda67a0eb38cee7d4f26a271ce51a2470cd71008fc20ef05698f8
SHA3-384 hash: 0d7e588281bb4f26086211bdc9f33bb7e6d9f8e99f892461a67df756ac853f00c01a9360a73b119bd0d606d2575a7ab2
SHA1 hash: f6f7ceed44bf1e6949960e8c9b5acf598eb08b52
MD5 hash: 9b2fd01a5eb1b2be50c48f3797dee997
humanhash: finch-black-connecticut-maryland
File name:PurchaseOrder#PO7211A20_RFQ_Samples_Pacific_Keystone_co.arj
Download: download sample
Signature NanoCore
File size:369'176 bytes
First seen:2020-05-06 07:04:57 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:bGbj6hshR90KtEqT8R8xhAePHwjU81LERr68yVO33FWTEpjOH0:Sj6u4+ERohdPwAEcm8yVKFWTEpjm0
TLSH C17423EEBFC317B6E53451B00288FF79AE01EEA0D33B4949724971BDCA9998BC814C11
Reporter jarumlus
Tags:NanoCore

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-06 07:35:26 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

arj b9660d46a2ceda67a0eb38cee7d4f26a271ce51a2470cd71008fc20ef05698f8

(this sample)

  
Dropped by
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments