ExecuteMalware

2021-07-28 Nanocore IOCs

Jul 28th, 2021
15,395
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.96 KB | None | 0 0
  1. THREAT IDENTIFICATION: NANOCORE
  2.  
  3. SUBJECTS OBSERVED
  4. RE: New Order
  5.  
  6. SENDERS OBSERVED
  7.  
  8. EMAIL BODY
  9. Dear Sir/Ma'am,
  10.  
  11. We are interested in your product, We are Metallurgical Industries
  12. company (E.JS.C) from Saudi Arabia , also we buy in large quantities,
  13.  
  14. Kindly send me your best price of the attached Order and provide me with
  15. your product catalogs, so that we can select more items for our company.
  16.  
  17. We have provided some of the products we buy in the attached file.
  18.  
  19. Indicate your minimum order quantity for our reference?
  20.  
  21. Waiting for your reply
  22.  
  23. Thanks.
  24.  
  25. Sabri Tahir Al Asmakh
  26. Sales Manager, Saudi Arabia
  27.  
  28. MALDOC FILE HASHES
  29. Order No.916754.gz
  30. 65a94caa7ec24ca10c22792ee762a42c
  31.  
  32. NANOCORE PAYLOAD FILE HASHES
  33. Order No.916754.exe
  34. 4a4d763bca1ebc9e0986c1bc3e8bd7bd
  35.  
  36. NANOCORE C2
  37. https://79.134.225.100:1985
  38.  
  39. SUPPORTING EVIDENCE
  40. https://app.any.run/tasks/4a17112f-71b9-4eea-aa37-793d609f4732/
  41.  
Advertisement
Add Comment
Please, Sign In to add comment