File name:

NanoCore by Eric [SEPERATED 2].rar

Full analysis: https://app.any.run/tasks/70159e9a-0898-491f-86dd-80e3ca9691b5
Verdict: Malicious activity
Analysis date: July 10, 2019, 03:50:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

847EBD35EE75C5C8C2DFE563730225DB

SHA1:

E1F50F1313D92E80D8B409E4ACEB05A32F9C8EF2

SHA256:

DB44488821739D89CA4405750C2CB5962B0904923BA769005AA7A1EA972A48A8

SSDEEP:

196608:4wqJ5HOBNOK8YaNc7HIImIRhY2yRvsziTYQeIW:YJ5unTqghXYtvzEQHW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Infinity Crypter - Original.exe (PID: 2684)
      • MorpheusCrypter.exe (PID: 3396)
      • Infinity Crypter - Cracked by Meth.exe (PID: 3620)
      • KazyCrypter - Cracked by Meth.exe (PID: 3232)
      • KazyCrypter - Original.exe (PID: 3844)
    • Loads dropped or rewritten executable

      • KazyCrypter - Cracked by Meth.exe (PID: 3232)
    • Changes settings of System certificates

      • KazyCrypter - Original.exe (PID: 3844)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2208)
      • KazyCrypter - Cracked by Meth.exe (PID: 3232)
    • Adds / modifies Windows certificates

      • KazyCrypter - Original.exe (PID: 3844)
  • INFO

    • Manual execution by user

      • Infinity Crypter - Original.exe (PID: 2684)
      • MorpheusCrypter.exe (PID: 3396)
      • Infinity Crypter - Cracked by Meth.exe (PID: 3620)
      • NOTEPAD.EXE (PID: 2432)
      • KazyCrypter - Cracked by Meth.exe (PID: 3232)
      • KazyCrypter - Original.exe (PID: 3844)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe morpheuscrypter.exe no specs infinity crypter - original.exe infinity crypter - cracked by meth.exe no specs kazycrypter - original.exe notepad.exe no specs kazycrypter - cracked by meth.exe

Process information

PID
CMD
Path
Indicators
Parent process
2208"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NanoCore by Eric [SEPERATED 2].rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2432"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Kazy Crypter - Cracked by Meth\loader.logC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2684"C:\Users\admin\Desktop\Infinity Crypter (BETA) - Cracked by Meth\Infinity Crypter - Original.exe" C:\Users\admin\Desktop\Infinity Crypter (BETA) - Cracked by Meth\Infinity Crypter - Original.exe
explorer.exe
User:
admin
Company:
Infinity Crypter
Integrity Level:
MEDIUM
Description:
Infinity Crypter
Exit code:
0
Version:
1.5.2.1
Modules
Images
c:\users\admin\desktop\infinity crypter (beta) - cracked by meth\infinity crypter - original.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3232"C:\Users\admin\Desktop\Kazy Crypter - Cracked by Meth\KazyCrypter - Cracked by Meth.exe" C:\Users\admin\Desktop\Kazy Crypter - Cracked by Meth\KazyCrypter - Cracked by Meth.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
KazyCrypter
Exit code:
0
Version:
1.3.0.0
Modules
Images
c:\users\admin\desktop\kazy crypter - cracked by meth\kazycrypter - cracked by meth.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3396"C:\Users\admin\Desktop\Morpheus Crypter\MorpheusCrypter.exe" C:\Users\admin\Desktop\Morpheus Crypter\MorpheusCrypter.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\morpheus crypter\morpheuscrypter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3620"C:\Users\admin\Desktop\Infinity Crypter (BETA) - Cracked by Meth\Infinity Crypter - Cracked by Meth.exe" C:\Users\admin\Desktop\Infinity Crypter (BETA) - Cracked by Meth\Infinity Crypter - Cracked by Meth.exeexplorer.exe
User:
admin
Company:
Infinity Crypter
Integrity Level:
MEDIUM
Description:
Infinity Crypter
Exit code:
0
Version:
1.5.2.1
Modules
Images
c:\users\admin\desktop\infinity crypter (beta) - cracked by meth\infinity crypter - cracked by meth.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3844"C:\Users\admin\Desktop\Kazy Crypter - Cracked by Meth\KazyCrypter - Original.exe" C:\Users\admin\Desktop\Kazy Crypter - Cracked by Meth\KazyCrypter - Original.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\kazy crypter - cracked by meth\kazycrypter - original.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
568
Read events
497
Write events
70
Delete events
1

Modification events

(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2208) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NanoCore by Eric [SEPERATED 2].rar
(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
8
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2208.12970\Morpheus Crypter\RunNet
MD5:
SHA256:
2208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2208.12970\Morpheus Crypter\MorpheusCrypter.exeexecutable
MD5:
SHA256:
3844KazyCrypter - Original.exeC:\Users\admin\Desktop\Kazy Crypter - Cracked by Meth\loader.logtext
MD5:
SHA256:
2208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2208.12970\Infinity Crypter (BETA) - Cracked by Meth\Infinity Crypter - Original.exeexecutable
MD5:
SHA256:
2208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2208.12970\Kazy Crypter - Cracked by Meth\KazyCrypter - Cracked by Meth.exeexecutable
MD5:
SHA256:
2208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2208.12970\Kazy Crypter - Cracked by Meth\KazyCrypter - Original.exeexecutable
MD5:
SHA256:
2684Infinity Crypter - Original.exeC:\Users\admin\Desktop\Infinity Crypter (BETA) - Cracked by Meth\loader.logtext
MD5:
SHA256:
3232KazyCrypter - Cracked by Meth.exeC:\res\res.exeexecutable
MD5:06E06F9B5C2B4357479CEE6BD9D0DBC9
SHA256:500C95003F463D8FCE22A99DB53C4F264CFFC201A34BA96F88066DA7397C292F
3232KazyCrypter - Cracked by Meth.exeC:\Users\admin\AppData\Local\SkinSoft\OSSkin\2.8.7.0\x86\ssapihook.dllexecutable
MD5:D7F644C06B4CDE60651D02AED6B4174D
SHA256:A99EA2F5759B34859B484AFA3A58CE82A7F3BF792886A6C838DB852D517D9C0D
3232KazyCrypter - Cracked by Meth.exeC:\res\upx.exeexecutable
MD5:E9EACBB7AB4B3F66019E0A2F13A1DBA9
SHA256:0C3DC789D0A46493BD097526B920D913D930D96B1052CB331EEC3AC560C89996
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2684
Infinity Crypter - Original.exe
52.216.144.117:443
s3.amazonaws.com
Amazon.com, Inc.
US
unknown
3844
KazyCrypter - Original.exe
52.216.170.93:443
s3.amazonaws.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
seal.nimoru.com
malicious
s3.amazonaws.com
  • 52.216.144.117
  • 52.216.170.93
shared

Threats

No threats detected
No debug info