| File name: | funnything.exe |
| Full analysis: | https://app.any.run/tasks/4ad62793-4eaf-4ebf-9d43-cdc7f214a67f |
| Verdict: | Malicious activity |
| Threats: | NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website. |
| Analysis date: | March 02, 2024, 19:52:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 6ACA8FFD54AF068F0C7F85FA3C65C576 |
| SHA1: | 4D6DDDB08DFFCEAE59BE6D619483B825B73FD492 |
| SHA256: | 3DE5571DD02A60841B980B77961D78A3734EFA5AFD1F17416A77310473D2F5BA |
| SSDEEP: | 6144:7r+qqvRbNrmq1g5S1kFpcVeikky8gDxfQs75yn7JdbZfSfm93WVN:zaRbVmq1mjp+b+1QGkn7J9Zfsm93WVN |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 0000:00:00 00:00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | - |
| CodeSize: | - |
| InitializedDataSize: | - |
| UninitializedDataSize: | - |
| EntryPoint: | 0x0154 |
| OSVersion: | - |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 680 | "C:\Users\admin\AppData\Local\Temp\salinewin.exe" | C:\Users\admin\AppData\Local\Temp\salinewin.exe | — | nan.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1432 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\kj.vbs" | C:\Windows\System32\wscript.exe | funnything.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2632 | "C:\Users\admin\AppData\Local\Temp\salinewin.exe" | C:\Users\admin\AppData\Local\Temp\salinewin.exe | nan.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2896 | "C:\Users\admin\Desktop\nan.exe" | C:\Users\admin\Desktop\nan.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2992 | REG ADD hkcu\Software\Microsoft\Windows\CurrentVersion\policies\system /v DisableTaskMgr /t reg_dword /d 1 /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3488 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\kj.vbs" | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 3616 | C:\Windows\system32\cmd.exe /c REG ADD hkcu\Software\Microsoft\Windows\CurrentVersion\policies\system /v DisableTaskMgr /t reg_dword /d 1 /f | C:\Windows\System32\cmd.exe | — | salinewin.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\AppData\Local\Temp\funnything.exe" | C:\Users\admin\AppData\Local\Temp\funnything.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3692 | "C:\Users\admin\Desktop\nan.exe" | C:\Users\admin\Desktop\nan.exe | funnything.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
Nanocore(PID) Process(3692) nan.exe KeyboardLoggingTrue BuildTime2024-03-02 19:47:13.325304 Version1.2.2.0 Mutex2e5f3c36-4873-479c-80aa-92426c28e6ac DefaultGroupDefault PrimaryConnectionHostBaggard437.ddns.net BackupConnectionHostBaggard437.ddns.net ConnectionPort8131 RunOnStartupTrue RequestElevationFalse BypassUserAccountControlFalse ClearZoneIdentifierTrue ClearAccessControlFalse SetCriticalProcessFalse PreventSystemSleepTrue ActivateAwayModeFalse EnableDebugModeFalse RunDelay0 ConnectDelay4000 RestartDelay5006 TimeoutInterval5000 KeepAliveTimeout30000 MutexTimeout5000 LanTimeout2500 WanTimeout8003 BufferSize65535 MaxPacketSize10485760 GCThreshold10485760 UseCustomDnsServerTrue PrimaryDnsServer8.8.8.8 BackupDnsServer8.8.4.4 | |||||||||||||||
| (PID) Process: | (3668) funnything.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3668) funnything.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3668) funnything.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3668) funnything.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1432) wscript.exe | Key: | HKEY_CURRENT_USER |
| Operation: | write | Name: | KJ |
Value: No | |||
| (PID) Process: | (1432) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | System.vbs |
Value: "C:\Users\admin\AppData\Local\Temp\System.vbs" | |||
| (PID) Process: | (1432) wscript.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | System.vbs |
Value: "C:\Users\admin\AppData\Local\Temp\System.vbs" | |||
| (PID) Process: | (3692) nan.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | TCP Monitor |
Value: C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\TCP Monitor\tcpmon.exe | |||
| (PID) Process: | (1432) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1432) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2632 | salinewin.exe | \Device\Harddisk0\DR0 | — | |
MD5:— | SHA256:— | |||
| 3668 | funnything.exe | C:\Users\admin\Desktop\nan.exe | executable | |
MD5:C98F5B4483F6B0F6EE0058F2E2C49B52 | SHA256:2FA2CBE2B65BC74CB56F993E1BE684E4A31C94C4E749A278DB0EB078A471ADF3 | |||
| 3668 | funnything.exe | C:\Users\admin\Desktop\kj.vbs | text | |
MD5:1FADA102E3C8E5D9D866CC7DF94D0C32 | SHA256:977FC109161458CE8722BA42CB83A7E609F6E5AFA90855702D8797BD82B794BE | |||
| 3692 | nan.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\catalog.dat | binary | |
MD5:5C33875B0D9ED1CDD09EF767C77A9B6D | SHA256:9D1BD160E7720DC3129B93930BE4CF5093C2490994D169541FC4214CE001DBDA | |||
| 3692 | nan.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\TCP Monitor\tcpmon.exe | executable | |
MD5:C98F5B4483F6B0F6EE0058F2E2C49B52 | SHA256:2FA2CBE2B65BC74CB56F993E1BE684E4A31C94C4E749A278DB0EB078A471ADF3 | |||
| 3692 | nan.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\settings.bin | binary | |
MD5:B3AF27165C2EE971B8A61A445D77BD77 | SHA256:9C53BF0F8016861052B1709C6D6691C5490254BCBC61E1B86EB99CB934778CEF | |||
| 1432 | wscript.exe | C:\Users\admin\AppData\Local\Temp\System.vbs | text | |
MD5:1FADA102E3C8E5D9D866CC7DF94D0C32 | SHA256:977FC109161458CE8722BA42CB83A7E609F6E5AFA90855702D8797BD82B794BE | |||
| 1432 | wscript.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\System.vbs | text | |
MD5:1FADA102E3C8E5D9D866CC7DF94D0C32 | SHA256:977FC109161458CE8722BA42CB83A7E609F6E5AFA90855702D8797BD82B794BE | |||
| 3692 | nan.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\run.dat | text | |
MD5:CFF614A2B14418BC9021E86D3D4C6E8D | SHA256:D2080D69752D67869EEB37A61DD8112061D9B55C93B0427A3E9D4CEBE01D4BF4 | |||
| 3692 | nan.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\settings.bak | binary | |
MD5:B3AF27165C2EE971B8A61A445D77BD77 | SHA256:9C53BF0F8016861052B1709C6D6691C5490254BCBC61E1B86EB99CB934778CEF | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3692 | nan.exe | 139.84.139.29:8131 | Baggard437.ddns.net | AS-CHOOPA | US | malicious |
1432 | wscript.exe | 139.84.139.29:9981 | Baggard437.ddns.net | AS-CHOOPA | US | malicious |
Domain | IP | Reputation |
|---|---|---|
Baggard437.ddns.net |
| unknown |
baggard437.ddns.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3692 | nan.exe | Potentially Bad Traffic | ET POLICY DNS Query to DynDNS Domain *.ddns .net |
1080 | svchost.exe | Potentially Bad Traffic | ET POLICY DNS Query to DynDNS Domain *.ddns .net |
3692 | nan.exe | A Network Trojan was detected | ET MALWARE NanoCore RAT Keepalive Response 3 |
3692 | nan.exe | A Network Trojan was detected | ET MALWARE NanoCore RAT Keepalive Response 1 |
3692 | nan.exe | A Network Trojan was detected | ET MALWARE NanoCore RAT Keepalive Response 3 |
3692 | nan.exe | Potentially Bad Traffic | ET POLICY DNS Query to DynDNS Domain *.ddns .net |
3692 | nan.exe | A Network Trojan was detected | ET MALWARE NanoCore RAT Keepalive Response 1 |
Process | Message |
|---|---|
funnything.exe | %s%s |