| File name: | NVIDIA Share.exe |
| Full analysis: | https://app.any.run/tasks/dc0d30b3-82de-4bc0-8f1a-db59310ec2ce |
| Verdict: | Malicious activity |
| Threats: | DCrat, also known as Dark Crystal RAT, is a remote access trojan (RAT), which was first introduced in 2018. It is a modular malware that can be customized to perform different tasks. For instance, it can steal passwords, crypto wallet information, hijack Telegram and Steam accounts, and more. Attackers may use a variety of methods to distribute DCrat, but phishing email campaigns are the most common. |
| Analysis date: | September 07, 2024, 16:18:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C1F0C5AAFA36AB9E85E33D4810640A55 |
| SHA1: | E3001BB5EA45B02349850F34D44531E28AF9CC85 |
| SHA256: | 51A5E5E3E680A3CAB1F9EA4D705037FF4EE8301FC1DCA8AFAE3B5714749BA07B |
| SSDEEP: | 98304:wyi3eXRJwbFMjSgVe/hE02ABuNlCN7LnN6nUori3h2pt5c73FFhhmeU4azPKpWCw:INSl |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:03:03 13:15:57+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.3 |
| CodeSize: | 203776 |
| InitializedDataSize: | 101376 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1f530 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 360 | schtasks.exe /create /tn "IdleI" /sc MINUTE /mo 11 /tr "'C:\Users\All Users\Idle.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1496 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2128 | schtasks.exe /create /tn "Memory Compression" /sc ONLOGON /tr "'C:\Users\admin\Downloads\Memory Compression.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Local\Temp\NVIDIA Share.exe" | C:\Users\admin\AppData\Local\Temp\NVIDIA Share.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2224 | schtasks.exe /create /tn "Memory CompressionM" /sc MINUTE /mo 13 /tr "'C:\Users\admin\Downloads\Memory Compression.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2464 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2720 | schtasks.exe /create /tn "MoUsoCoreWorkerM" /sc MINUTE /mo 6 /tr "'C:\Users\Public\MoUsoCoreWorker.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2816 | schtasks.exe /create /tn "IdleI" /sc MINUTE /mo 8 /tr "'C:\Users\All Users\Idle.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4076 | schtasks.exe /create /tn "sihosts" /sc MINUTE /mo 10 /tr "'C:\Windows\Tasks\sihost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4164 | schtasks.exe /create /tn "dllhostd" /sc MINUTE /mo 9 /tr "'C:\Users\Default\Pictures\dllhost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2208) NVIDIA Share.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbe\OpenWithProgids |
| Operation: | write | Name: | VBEFile |
Value: | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (4976) MoUsoCoreWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MoUsoCoreWorker_RASMANCS |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2208 | NVIDIA Share.exe | C:\Users\admin\AppData\Roaming\NVIDIA\cM3I0Acfi6vfQZMwt.vbe | vbe | |
MD5:02FD07EDD00E6CAC4197B169D409A893 | SHA256:5AA739C9F35D4E7762C17CB83B9E90F46124B7B12FAB3707E0E5FB39B294A101 | |||
| 2208 | NVIDIA Share.exe | C:\Users\admin\AppData\Roaming\NVIDIA\MjDgJCX1b5kbsHkeSp5vS8ADlws6j58rPgjvfDs.bat | text | |
MD5:821A53C99B822F905D8FA87B76A4B715 | SHA256:38D8D0F3719027B875D54AC465AE47EB63C866EC88DC6929F102E06DE1D9635A | |||
| 2208 | NVIDIA Share.exe | C:\Users\admin\AppData\Roaming\NVIDIA\NVIDIA Share.exe | executable | |
MD5:8AA4EE38B9AB7ECB03EE7F86ED3AFC12 | SHA256:8EE79B27F13623F27FAE4B057DA0862DCAF4F5249E51C58B0B113FACD99B5E63 | |||
| 6824 | NVIDIA Share.exe | C:\ProgramData\Idle.exe | executable | |
MD5:8AA4EE38B9AB7ECB03EE7F86ED3AFC12 | SHA256:8EE79B27F13623F27FAE4B057DA0862DCAF4F5249E51C58B0B113FACD99B5E63 | |||
| 6824 | NVIDIA Share.exe | C:\Users\Default\Pictures\dllhost.exe | executable | |
MD5:8AA4EE38B9AB7ECB03EE7F86ED3AFC12 | SHA256:8EE79B27F13623F27FAE4B057DA0862DCAF4F5249E51C58B0B113FACD99B5E63 | |||
| 6824 | NVIDIA Share.exe | C:\Windows\Tasks\66fc9ff0ee96c2 | text | |
MD5:613F274DAAC4710F42B8C79339964C85 | SHA256:0C3E20D04BA8E7ACB65663AF928892FAFB33651AD9969C8CDBD8454EA67E842D | |||
| 6824 | NVIDIA Share.exe | C:\Users\Default\Pictures\5940a34987c991 | text | |
MD5:C91FAD561E0592E7675719A74415BB40 | SHA256:B4045D108DE749E844BF437A068D8C4399C6F4556192F2C04FFB2B8AA1474FBD | |||
| 6824 | NVIDIA Share.exe | C:\ProgramData\6ccacd8608530f | text | |
MD5:8A2849CD9DEA9F214C36D54CF6A58377 | SHA256:DC55386392866F61F0E0B3D355BFBD1EAA9DBC33ADA15CE857E5A7CDD6AF3E71 | |||
| 6824 | NVIDIA Share.exe | C:\Users\admin\Desktop\vdpSqLTB.log | executable | |
MD5:D478E398EFCD2BD9BDBFEA958F7BEE4F | SHA256:32E821193BE1D81BB3BE97F2719D28A0C7DD2E5BD94DC581D79A1497462EAC9B | |||
| 6824 | NVIDIA Share.exe | C:\Users\admin\AppData\Local\Temp\d84029cc8b7dbf74b187233303eefdd21883bb6f | text | |
MD5:4A6A30132B22F4CBCEDBF534AC2799CF | SHA256:9488A6C9477DF87C1EE35F94FFE9A3F9C4FAB56B8B5A4EB8E8F9AAA83D74A53B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1332 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6876 | svchost.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4976 | MoUsoCoreWorker.exe | POST | 200 | 91.214.78.75:80 | http://91.214.78.75/wp/91apiProtect/Pipe/Better/Base/flowerPythonSqlBase/private6/LineLinuxcdn/DbPrivate.php | unknown | — | — | unknown |
4976 | MoUsoCoreWorker.exe | POST | 200 | 91.214.78.75:80 | http://91.214.78.75/wp/91apiProtect/Pipe/Better/Base/flowerPythonSqlBase/private6/LineLinuxcdn/DbPrivate.php | unknown | — | — | unknown |
4976 | MoUsoCoreWorker.exe | POST | 200 | 91.214.78.75:80 | http://91.214.78.75/wp/91apiProtect/Pipe/Better/Base/flowerPythonSqlBase/private6/LineLinuxcdn/DbPrivate.php | unknown | — | — | unknown |
1432 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4976 | MoUsoCoreWorker.exe | POST | 200 | 91.214.78.75:80 | http://91.214.78.75/wp/91apiProtect/Pipe/Better/Base/flowerPythonSqlBase/private6/LineLinuxcdn/DbPrivate.php | unknown | — | — | unknown |
4976 | MoUsoCoreWorker.exe | POST | 200 | 91.214.78.75:80 | http://91.214.78.75/wp/91apiProtect/Pipe/Better/Base/flowerPythonSqlBase/private6/LineLinuxcdn/DbPrivate.php | unknown | — | — | unknown |
4976 | MoUsoCoreWorker.exe | POST | 200 | 91.214.78.75:80 | http://91.214.78.75/wp/91apiProtect/Pipe/Better/Base/flowerPythonSqlBase/private6/LineLinuxcdn/DbPrivate.php | unknown | — | — | unknown |
4976 | MoUsoCoreWorker.exe | POST | 200 | 91.214.78.75:80 | http://91.214.78.75/wp/91apiProtect/Pipe/Better/Base/flowerPythonSqlBase/private6/LineLinuxcdn/DbPrivate.php | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4316 | RUXIMICS.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6876 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6876 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6876 | svchost.exe | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2120 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1332 | svchost.exe | 20.190.159.75:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1332 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4976 | MoUsoCoreWorker.exe | A Network Trojan was detected | REMOTE [ANY.RUN] DarkCrystal Rat Check-in (POST) |
4976 | MoUsoCoreWorker.exe | A Network Trojan was detected | ET MALWARE [ANY.RUN] DarkCrystal Rat Check-in (POST) |
4976 | MoUsoCoreWorker.exe | Misc activity | SUSPICIOUS [ANY.RUN] Possible DarkCrystal Rat Encrypted Connection |
4976 | MoUsoCoreWorker.exe | A suspicious string was detected | SUSPICIOUS [ANY.RUN] Sending an HTTP request body with a Base64 encoded ZIP file |
4976 | MoUsoCoreWorker.exe | A Network Trojan was detected | ET MALWARE [ANY.RUN] DarkCrystal Rat Exfiltration (POST) |
4976 | MoUsoCoreWorker.exe | A Network Trojan was detected | REMOTE [ANY.RUN] DarkCrystal Rat Exfiltration (POST) |