File name: | NanoCore 1.2.2.0 (1).zip |
Full analysis: | https://app.any.run/tasks/01976d4e-59aa-40c1-aef2-4e666ba8ada8 |
Verdict: | Malicious activity |
Analysis date: | November 08, 2018, 18:05:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 447BDB4513F3227FF375A7F90111B3F7 |
SHA1: | 269A664F7A0155BB7116BB7DE10D94CD972CC71F |
SHA256: | 2E29028768904CFCA3EF980998232005E55A064D5156FF82846DD94F86C0800D |
SSDEEP: | 98304:zr8SNLi4OeqDkBWcmg6OItz1R5dXWr+yl5jvj6Z61UBCFCH/IxCFJDCn03VgkdP7:zJXnIcB6D1JWiyf65B2hkrDK03VlDROg |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | NanoCore 1.2.2.0/ |
---|---|
ZipUncompressedSize: | - |
ZipCompressedSize: | - |
ZipCRC: | 0x00000000 |
ZipModifyDate: | 2018:01:21 14:29:24 |
ZipCompression: | None |
ZipBitFlag: | - |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3608 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NanoCore 1.2.2.0 (1).zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
3700 | "C:\Users\admin\Desktop\NanoCore 1.2.2.0\NanoCore.exe" | C:\Users\admin\Desktop\NanoCore 1.2.2.0\NanoCore.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Description: NanoCore Exit code: 3221225595 Version: 1.2.2.0 | ||||
1348 | "C:\Users\admin\Desktop\NanoCore 1.2.2.0\NanoCore.exe" | C:\Users\admin\Desktop\NanoCore 1.2.2.0\NanoCore.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Description: NanoCore Exit code: 3221225595 Version: 1.2.2.0 | ||||
3496 | "C:\Users\admin\Desktop\NanoCore 1.2.2.0\PluginCompiler.exe" | C:\Users\admin\Desktop\NanoCore 1.2.2.0\PluginCompiler.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Description: Exit code: 3221225595 Version: 1.2.0.0 | ||||
716 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Version: 7.00.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\NanoCore 1.2.2.0 (1).zip | |||
(PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (716) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (716) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E |
Operation: | write | Name: | @C:\Windows\System32\msxml3r.dll,-1 |
Value: XML Document |
PID | Process | Filename | Type | |
---|---|---|---|---|
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\Databases\main.sqlite | sqlite | |
MD5:D763BE72920115E752DC949F9559F1CB | SHA256:95F96791FDC34F00512DB9A1088170C5843939FB283566FEEF98DC93C09B3447 | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\client.bin | executable | |
MD5:906A949E34472F99BA683EFF21907231 | SHA256:9D3EA5AF7DC261BF93C76F55D702A315AA22FB241E4207DC86CD834C262245C8 | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\NanoCore.exe | executable | |
MD5:A9FCDB1DF9F40107C98218F3C12528F9 | SHA256:A62CE60523E61AD01518C278BCD5A3BD386AECD64A31387F4A41A5A5BCBAA108 | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\builder.log | text | |
MD5:7C1DFDE6434A38A2DD0F4794B4A51175 | SHA256:96EF7F03E4AB6B860C9DA6E8D1817D9DAD6AAFBB93869B1619920FF63D3B8724 | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\Plugins\MultiCore.ncp | binary | |
MD5:BECB82E1E914E906BE158E3F9DD658AC | SHA256:5494ADF651FC64E3AA6C08E38165D8DBFEC52056CDF4FADAE90B76B0E6816A33 | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\PluginCompiler.exe | executable | |
MD5:D2CFF08AFD4FC84614B7038FD966C77B | SHA256:4EBDB8D71B9610452B0B6E47A328E4789D578051B934C8313AF14A84A76998B0 | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\plugins.bin | binary | |
MD5:5E709FC806E8BA3385487699004F6D29 | SHA256:9ECBF989DEDF1403DB953FB4E5955C9F63415CBE1F6492C3246BAC405A4D036F | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\Plugins\NanoBrowser.ncp | binary | |
MD5:8B13FDC96AF0A84C152F5A601DCC6B06 | SHA256:997C41B05150480BCFAE9ABB3132FC807F6C6B511B810B554FDB5AEDF89F5DB0 | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\Databases\network.sqlite | sqlite | |
MD5:856342A3A887715F53CD7277A2B220AF | SHA256:DE1CC5F927BDC0ACE22CF11BEBE0B83977B16338A97724E2489302A0FCDA0173 | |||
3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3608.38982\NanoCore 1.2.2.0\ClientPlugin.xml | xml | |
MD5:5D0381A56563B1CA8928E3CF087F1625 | SHA256:0497B92461C2A9CE3101D9397FB3079F60979164336A16653D282273D3085BCC |