analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

1.rar

Full analysis: https://app.any.run/tasks/34fc7c29-7457-4e9a-ae9b-8f0c05af7f4e
Verdict: Malicious activity
Threats:

NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website.

Analysis date: February 18, 2019, 15:41:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
nanocore
rat
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6C84991B6696D0BE4A818F9B7636B16F

SHA1:

7F49618307DB32FECE3A7974077B9DE4303FAD21

SHA256:

0210F63661C825DC544F48C39B6ADCF35E81CBAC97C1B2F020D0630A4E9219A8

SSDEEP:

98304:AjDWFkDL2E1iuDFSV7Dm7AkxYnhZxX6B2iSEU0uKR:AjDkkH2E1in1SA0B2DKR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 612)
    • Changes the autorun value in the registry

      • Sony Vegas 15.exe (PID: 2988)
    • NanoCore was detected

      • Sony Vegas 15.exe (PID: 2988)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3508)
      • schtasks.exe (PID: 2512)
    • Uses Task Scheduler to run other applications

      • Sony Vegas 15.exe (PID: 2988)
    • Application was dropped or rewritten from another process

      • Sony Vegas 15.exe (PID: 2988)
    • Connects to CnC server

      • Sony Vegas 15.exe (PID: 2988)
    • Actions looks like stealing of personal data

      • vbc.exe (PID: 2940)
  • SUSPICIOUS

    • Creates files in the program directory

      • Sony Vegas 15.exe (PID: 2988)
    • Creates files in the user directory

      • Sony Vegas 15.exe (PID: 2988)
    • Executable content was dropped or overwritten

      • Sony Vegas 15.exe (PID: 2988)
    • Connects to unusual port

      • Sony Vegas 15.exe (PID: 2988)
    • Loads DLL from Mozilla Firefox

      • vbc.exe (PID: 3264)
    • Executes scripts

      • Sony Vegas 15.exe (PID: 2988)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
7
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs searchprotocolhost.exe no specs #NANOCORE sony vegas 15.exe schtasks.exe no specs schtasks.exe no specs vbc.exe vbc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3016"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
612"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
2988"C:\Users\admin\Desktop\Sony Vegas 15.exe" C:\Users\admin\Desktop\Sony Vegas 15.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
2512"schtasks.exe" /create /f /tn "TCP Monitor" /xml "C:\Users\admin\AppData\Local\Temp\tmp9DA8.tmp"C:\Windows\system32\schtasks.exeSony Vegas 15.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3508"schtasks.exe" /create /f /tn "TCP Monitor Task" /xml "C:\Users\admin\AppData\Local\Temp\tmp9E35.tmp"C:\Windows\system32\schtasks.exeSony Vegas 15.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2940"c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" /shtml "C:\Users\admin\AppData\Local\Temp\bq2mksak.o5w"c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
Sony Vegas 15.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual Basic Command Line Compiler
Exit code:
0
Version:
8.0.50727.5420
3264"c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" /shtml "C:\Users\admin\AppData\Local\Temp\regsvdv1.eat"c:\windows\microsoft.net\framework\v2.0.50727\vbc.exeSony Vegas 15.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual Basic Command Line Compiler
Exit code:
0
Version:
8.0.50727.5420
Total events
503
Read events
483
Write events
20
Delete events
0

Modification events

(PID) Process:(3016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3016) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.rar
(PID) Process:(3016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2988) Sony Vegas 15.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:TCP Monitor
Value:
C:\Program Files\TCP Monitor\tcpmon.exe
(PID) Process:(3016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
1
Suspicious files
2
Text files
3
Unknown types
1

Dropped files

PID
Process
Filename
Type
3016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3016.49144\Sony Vegas 15.exe
MD5:
SHA256:
3016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3016.49144\sftutor60.dll
MD5:
SHA256:
3016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3016.49144\SfVstProxyStubx64.dll
MD5:
SHA256:
3016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3016.49144\sfvstwrap.dll
MD5:
SHA256:
3016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3016.49144\sfscsi.dll
MD5:
SHA256:
3016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3016.49144\sfspti.dll
MD5:
SHA256:
3016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3016.49144\sftutor.dll
MD5:
SHA256:
2988Sony Vegas 15.exeC:\Users\admin\AppData\Local\Temp\tmp9DA8.tmp
MD5:
SHA256:
2940vbc.exeC:\Users\admin\AppData\Local\Temp\bq2mksak.o5w
MD5:
SHA256:
3264vbc.exeC:\Users\admin\AppData\Local\Temp\regsvdv1.eat
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2988
Sony Vegas 15.exe
8.8.8.8:53
Google Inc.
US
whitelisted
2988
Sony Vegas 15.exe
109.117.107.83:1604
ciao2.hopto.org
IT
malicious

DNS requests

Domain
IP
Reputation
ciao2.hopto.org
  • 109.117.107.83
malicious

Threats

PID
Process
Class
Message
2988
Sony Vegas 15.exe
A Network Trojan was detected
ET TROJAN Possible NanoCore C2 60B
2988
Sony Vegas 15.exe
A Network Trojan was detected
MALWARE [PTsecurity] NanoCore.RAT
2988
Sony Vegas 15.exe
A Network Trojan was detected
ET TROJAN Possible NanoCore C2 64B
2988
Sony Vegas 15.exe
A Network Trojan was detected
ET TROJAN Possible NanoCore C2 60B
2988
Sony Vegas 15.exe
A Network Trojan was detected
MALWARE [PTsecurity] NanoCore.RAT
2988
Sony Vegas 15.exe
A Network Trojan was detected
ET TROJAN Possible NanoCore C2 64B
2988
Sony Vegas 15.exe
A Network Trojan was detected
MALWARE [PTsecurity] NanoCore.RAT
2988
Sony Vegas 15.exe
A Network Trojan was detected
ET TROJAN Possible NanoCore C2 64B
2988
Sony Vegas 15.exe
A Network Trojan was detected
MALWARE [PTsecurity] NanoCore.RAT
2988
Sony Vegas 15.exe
A Network Trojan was detected
ET TROJAN Possible NanoCore C2 64B
22 ETPRO signatures available at the full report
No debug info