URL:

https://onedrive.live.com/download?cid=914146BA02B70D25&resid=914146BA02B70D25%21150&authkey=ADOa3G8wVgQnyH8

Full analysis: https://app.any.run/tasks/136021be-b7ca-427a-a334-b7acd9a83dac
Verdict: Malicious activity
Threats:

NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website.

Analysis date: July 12, 2020, 10:01:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
nanocore
trojan
Indicators:
MD5:

5FE00999458174AE785BF373765DB6EE

SHA1:

D8E0CB4D8391F4BC60E04A0933F922CA5416D3E9

SHA256:

7A65AD3D4DC6F95643A1CFE7DF3886B42696A011A4C5AF7A0BFAE27C5DF1B835

SSDEEP:

3:N8Ck3CTwKbl3dLXVWAxUydLX9UUmPxpoP0Ls:2CkST/ZNjeYj9NmppoKs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2380)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1896)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2200)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2600)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2612)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3520)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2676)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3932)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 4084)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2188)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2232)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2892)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1680)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1768)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3024)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1876)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 316)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2708)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3260)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3740)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3568)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2184)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3352)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1056)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2376)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2416)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3508)
    • Writes to a start menu file

      • notepad.exe (PID: 3964)
      • notepad.exe (PID: 2296)
      • notepad.exe (PID: 1876)
      • notepad.exe (PID: 2068)
      • notepad.exe (PID: 3180)
      • notepad.exe (PID: 2488)
      • notepad.exe (PID: 1892)
      • notepad.exe (PID: 2748)
      • notepad.exe (PID: 1528)
    • Changes the autorun value in the registry

      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1896)
    • Connects to CnC server

      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1896)
    • NANOCORE was detected

      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1896)
    • Actions looks like stealing of personal data

      • vbc.exe (PID: 3584)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2660)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1896)
    • Application launched itself

      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2380)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2612)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2188)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2232)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1768)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3932)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1876)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1056)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 3568)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2184)
    • Creates files in the user directory

      • notepad.exe (PID: 3964)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1896)
      • notepad.exe (PID: 2296)
      • notepad.exe (PID: 3180)
      • notepad.exe (PID: 1876)
      • notepad.exe (PID: 2488)
      • notepad.exe (PID: 2068)
      • notepad.exe (PID: 2748)
      • notepad.exe (PID: 1892)
      • notepad.exe (PID: 1528)
    • Executes scripts

      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 1896)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 2140)
    • Reads the hosts file

      • chrome.exe (PID: 3996)
      • chrome.exe (PID: 2140)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 2140)
    • Manual execution by user

      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 2380)
      • PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe (PID: 4084)
    • Reads settings of System Certificates

      • chrome.exe (PID: 3996)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
85
Monitored processes
49
Malicious processes
15
Suspicious processes
3

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs winrar.exe chrome.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe #NANOCORE proforma invoice scan order copy 1121-pdf01.exe proforma invoice scan order copy 1121-pdf01.exe no specs chrome.exe no specs chrome.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs notepad.exe proforma invoice scan order copy 1121-pdf01.exe no specs proforma invoice scan order copy 1121-pdf01.exe no specs vbc.exe

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe"C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exePROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\proforma invoice scan order copy 1121-pdf01.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
440"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1492 --on-initialized-event-handle=324 --parent-handle=328 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
684"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1040,10233868235883514812,1713025288236457964,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=2304773832404582230 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2260 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1056"C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe" 2 3352 1537421C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exePROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\proforma invoice scan order copy 1121-pdf01.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1528"C:\Windows\system32\notepad.exe"C:\Windows\system32\notepad.exe
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1680"C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe"C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exePROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\proforma invoice scan order copy 1121-pdf01.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
1768"C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe"C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exePROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\proforma invoice scan order copy 1121-pdf01.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1876"C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe" 2 3024 1525593C:\Users\admin\Desktop\PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exePROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\imm32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winspool.drv
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernel32.dll
1876"C:\Windows\system32\notepad.exe"C:\Windows\system32\notepad.exe
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1892"C:\Windows\system32\notepad.exe"C:\Windows\system32\notepad.exe
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 695
Read events
1 616
Write events
76
Delete events
3

Modification events

(PID) Process:(440) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2140-13239021715499875
Value:
259
(PID) Process:(2140) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2140) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2140) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2140) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2140) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2140) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2140) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2140) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3120-13213713943555664
Value:
0
(PID) Process:(2140) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
2
Suspicious files
17
Text files
83
Unknown types
1

Dropped files

PID
Process
Filename
Type
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5F0ADF94-85C.pma
MD5:
SHA256:
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\9dfb211e-e29c-4519-87e5-64275e76e77c.tmp
MD5:
SHA256:
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000028.dbtmp
MD5:
SHA256:
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.oldtext
MD5:
SHA256:
2820chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pmabinary
MD5:9543068B6751E1F3E11F91D72EE78D95
SHA256:D060AD21AE6E04CB58668CAA52ADFCA573E018102CC07554D2ED3EAE11AB7785
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF15d441.TMPtext
MD5:
SHA256:
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF15d3f3.TMPtext
MD5:
SHA256:
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
2140chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF15d5f7.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
10
Threats
49

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3996
chrome.exe
172.217.23.131:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
3996
chrome.exe
13.107.42.13:443
onedrive.live.com
Microsoft Corporation
US
malicious
3996
chrome.exe
13.107.42.12:443
zcq0vq.dm.files.1drv.com
Microsoft Corporation
US
suspicious
3996
chrome.exe
172.217.21.238:443
sb-ssl.google.com
Google Inc.
US
whitelisted
3996
chrome.exe
172.217.16.164:443
www.google.com
Google Inc.
US
whitelisted
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
37.235.1.174:53
ANEXIA Internetdienstleistungs GmbH
AT
suspicious
3996
chrome.exe
172.217.23.163:443
www.gstatic.com
Google Inc.
US
whitelisted
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
194.5.97.18:8282
judge2020.ddns.net
FR
malicious
3996
chrome.exe
216.58.212.131:443
ssl.gstatic.com
Google Inc.
US
whitelisted
3996
chrome.exe
216.58.207.46:443
clients1.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 172.217.23.131
whitelisted
onedrive.live.com
  • 13.107.42.13
shared
accounts.google.com
  • 216.58.212.141
shared
zcq0vq.dm.files.1drv.com
  • 13.107.42.12
whitelisted
sb-ssl.google.com
  • 172.217.21.238
whitelisted
www.google.com
  • 172.217.16.164
malicious
ssl.gstatic.com
  • 216.58.212.131
whitelisted
judge2020.ddns.net
  • 194.5.97.18
unknown
www.gstatic.com
  • 172.217.23.163
whitelisted
clients1.google.com
  • 216.58.207.46
whitelisted

Threats

PID
Process
Class
Message
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
Potentially Bad Traffic
ET POLICY DNS Query to DynDNS Domain *.ddns .net
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
A Network Trojan was detected
REMOTE [PTsecurity] NanoCore.RAT
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
A Network Trojan was detected
REMOTE [PTsecurity] NanoCore.RAT
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
A Network Trojan was detected
REMOTE [PTsecurity] NanoCore.RAT
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
A Network Trojan was detected
REMOTE [PTsecurity] NanoCore.RAT
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
A Network Trojan was detected
REMOTE [PTsecurity] NanoCore.RAT
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
A Network Trojan was detected
REMOTE [PTsecurity] NanoCore.RAT
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
A Network Trojan was detected
REMOTE [PTsecurity] NanoCore.RAT
1896
PROFORMA INVOICE SCAN ORDER COPY 1121-PDF01.exe
A Network Trojan was detected
REMOTE [PTsecurity] NanoCore.RAT
40 ETPRO signatures available at the full report
No debug info