| File name: | Dox_Tool_V2.exe |
| Full analysis: | https://app.any.run/tasks/61ae531c-fedc-4ac9-b8ad-8b19d4a540b9 |
| Verdict: | Malicious activity |
| Threats: | NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website. |
| Analysis date: | May 29, 2021, 17:32:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | F1BE942862AD25C53F8F14A7A942BFDA |
| SHA1: | 21A0F8C1C1AA75545B3E0C9D5AE1880BCAAADFA3 |
| SHA256: | FD34112A0025E5455CF180799B62DBD495D72D67EBAF739731E0DF8C5B40EFF0 |
| SSDEEP: | 1536:luDKVw90Gyw0o1lwIXw+wsEvwJXw06q0bJwxXy9VsH5qM/J029w7NBwi/T5wpStj:luxi |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (82.9) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (7.4) |
| .exe | | | Win32 Executable (generic) (5.1) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| AssemblyVersion: | 1.460.510.611 |
|---|---|
| ProductVersion: | 1.460.510.611 |
| ProductName: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 |
| OriginalFileName: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟.exe |
| LegalTrademarks: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 |
| InternalName: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟.exe |
| LegalCopyright: | All Rights Reserved |
| FileVersion: | 1.460.510.611 |
| FileDescription: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 |
| CompanyName: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 Inc. |
| Comments: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 |
| CharacterSet: | Windows, Latin1 |
| LanguageCode: | English (U.S.) |
| FileSubtype: | - |
| ObjectFileType: | Dynamic link library |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x003f |
| ProductVersionNumber: | 1.460.510.611 |
| FileVersionNumber: | 1.460.510.611 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 6 |
| ImageVersion: | - |
| OSVersion: | 4 |
| EntryPoint: | 0x3d29fe |
| UninitializedDataSize: | - |
| InitializedDataSize: | 3072 |
| CodeSize: | 4000768 |
| LinkerVersion: | 48 |
| PEType: | PE32 |
| TimeStamp: | 2059:10:03 10:06:47+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 28-Aug-1923 01:38:31 |
| Detected languages: |
|
| Comments: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 |
| CompanyName: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 Inc. |
| FileDescription: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 |
| FileVersion: | 1.460.510.611 |
| LegalCopyright: | All Rights Reserved |
| InternalName: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟.exe |
| LegalTrademarks: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 |
| OriginalFilename: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟.exe |
| ProductName: | 㤮㥡㤱㤴㤰㥪㤵㥞㤰㤯㥃㤰㤰㤭㤳㤵㤯㥞㥠㥡㥞㤲㥱㤰㤲㥈㤱㤬㤰㤲㤱㥝㤰㥒㥟㤰㤬㥟㥠㥞㥩㤮㤯㥋㥡㥟 |
| ProductVersion: | 1.460.510.611 |
| Assembly Version: | 1.460.510.611 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000080 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 28-Aug-1923 01:38:31 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00002000 | 0x003D0A04 | 0x003D0C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 2.5506 |
.rsrc | 0x003D4000 | 0x0000081C | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.98117 |
.reloc | 0x003D6000 | 0x0000000C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.0815394 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.00112 | 490 | Latin 1 / Western European | UNKNOWN | RT_MANIFEST |
mscoree.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Windows\Resources\Themes\aero\Shell\5J479fb54ca084Qc322IBap902RVbT9i3Ru32fda2w4g4c\svchost.exe" -Force | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | 8Bebf4badnbc9R3F693xl1cg70e52010b.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | |||||||||||||||
| 376 | sc stop InstallService | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 444 | "C:\Windows\TEMP\127741ce-f216-469d-91c2-f60d35d0e60e\AdvancedRun.exe" /EXEFilename "C:\Windows\TEMP\127741ce-f216-469d-91c2-f60d35d0e60e\test.bat" /WindowState ""0"" /PriorityClass ""32"" /CommandLine "" /StartDirectory "" /RunAs 8 /Run | C:\Windows\TEMP\127741ce-f216-469d-91c2-f60d35d0e60e\AdvancedRun.exe | — | 8Bebf4badnbc9R3F693xl1cg70e52010b.exe | |||||||||||
User: SYSTEM Company: NirSoft Integrity Level: HIGH Description: Run a program with different settings that you choose. Exit code: 0 Version: 1.22 Modules
| |||||||||||||||
| 540 | sc config Sense start= disabled | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 540 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Windows\Resources\Themes\aero\Shell\5J479fb54ca084Qc322IBap902RVbT9i3Ru32fda2w4g4c\svchost.exe" -Force | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Dox_Tool_V2.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 560 | sc config SecurityHealthService start= disabled | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 660 | sc stop SecurityHealthService | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 660 | sc config usosvc start= disabled | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 668 | "C:\Users\admin\AppData\Local\Temp\Dox_Tool_V2.exe" | C:\Users\admin\AppData\Local\Temp\Dox_Tool_V2.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 672 | sc config windefend start= disabled | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2808) cmstp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2808) cmstp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2808) cmstp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2808) cmstp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2808) cmstp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (2808) cmstp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (2808) cmstp.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Network\Network Connections |
| Operation: | write | Name: | DesktopShortcut |
Value: 0 | |||
| (PID) Process: | (2764) DllHost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe |
| Operation: | write | Name: | ProfileInstallPath |
Value: C:\ProgramData\Microsoft\Network\Connections\Cm | |||
| (PID) Process: | (2764) DllHost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion |
| Operation: | write | Name: | SM_AccessoriesName |
Value: Accessories | |||
| (PID) Process: | (2764) DllHost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion |
| Operation: | write | Name: | PF_AccessoriesName |
Value: Accessories | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2256 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\A3M1IO736BW3A646XUXP.temp | — | |
MD5:— | SHA256:— | |||
| 2944 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5QDY1WBC8GEC53KEEEI8.temp | — | |
MD5:— | SHA256:— | |||
| 3928 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TQDPKNSK9H86Z506ENRZ.temp | — | |
MD5:— | SHA256:— | |||
| 2724 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2D54EE9J83SN9XDJYHJY.temp | — | |
MD5:— | SHA256:— | |||
| 2440 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TN2PBZA69788IZJZMIFW.temp | — | |
MD5:— | SHA256:— | |||
| 668 | Dox_Tool_V2.exe | C:\windows\temp\ang2rlm5.inf | ini | |
MD5:— | SHA256:— | |||
| 2548 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\39BKJF5UU2954VOUIX2S.temp | — | |
MD5:— | SHA256:— | |||
| 2176 | Dox_Tool_V2.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8Bebf4badnbc9R3F693xl1cg70e52010b.exe | executable | |
MD5:— | SHA256:— | |||
| 2944 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:— | SHA256:— | |||
| 3896 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RWOKJGP6N1ZGMO03ON4T.temp | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4008 | Dox_Tool_V2.exe | 8.8.8.8:53 | — | Google Inc. | US | malicious |
4008 | Dox_Tool_V2.exe | 91.109.190.2:1605 | 12KX.sytes.net | Lost Oasis SARL | NL | malicious |
— | — | 8.8.8.8:53 | — | Google Inc. | US | malicious |
— | — | 91.109.190.2:1605 | 12KX.sytes.net | Lost Oasis SARL | NL | malicious |
Domain | IP | Reputation |
|---|---|---|
12KX.sytes.net |
| malicious |