File name:

bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe

Full analysis: https://app.any.run/tasks/a6573fdf-1c65-4773-9dc2-41d65154b7fc
Verdict: Malicious activity
Threats:

NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website.

Analysis date: May 15, 2025, 18:50:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
nanocore
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

3282A651D32FF0BD17FB9E5CD5FEE7BA

SHA1:

A395DCF7917E6EE7D7CF409B8484EF0A46F640A0

SHA256:

BF90356A990236ED0CCA1408F0C6CF4FE6CC70AAD795ED254F69E29036EF5B67

SSDEEP:

3072:6pjFiF4UMYXw+zcgi+oG/j9iaMP2s/HRlvA21REmUbowrqUy4OSgcD9seLez7UiB:6NFfUMuzkIM5HAEjJgqUgSgcps/z7UiB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
    • NANOCORE has been detected (YARA)

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
    • The process creates files with name similar to system file names

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
    • Reads security settings of Internet Explorer

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
    • Application launched itself

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
    • Connects to unusual port

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
  • INFO

    • Process checks whether UAC notifications are on

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
    • Creates files or folders in the user directory

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
    • Checks supported languages

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
    • Reads the machine GUID from the registry

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
    • Reads the computer name

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
    • Process checks computer location settings

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 2384)
    • Reads the software policy settings

      • slui.exe (PID: 2152)
    • Creates files in the program directory

      • bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe (PID: 3304)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:02:22 00:49:37+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 116736
InitializedDataSize: 90112
UninitializedDataSize: -
EntryPoint: 0x1e792
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe #NANOCORE bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2152"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2384"C:\Users\admin\AppData\Local\Temp\bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe" C:\Users\admin\AppData\Local\Temp\bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2552C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3272C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
3304"C:\Users\admin\AppData\Local\Temp\bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe" C:\Users\admin\AppData\Local\Temp\bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
1 451
Read events
1 448
Write events
2
Delete events
1

Modification events

(PID) Process:(2384) bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:LAN Host
Value:
C:\Users\admin\AppData\Roaming\BB926E54-E3CA-40FD-AE90-2764341E7792\LAN Host\lanhost.exe
(PID) Process:(3304) bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:LAN Host
Value:
C:\Program Files (x86)\LAN Host\lanhost.exe
(PID) Process:(3304) bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:LAN Host
Value:
C:\Users\admin\AppData\Roaming\BB926E54-E3CA-40FD-AE90-2764341E7792\LAN Host\lanhost.exe
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2384bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exeC:\Users\admin\AppData\Roaming\BB926E54-E3CA-40FD-AE90-2764341E7792\run.dattext
MD5:33B9571AD745EE96EC73EB997D0E9CD1
SHA256:DB1D9B42CAA219247E9A38B70C15AE4918592FB7753375E8192C6E87453BC369
3304bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exeC:\Program Files (x86)\LAN Host\lanhost.exeexecutable
MD5:3282A651D32FF0BD17FB9E5CD5FEE7BA
SHA256:BF90356A990236ED0CCA1408F0C6CF4FE6CC70AAD795ED254F69E29036EF5B67
2384bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exeC:\Users\admin\AppData\Roaming\BB926E54-E3CA-40FD-AE90-2764341E7792\LAN Host\lanhost.exeexecutable
MD5:3282A651D32FF0BD17FB9E5CD5FEE7BA
SHA256:BF90356A990236ED0CCA1408F0C6CF4FE6CC70AAD795ED254F69E29036EF5B67
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
33
DNS requests
23
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2104
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4988
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4988
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3768
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.139:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
192.169.69.26:8079
jerrytech.duckdns.org
SERVERSTADIUM
US
malicious
6544
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.139
  • 23.48.23.193
  • 23.48.23.190
  • 23.48.23.192
  • 23.48.23.194
  • 23.48.23.177
  • 23.48.23.138
  • 23.48.23.183
  • 23.48.23.181
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
jerrytech.duckdns.org
  • 192.169.69.26
malicious
login.live.com
  • 20.190.160.64
  • 20.190.160.130
  • 40.126.32.134
  • 40.126.32.74
  • 20.190.160.3
  • 20.190.160.66
  • 20.190.160.22
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

PID
Process
Class
Message
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Potentially Bad Traffic
ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Misc activity
ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Potentially Bad Traffic
ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Misc activity
ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Potentially Bad Traffic
ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Misc activity
ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Potentially Bad Traffic
ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Misc activity
ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Potentially Bad Traffic
ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain
3304
bf90356a990236ed0cca1408f0c6cf4fe6cc70aad795ed254f69e29036ef5b67.exe
Misc activity
ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain
No debug info