| URL: | https://f004.backblazeb2.com/file/SoulseekQt/SoulseekQt-2024-2-1-64bit.exe |
| Full analysis: | https://app.any.run/tasks/ceee9dcd-6ed8-43e4-96ec-944cdf254e83 |
| Verdict: | Malicious activity |
| Threats: | NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website. |
| Analysis date: | March 08, 2025, 21:04:58 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 8D552B7F5600045ED1554B52422F1ACB |
| SHA1: | 0C97C005D53A271CDCB5412C50EBFDA5EBBEFB12 |
| SHA256: | A60CE65B10EA1413FB5146F9E0B4B2955231D57945101239CC3CE82C02E17E03 |
| SSDEEP: | 3:N8n7qHJ3ZzotlOoK2LYlOoIumTR+N:27YJe1Ktl1IukRq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1072 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2360 --field-trial-handle=2136,i,11247799361282824812,3067418440225084484,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1116 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6132 --field-trial-handle=2136,i,11247799361282824812,3067418440225084484,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1128 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1196 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5796 --field-trial-handle=2136,i,11247799361282824812,3067418440225084484,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1272 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7392 --field-trial-handle=2296,i,6929181568552476806,2106549495026788074,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1660 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5260 --field-trial-handle=2136,i,11247799361282824812,3067418440225084484,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1760 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5024 --field-trial-handle=2136,i,11247799361282824812,3067418440225084484,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2040 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1288 --field-trial-handle=2136,i,11247799361282824812,3067418440225084484,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2240 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x294,0x298,0x29c,0x28c,0x2b4,0x7ffc88805fd8,0x7ffc88805fe4,0x7ffc88805ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (7236) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (7236) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (7236) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (7236) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (6044) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6044) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6044) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6044) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (6044) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (6044) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | DisableFirstRunCustomize |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF10b76b.TMP | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF10b76b.TMP | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10b76b.TMP | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10b77a.TMP | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF10b76b.TMP | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7236 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
7384 | svchost.exe | GET | 206 | 23.50.131.85:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/44953cfd-a8de-4bf2-87a0-43bfd8331a40?P1=1741982560&P2=404&P3=2&P4=QYkmsR5poBRMak9qBk42hcaIIHX5TH%2f%2bEYKlW28Afn5rmPc7TvjJsyZOrVxaIx%2bOK3sEnZj4CmHoQrvithbIfg%3d%3d | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7236 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
7488 | msedge.exe | 52.123.224.66:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7488 | msedge.exe | 149.137.128.16:443 | f004.backblazeb2.com | BACKBLAZE | US | malicious |
7488 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7488 | msedge.exe | 13.107.6.158:443 | business.bing.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
f004.backblazeb2.com |
| malicious |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
business.bing.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
edgeservices.bing.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspected AllBass Phishing (f004 .backblazeb2 .com) |
7488 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspected AllBass Phishing (f004 .backblazeb2 .com) |
7488 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspected AllBass Phishing (f004 .backblazeb2 .com) |
7488 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] B2 Cloud Storage (.backblazeb2 .com) |
3020 | SoulseekQt.exe | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
3020 | SoulseekQt.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 434 |
3020 | SoulseekQt.exe | Misc Attack | ET TOR Known Tor Exit Node Traffic group 34 |
3020 | SoulseekQt.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 34 |
3020 | SoulseekQt.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 309 |
3020 | SoulseekQt.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 74 |