Severity
Medium
Analysis Summary
Nanocore rat malware is actively being spread through different phishing campaigns and is dropping malicious url’s. Threat indicators are provided.
Impact
Malware infection
Indicators of Compromise
| URLs | helvitlukakusing.duckdns[.]org normaluksinga.duckdns[.]org hxxps://sibatp[.]net/brazil/home.php |
| Email Address | celsoborba[@]mevepi.com[.]br lynnette[@]c2ccollection[.]com |
| Malware Hash (MD5/SHA1/SH256) | 5d1961d67ac73cb1690436625c0de4b4 7d4bc9c2b946c5eec044fa6d3902dfe4 |
Remediation
- Block threat indicators at your respective controls
- Always be suspicious of the emails sent by unknown senders
- Never click on the links/ attachments sent by unknown users/senders