MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef8136cbfba5b8b00ec27d50910f84738c2efe718511c18295e0f71aa9b1b5c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ef8136cbfba5b8b00ec27d50910f84738c2efe718511c18295e0f71aa9b1b5c0
SHA3-384 hash: fe441226d7069631fdafefbb5fceaeaa2124a1cbf937b7d34abbfa159b7e9c7bcbab4bf2e8e3a43ea3b60dafa8a34f9f
SHA1 hash: 2fbe787997bfb7e79cd753842974fb9ad05a73a4
MD5 hash: 88d0f3494a1daa154ea482701cd99ecd
humanhash: sierra-mexico-wyoming-william
File name:SHIPPING DOCUMENTS.pdf.z
Download: download sample
Signature NanoCore
File size:644'204 bytes
First seen:2020-11-12 19:13:38 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:VBEIufTFPm+LEZtgjb5hSHcXzw5J/MByhC5NmStgN+CVDzDEQfY:krk+AG08w70ByhC5MStgN+CVDUQfY
TLSH D9D423B0D5F65603EB417EBCE4880A693C79F2D9730B5437EF8E29B02E6616E4D3A015
Reporter GovCERT_CH
Tags:NanoCore

Intelligence


File Origin
# of uploads :
1
# of downloads :
170
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NanoBot
Status:
Malicious
First seen:
2020-11-12 09:42:57 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

z ef8136cbfba5b8b00ec27d50910f84738c2efe718511c18295e0f71aa9b1b5c0

(this sample)

  
Dropped by
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments