| File name: | NanoCore 1.2.2.0_Cracked By Alcatraz3222.rar |
| Full analysis: | https://app.any.run/tasks/8c99d166-a97d-4e02-bcb7-b4b47297295f |
| Verdict: | Malicious activity |
| Analysis date: | July 16, 2019, 22:42:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | C75744769BAE7A3E7A4A1AEC27673851 |
| SHA1: | 56B0AA88B44C532BE4975BC096CB8E4B9E7ECB49 |
| SHA256: | CEB348DFA61B34BEBCE021FA783B0AFDB874EA7205F75E7FB42B01898439BE75 |
| SSDEEP: | 98304:5S+zg4KC/4ObL3j/ZV2tKRcHhMBJcPpylijvjTZi1UBCFCX/IxCF+/h0k98nRDdj:51kC/40z3tKMrcByIT1B2zkA/Ck92thv |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 3066 |
|---|---|
| UncompressedSize: | 22746 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2016:06:05 21:53:28 |
| PackingMethod: | Best Compression |
| ArchivedFileName: | NanoCore 1.2.2.0_Cracked By Alcatraz3222\builder.log |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2804 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47953\NanoCore 1.2.2.0_Cracked By Alcatraz3222\PluginCompiler.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47953\NanoCore 1.2.2.0_Cracked By Alcatraz3222\PluginCompiler.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 1.2.0.0 Modules
| |||||||||||||||
| 3476 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NanoCore 1.2.2.0_Cracked By Alcatraz3222.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\NanoCore.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\NanoCore.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: NanoCore Exit code: 0 Version: 1.2.2.0 Modules
| |||||||||||||||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\NanoCore 1.2.2.0_Cracked By Alcatraz3222.rar | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\ClientPlugin.dll | executable | |
MD5:BDC8945F1D799C845408522E372D1DBD | SHA256:61E9D5C0727665E9EF3F328141397BE47C65ED11AB621C644B5BBF1D67138403 | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Databases\main.sqlite | sqlite | |
MD5:EA522FC387E8E1C1C65E946C9118E2C7 | SHA256:AE429DBFCA9416CFC6832AED1190FA7B9EB90127328136A249DE024349FD3B3B | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\NanoBlack.ncp | binary | |
MD5:794AB16C092EBF2B1D812D6CCE158537 | SHA256:7919B7998D6B359D7CB700018DC2D69FF6FFB45BD01C9C190B98FB4C9FF4BEAB | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\AIO.ncp | binary | |
MD5:60C274CCB344DA9E3D77449F6068D253 | SHA256:0A59AAEE013C57F3B6190D683160D88CA1C5868565CBF5ACBB7B17D3E925C602 | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\CorePlugin.ncp | binary | |
MD5:7914E7302F72D330AA5F6C5C8C26DF43 | SHA256:F66985518B1E56A04F512D110F5B79F21ED91CBCBF6BD3E17EBA3DCDFB85F9B5 | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\DucPlugin.ncp | binary | |
MD5:5ECA68A8368E0E144B7016E30B85515C | SHA256:E2CE89B3E68B003CB27E2C5652CCBA073C8938BEF194E51830539B2464A3F676 | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\ManagementPlugin.ncp | binary | |
MD5:B612C2C9A6D361A5DB14C04BA126119C | SHA256:B86FE4E126A9748A383A34D615B9598C715F2380C0AAD957495C66923902026C | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\MultiCore.ncp | binary | |
MD5:BECB82E1E914E906BE158E3F9DD658AC | SHA256:5494ADF651FC64E3AA6C08E38165D8DBFEC52056CDF4FADAE90B76B0E6816A33 | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\NanoBrowser.ncp | binary | |
MD5:8B13FDC96AF0A84C152F5A601DCC6B06 | SHA256:997C41B05150480BCFAE9ABB3132FC807F6C6B511B810B554FDB5AEDF89F5DB0 | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\Plugins\NanoCoreSwiss.ncp | binary | |
MD5:FCB5AFD01E75ACA8ED9FBD35A46E54F3 | SHA256:BF0386F6E9B4A35FEFE5FE917E2BE7C64867EFE24521F18E4567F8AF5F6DD5E5 | |||
Domain | IP | Reputation |
|---|---|---|
lazyshare.net |
| unknown |
Process | Message |
|---|---|
NanoCore.exe | Trying to load native SQLite library "C:\Users\admin\AppData\Local\Temp\Rar$EXa3476.47164\NanoCore 1.2.2.0_Cracked By Alcatraz3222\x86\SQLite.Interop.dll"...
|