MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e43e9542b921c80431ceef61da4b0c70af418052491048e1c2a499bec5ecc530. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e43e9542b921c80431ceef61da4b0c70af418052491048e1c2a499bec5ecc530
SHA3-384 hash: 1d6493e7f26f76bc38d1568ea181491f8b16625572a023aef33386900a3e3334e54af7af4ed43b925c9aae2251f6e84c
SHA1 hash: 4dd762e0eb77e13c797caead4fbff442e0d1c82f
MD5 hash: 5dd1acee4a21bfecd60eb2562fbe5142
humanhash: happy-nineteen-social-nitrogen
File name:Bank Details pdf.z
Download: download sample
Signature NanoCore
File size:212'124 bytes
First seen:2020-05-04 22:20:34 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:j/sunjd2rFYRphUgiIaQQfEnmGjrMYOPq:Tbj0FabefzGmS
TLSH 3C2423224AE23CE2E15D2B11316578441CF1E3BBBDC8ADFCD085C0DD916E25E7E3966A
Reporter abuse_ch
Tags:NanoCore RAT z


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: srv01.pd-host.com
Sending IP: 216.12.197.50
From: NRB Commercial Bank <asadeco@nrbcommercialbank.com>
Subject: wrong IBAN/Account number
Attachment: Bank Details pdf.z (contains "Bank Details pdf.exe")

NanoCore RAT C2:
fackrul.ddns.net:1720 (192.99.127.206)

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Injector
Status:
Malicious
First seen:
2020-05-05 02:07:16 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

z e43e9542b921c80431ceef61da4b0c70af418052491048e1c2a499bec5ecc530

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments