| download: | 2018-1411_Documents00117663814426.pdf.z |
| Full analysis: | https://app.any.run/tasks/fdb869c4-0365-47da-b529-6ece83be6230 |
| Verdict: | Malicious activity |
| Threats: | NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website. |
| Analysis date: | November 15, 2018, 10:50:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 209B054FE79D00984181DFDDE01EDAC3 |
| SHA1: | D37407523F20915E76EB4EAA5FE56FA5A984DD58 |
| SHA256: | A4AB85F7876AB0B5286E6ADF872A92B4F368EF0C0569758DB5E09D8D91EEC9A5 |
| SSDEEP: | 6144:ChX0kzU+UcEn9zvlERmGm0B79DaqdYX7wKZ3KMjj47oJvpHJyNRQihMPqN:CR0xdvGm70FRVdYXsG3KMK0pHJSQ2GS |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 476 | "C:\Windows\System32\schtasks.exe" /run /tn "Utilbrligt" | C:\Windows\System32\schtasks.exe | — | 2018-1411_Documents00117663814426.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2312 | "C:\Windows\System32\schtasks.exe" /run /tn "Utilbrligt" | C:\Windows\System32\schtasks.exe | — | 2018-1411_Documents00117663814426.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2524 | "C:\Windows\System32\schtasks.exe" /Create /SC HOURLY /MO 23 /TN "Utilbrligt" /TR "reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "\""Utilbrligt"\"" /f /t REG_SZ /d "\""C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe\"" | C:\Windows\System32\schtasks.exe | — | 2018-1411_Documents00117663814426.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2628 | "C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe" | C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe | 2018-1411_Documents00117663814426.exe | ||||||||||||
User: admin Company: FURORES Integrity Level: MEDIUM Description: Vurofenceen Exit code: 0 Version: 4.02.0009 Modules
| |||||||||||||||
| 2936 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa4080.5689\2018-1411_Documents00117663814426.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa4080.5689\2018-1411_Documents00117663814426.exe | WinRAR.exe | ||||||||||||
User: admin Company: FURORES Integrity Level: MEDIUM Description: Vurofenceen Exit code: 0 Version: 4.02.0009 Modules
| |||||||||||||||
| 3200 | "C:\Windows\System32\schtasks.exe" /Create /SC HOURLY /MO 23 /TN "Utilbrligt" /TR "reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "\""Utilbrligt"\"" /f /t REG_SZ /d "\""C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe\"" | C:\Windows\System32\schtasks.exe | — | 2018-1411_Documents00117663814426.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3220 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa4080.8514\2018-1411_Documents00117663814426.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa4080.8514\2018-1411_Documents00117663814426.exe | — | WinRAR.exe | |||||||||||
User: admin Company: FURORES Integrity Level: MEDIUM Description: Vurofenceen Exit code: 0 Version: 4.02.0009 Modules
| |||||||||||||||
| 3304 | C:\Windows\system32\reg.EXE add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Utilbrligt" /f /t REG_SZ /d "C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe" | C:\Windows\system32\reg.EXE | taskeng.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3732 | C:\Windows\system32\reg.EXE add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Utilbrligt" /f /t REG_SZ /d "C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe" | C:\Windows\system32\reg.EXE | taskeng.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3840 | "C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe" | C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe | — | 2018-1411_Documents00117663814426.exe | |||||||||||
User: admin Company: FURORES Integrity Level: MEDIUM Description: Vurofenceen Exit code: 0 Version: 4.02.0009 Modules
| |||||||||||||||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\2018-1411_Documents00117663814426.pdf.z | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (4080) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2936 | 2018-1411_Documents00117663814426.exe | C:\Users\admin\AppData\Local\VirtualStore\Windows\畓潲敦据敥n | text | |
MD5:— | SHA256:— | |||
| 4080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4080.5689\2018-1411_Documents00117663814426.exe | executable | |
MD5:— | SHA256:— | |||
| 2628 | Fjeligt9.exe | C:\Users\admin\AppData\Local\VirtualStore\Windows\畓潲敦据敥n | — | |
MD5:— | SHA256:— | |||
| 3220 | 2018-1411_Documents00117663814426.exe | C:\Users\admin\AppData\Local\VirtualStore\Windows\畓潲敦据敥n | — | |
MD5:— | SHA256:— | |||
| 4080 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4080.8514\2018-1411_Documents00117663814426.exe | executable | |
MD5:— | SHA256:— | |||
| 2936 | 2018-1411_Documents00117663814426.exe | C:\Users\admin\AppData\Local\Temp\Fjeligt9.exe | executable | |
MD5:— | SHA256:— | |||
| 2628 | Fjeligt9.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\TCP Monitor\tcpmon.exe | executable | |
MD5:— | SHA256:— | |||
| 2628 | Fjeligt9.exe | C:\Users\admin\AppData\Roaming\90059C37-1320-41A4-B58D-2B75A9850D2F\run.dat | text | |
MD5:— | SHA256:— | |||
| 3840 | Fjeligt9.exe | C:\Users\admin\AppData\Local\VirtualStore\Windows\畓潲敦据敥n | — | |
MD5:— | SHA256:— | |||
| 2936 | 2018-1411_Documents00117663814426.exe | C:\Users\admin\AppData\Local\Temp\~DF2C07F13794609DC0.TMP | binary | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2628 | Fjeligt9.exe | 8.8.8.8:53 | — | Google Inc. | US | malicious |
2628 | Fjeligt9.exe | 185.244.30.121:7878 | — | — | — | malicious |
Domain | IP | Reputation |
|---|---|---|
irokko.ddns.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2628 | Fjeligt9.exe | A Network Trojan was detected | SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain |
2628 | Fjeligt9.exe | A Network Trojan was detected | SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain |
2628 | Fjeligt9.exe | A Network Trojan was detected | SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain |
2628 | Fjeligt9.exe | A Network Trojan was detected | SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain |
2628 | Fjeligt9.exe | A Network Trojan was detected | SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain |
2628 | Fjeligt9.exe | A Network Trojan was detected | SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain |
2628 | Fjeligt9.exe | A Network Trojan was detected | SC BAD_UNKNOWN DYNAMIC_DNS Query to a Suspicious *.ddns.net Domain |