MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 feb3f9dea6e9ef879ac0cff4499f2b7e1c49b1c5fb487baf6c44494834bdb676. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: feb3f9dea6e9ef879ac0cff4499f2b7e1c49b1c5fb487baf6c44494834bdb676
SHA3-384 hash: 983015f671362150e46b7e07a0b067548ed896c25051b149d7f878fc74968c4c82cb1d4cad1e22be98ca83bb5a517ead
SHA1 hash: dd1bf5008546d5d78deeebadfa2e7063bef74cb6
MD5 hash: 8f8372f70c8ab59c7c8091b2b1de99e2
humanhash: fourteen-twelve-fish-hydrogen
File name:Receipt 133927392 25-06-2020.iso
Download: download sample
Signature NanoCore
File size:1'245'184 bytes
First seen:2020-06-25 12:35:16 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:oUw6/z4VHS20YzAc5eLI53A3DJ925TWPlIfW1YmAB2Lp1JndBCd3GQFkb5f:pP/zQHbzAc5uDnET2sm42TJdBPzb5f
TLSH 0345E0541358CF5AD6BD47BDD0E1201583B896063247FBAABECC74EC2FA37E1890A257
Reporter abuse_ch
Tags:iso NanoCore RAT


Avatar
abuse_ch
Malspam distributing NanoCore:

HELO: server0.wynntrade.pw
Sending IP: 23.238.49.34
From: Tassos Krokos <tasos.krokos@gluesystem.gr>
Reply-To: Tassos Krokos <jihoseoyun20@gmail.com>
Subject: STATEMENT OF ACCOUNT 25-06-2020
Attachment: Receipt 133927392 25-06-2020.iso (contains "Jqfv6hf2mh0QvMk.exe")

NanoCore RAT C2:
osharay.ddns.net:49291 (37.49.230.92)

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-25 13:53:36 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

iso feb3f9dea6e9ef879ac0cff4499f2b7e1c49b1c5fb487baf6c44494834bdb676

(this sample)

  
Dropping
NanoCore
  
Delivery method
Distributed via e-mail attachment

Comments