| File name: | NanoCore_1.2.2.0.exe |
| Full analysis: | https://app.any.run/tasks/2fd81678-506d-4f3f-a575-cd94eac99ab7 |
| Verdict: | Malicious activity |
| Analysis date: | August 30, 2024, 15:03:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 9F0245A3C5E691126F42EE5BB1BC1A40 |
| SHA1: | EA40C726473B6EE7E5FED2FA2E560EDCCA7D3559 |
| SHA256: | F53F62A9093F8AF6FD63F1284E2E264343E9E54080DD7345B8F0247FCA8C80B4 |
| SSDEEP: | 98304:tM5+Q2iFsD6GHlUv9t0ri8s99D/U3ThSSF4bNzIPZc26ejV0zCp0CrCOxCd6n5Mq:ap/bjhgGAFCxQrqsAuLgLNZ4a2 |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:08:14 19:15:49+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 188416 |
| InitializedDataSize: | 196096 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1cab5 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 32 | "C:\Users\admin\AppData\Local\Temp\crack.exe" | C:\Users\admin\AppData\Local\Temp\crack.exe | crack.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 420 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1184 | "C:\Users\admin\AppData\Local\Temp\Payload.exe" | C:\Users\admin\AppData\Local\Temp\Payload.exe | — | crack.exe | |||||||||||
User: admin Integrity Level: MEDIUM | |||||||||||||||
| 1436 | "C:\Users\admin\AppData\Local\Temp\Payload.exe" | C:\Users\admin\AppData\Local\Temp\Payload.exe | — | crack.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1492 | "C:\Users\admin\AppData\Local\Temp\crack.exe" | C:\Users\admin\AppData\Local\Temp\crack.exe | — | crack.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1568 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "PAAjAGkAYgBhACMAPgBBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAGoAdwBjACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAJABlAG4AdgA6AFMAeQBzAHQAZQBtAEQAcgBpAHYAZQApACAAPAAjAGwAcwBnACMAPgAgAC0ARgBvAHIAYwBlACAAPAAjAGEAdABnACMAPgA=" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | crack.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1780 | "C:\Users\admin\AppData\Local\Temp\crack.exe" | C:\Users\admin\AppData\Local\Temp\crack.exe | crack.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1944 | "C:\Users\admin\AppData\Local\Temp\Payload.exe" | C:\Users\admin\AppData\Local\Temp\Payload.exe | — | crack.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2112 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "PAAjAGkAYgBhACMAPgBBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAGoAdwBjACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAJABlAG4AdgA6AFMAeQBzAHQAZQBtAEQAcgBpAHYAZQApACAAPAAjAGwAcwBnACMAPgAgAC0ARgBvAHIAYwBlACAAPAAjAGEAdABnACMAPgA=" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | crack.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2132 | "C:\Users\admin\AppData\Local\Temp\Payload.exe" | C:\Users\admin\AppData\Local\Temp\Payload.exe | — | crack.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFavoritesInitialSelection |
Value: | |||
| (PID) Process: | (7004) NanoCore_1.2.2.0.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFeedsInitialSelection |
Value: | |||
| (PID) Process: | (2612) crack.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\Resources\Themes\Firefly.xml | xml | |
MD5:B84CFC71EB55E42464E9C8868401AF4A | SHA256:B7F01DB02FDB9C586C89C5FAE3301AF28365928CF9C5FB74084082C9AFC95227 | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\ClientPlugin.xml | xml | |
MD5:5D0381A56563B1CA8928E3CF087F1625 | SHA256:0497B92461C2A9CE3101D9397FB3079F60979164336A16653D282273D3085BCC | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\ServerPlugin.xml | xml | |
MD5:8245E02B3A884C86E66791879FB79A28 | SHA256:3CF9CC86656B3719555E76B9F86D1765BC700C6A9A8228539F0521AF96E81CDA | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\Resources\Themes\Venom.xml | xml | |
MD5:9895CAA6689F649AA4C16EA00C010AA6 | SHA256:F8701D3C100E6DA867C66D58EEC2D20519D9383DCD0CB3B3F14176CEF54E69CF | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\PluginCompiler.exe | executable | |
MD5:E2D1C5DF11F9573F6C5D0A7AD1A79FBF | SHA256:0B41B2FCD0F1A4E913D3EFE293F713849D59EFEBB27BAC060AB31BED51AC2F6B | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\x64\SQLite.Interop.dll | executable | |
MD5:382398711315E2FA8E93D305B4873908 | SHA256:270D61D183CFF3DAFAD0DB3DBE7942374552044BAEA1E28411C3A143CB620C02 | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\Resources\Themes\Default.xml | xml | |
MD5:66BED75987DFF3835A4AB05E61E619EF | SHA256:193DA22D8E0F6431CA6CCD4490C122BE113DBBAACDB973B4F1C8572A461A8047 | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\Resources\Themes\Classic.xml | xml | |
MD5:769E96DFDE51FF03A4A1B6F1B7A6F0D9 | SHA256:F35CCB8A314F11EE46668D08528F6F21F02BC7E8D5716C838623C9F0ECC557E9 | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\Resources\Themes\Ember.xml | xml | |
MD5:5DB56C0FB5A2BD0B51E4A16D62FD22D4 | SHA256:F4F2410031FE6C41FB7DC01E1AE46CFFBF226E839722C6ECB8991C485193B6C6 | |||
| 7004 | NanoCore_1.2.2.0.exe | C:\Users\admin\AppData\Local\Temp\builder.log | text | |
MD5:F4BECBF84FA42FF104B05106513289E3 | SHA256:71AD3A3F04E6869CFD4387913D0BA5E9C35125A03E852DB5D87FF3DCD7E5760F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1764 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
1496 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | DE | binary | 407 b | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | US | binary | 471 b | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | US | binary | 471 b | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | US | binary | 471 b | whitelisted |
1496 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | DE | binary | 419 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6052 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
892 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
6052 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1764 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1764 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1496 | SIHClient.exe | 20.114.59.183:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
r.bing.com |
| whitelisted |
Process | Message |
|---|---|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|
crack.exe | Invalid parameter passed to C runtime function.
|