| File name: | NanoCore 1.2.2.0_Cracked By Alcatraz3222.rar |
| Full analysis: | https://app.any.run/tasks/5d338cac-04c9-4c0c-a4ff-e4e7564fd151 |
| Verdict: | Malicious activity |
| Analysis date: | January 10, 2019, 14:44:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | B503DAE91C8591B708DE239431896A26 |
| SHA1: | 9045A05BDDF56D2A11F2E7736E742CEA90FF03B7 |
| SHA256: | 84C3D629D2C9FDB8F142172851C3B63CFAE6AED020985C06FCD838CBD4AFCCBA |
| SSDEEP: | 98304:QqCoJGzrY4vrFnMcN+i/3o0yt0RBZqo/+ylLjvjYZb1UBCFCm/IxCFPztndU7B1U:FXGz0WrFM8+KPgoGytYQB28kBztndI1U |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3080 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NanoCore 1.2.2.0_Cracked By Alcatraz3222.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3204 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\NanoCore.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\NanoCore.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: NanoCore Exit code: 0 Version: 1.2.2.0 Modules
| |||||||||||||||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\NanoCore 1.2.2.0_Cracked By Alcatraz3222.rar | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Databases\main.sqlite | sqlite | |
MD5:90B3717210CCD4C2E15923E4A5AF9017 | SHA256:AAC36B2E3D13BBF3AEB6D2CF40CD9BEC6DE38DF56ADB01783BBA7D55EFE281DB | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\ClientPlugin.xml | xml | |
MD5:5D0381A56563B1CA8928E3CF087F1625 | SHA256:0497B92461C2A9CE3101D9397FB3079F60979164336A16653D282273D3085BCC | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\ClientPlugin.dll | executable | |
MD5:BDC8945F1D799C845408522E372D1DBD | SHA256:61E9D5C0727665E9EF3F328141397BE47C65ED11AB621C644B5BBF1D67138403 | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Databases\geolocation.sqlite | sqlite | |
MD5:0E8D861CDDEDE3A0B2B02CFC0B060B99 | SHA256:11BD851D8994D3CA9D078144679AA2DC06841ADDD0947B8FA8AD36758BDECF7A | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\NanoBlack.ncp | binary | |
MD5:794AB16C092EBF2B1D812D6CCE158537 | SHA256:7919B7998D6B359D7CB700018DC2D69FF6FFB45BD01C9C190B98FB4C9FF4BEAB | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\NanoCore.exe | executable | |
MD5:1728ACC244115CBAFD3B810277D2E321 | SHA256:EC359F50CA15395F273899C0FF7C0CD87AB5C2E23FDCFC6C72FEDC0097161D4B | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\MiscTools.ncp | binary | |
MD5:78E3006FC6468EB7DFC7761072B84AC6 | SHA256:3A3A3B105EEFB45E3B70CC1592E484DF02DF7020D5154E8C2E5D7D439E295E46 | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\AIO.ncp | binary | |
MD5:60C274CCB344DA9E3D77449F6068D253 | SHA256:0A59AAEE013C57F3B6190D683160D88CA1C5868565CBF5ACBB7B17D3E925C602 | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\CorePlugin.ncp | binary | |
MD5:7914E7302F72D330AA5F6C5C8C26DF43 | SHA256:F66985518B1E56A04F512D110F5B79F21ED91CBCBF6BD3E17EBA3DCDFB85F9B5 | |||
| 3080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\NanoCoreSwiss.ncp | binary | |
MD5:FCB5AFD01E75ACA8ED9FBD35A46E54F3 | SHA256:BF0386F6E9B4A35FEFE5FE917E2BE7C64867EFE24521F18E4567F8AF5F6DD5E5 | |||
Domain | IP | Reputation |
|---|---|---|
lazyshare.net |
| unknown |
Process | Message |
|---|---|
NanoCore.exe | Trying to load native SQLite library "C:\Users\admin\AppData\Local\Temp\Rar$EXa3080.49496\NanoCore 1.2.2.0_Cracked By Alcatraz3222\x86\SQLite.Interop.dll"...
|