MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1d286713588056bdd52865cdd1890ecd13dd44f346adffff875cf74247f1a42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d1d286713588056bdd52865cdd1890ecd13dd44f346adffff875cf74247f1a42
SHA3-384 hash: b243507ac3ee854e44af4e4c1535a8f07240627804bc56262341a44074986d226cad6b41a54eba2089747ad9625eadd5
SHA1 hash: 3aa5298fe1c4fe830251598fba3281b8e226b7df
MD5 hash: 08d9964ca235141e9f014c40b8b815c1
humanhash: coffee-vermont-arkansas-double
File name:2362eb54bb90ab9066fd5a30f9f81a51.exe
Download: download sample
Signature NanoCore
File size:207'872 bytes
First seen:2020-03-26 14:51:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'744 x AgentTesla, 19'608 x Formbook, 12'242 x SnakeKeylogger)
ssdeep 6144:MLV6Bta6dtJmakIM5/8GL+1WUQ52F+/8Ej4ew:MLV6BtpmkjGLUcQsEEj4N
Threatray 1'088 similar samples on MalwareBazaar
TLSH 4C14C02677A88A3FE2DE8979611201129739C2E3D9C3F7DE28D455B39F263E44A071D3
Reporter abuse_ch
Tags:exe GuLoader NanoCore


Avatar
abuse_ch
Payload dropped by GuLoader from the following URL:
https://drive.google.com/uc?export=download&id=1-RFFDMcMRBiaVzpmYNj6rKVH_dgkcFl8

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Nanocore
Status:
Malicious
First seen:
2020-03-26 15:36:24 UTC
AV detection:
31 of 31 (100.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

605e97c12f7b0968bca0f35deb286e8602cad3e4ee4d2a7fe3403d9e603b732b

NanoCore

Executable exe d1d286713588056bdd52865cdd1890ecd13dd44f346adffff875cf74247f1a42

(this sample)

  
Dropped by
MD5 2362eb54bb90ab9066fd5a30f9f81a51
  
Dropped by
MD5 4140ef7d2bdb9e39d36bc3f1036e181b
  
Dropped by
GuLoader
  
Dropped by
SHA256 605e97c12f7b0968bca0f35deb286e8602cad3e4ee4d2a7fe3403d9e603b732b
  
Dropped by
SHA256 406cd200c40a0d0b22f69b119e589ec7d1a7af83dc20527923a168235fa0e3cf

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments