MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e7b3d88a84692e6bcdec4b41de652c19e48f2b1f89a38bd725c4dd7ed571cf3c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e7b3d88a84692e6bcdec4b41de652c19e48f2b1f89a38bd725c4dd7ed571cf3c
SHA3-384 hash: 954211b1fb99053250b5a571f877fe5fdeb5012bc674833f96919fd96b0f0738128fd7d0ec5b48db6fbd49d406cfcdf9
SHA1 hash: 19c4381ca610d236b9a822fa34d43e17fa4df85c
MD5 hash: 070d20b95491010577dfcaedb7c6803b
humanhash: pennsylvania-orange-cold-beryllium
File name:INVOICE.pdf.gz
Download: download sample
Signature NanoCore
File size:301'100 bytes
First seen:2020-05-11 11:19:24 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:dAcfkKdhCC64YsaSHnMGE+g8acX/zgG7dDVPzx6XefUemmwOUP:dAtK+C64sSHMN+glcJdDVPAMUezAP
TLSH 51542349EAB500D8ACF2F8C8CE1BF0A6496B9B2C055253E61FDD4BE7716317680B15F2
Reporter jarumlus
Tags:NanoCore

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Rdn
Status:
Malicious
First seen:
2020-05-11 13:59:47 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
31 of 48 (64.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip e7b3d88a84692e6bcdec4b41de652c19e48f2b1f89a38bd725c4dd7ed571cf3c

(this sample)

  
Dropped by
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments