Loading ...

Play interactive tourEdit tour

Analysis Report wDIaJji4Vv.exe

Overview

General Information

Sample Name:wDIaJji4Vv.exe
Analysis ID:381644
MD5:6a0c22a8a8d9524ba012910571b57d38
SHA1:b75a74ca657f4940b251c5116bcf2d3a78773671
SHA256:cc9690dcde0dfa23d657f84bc221296c45590b595d5cca9131087638c35c8a8b
Tags:exeNanoCoreRAT
Infos:

Most interesting Screenshot:

Detection

Nanocore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected Nanocore Rat
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: NanoCore
Sigma detected: Scheduled temp file as task from temp location
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected AntiVM3
Yara detected Nanocore RAT
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Antivirus or Machine Learning detection for unpacked file
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains capabilities to detect virtual machines
Contains functionality to call native functions
Contains functionality to detect virtual machines (SGDT)
Contains functionality to detect virtual machines (SLDT)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains long sleeps (>= 3 min)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
IP address seen in connection with other malware
Installs a raw input device (often for capturing keystrokes)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains strange resources
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

Startup

  • System is w10x64
  • wDIaJji4Vv.exe (PID: 2788 cmdline: 'C:\Users\user\Desktop\wDIaJji4Vv.exe' MD5: 6A0C22A8A8D9524BA012910571B57D38)
    • powershell.exe (PID: 6104 cmdline: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath 'C:\Users\user\Desktop\wDIaJji4Vv.exe' MD5: DBA3E6449E97D4E3DF64527EF7012A10)
      • conhost.exe (PID: 404 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • schtasks.exe (PID: 3120 cmdline: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\LGKyjAEnmfdSo' /XML 'C:\Users\user\AppData\Local\Temp\tmpE049.tmp' MD5: 15FF7D8324231381BAD48A052F85DF04)
      • conhost.exe (PID: 6100 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • powershell.exe (PID: 5528 cmdline: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath 'C:\Users\user\AppData\Roaming\LGKyjAEnmfdSo.exe' MD5: DBA3E6449E97D4E3DF64527EF7012A10)
      • conhost.exe (PID: 4812 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • RegSvcs.exe (PID: 4688 cmdline: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe MD5: 71369277D09DA0830C8C59F9E22BB23A)
    • RegSvcs.exe (PID: 6172 cmdline: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe MD5: 71369277D09DA0830C8C59F9E22BB23A)
    • RegSvcs.exe (PID: 6228 cmdline: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe MD5: 71369277D09DA0830C8C59F9E22BB23A)
  • dhcpmon.exe (PID: 6744 cmdline: 'C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe' MD5: 71369277D09DA0830C8C59F9E22BB23A)
    • conhost.exe (PID: 6752 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • cleanup

Malware Configuration

Threatname: NanoCore

{"Version": "1.2.2.0", "Mutex": "282cf72b-8a92-4c1b-b768-b591a1e0", "Group": "jobo", "Domain1": "james12.ddns.net", "Domain2": "127.0.0.1", "Port": 6060, "KeyboardLogging": "Enable", "RunOnStartup": "Enable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "", "BackupDNSServer": ""}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
0000000C.00000002.484889407.0000000006880000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x59eb:$x1: NanoCore.ClientPluginHost
  • 0x5b48:$x2: IClientNetworkHost
0000000C.00000002.484889407.0000000006880000.00000004.00000001.sdmpNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x59eb:$x2: NanoCore.ClientPluginHost
  • 0x6941:$s3: PipeExists
  • 0x5be1:$s4: PipeCreated
  • 0x5a05:$s5: IClientLoggingHost
0000000C.00000002.484797009.0000000006840000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x5b0b:$x1: NanoCore.ClientPluginHost
  • 0x5b44:$x2: IClientNetworkHost
0000000C.00000002.484797009.0000000006840000.00000004.00000001.sdmpNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x5b0b:$x2: NanoCore.ClientPluginHost
  • 0x5c0f:$s4: PipeCreated
  • 0x5b25:$s5: IClientLoggingHost
00000000.00000002.221605771.0000000004202000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x168295:$x1: NanoCore.ClientPluginHost
  • 0x19aab5:$x1: NanoCore.ClientPluginHost
  • 0x1682d2:$x2: IClientNetworkHost
  • 0x19aaf2:$x2: IClientNetworkHost
  • 0x16be05:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
  • 0x19e625:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
Click to see the 42 entries

Unpacked PEs

SourceRuleDescriptionAuthorStrings
12.2.RegSvcs.exe.68b0000.28.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x3d99:$x1: NanoCore.ClientPluginHost
  • 0x3db3:$x2: IClientNetworkHost
12.2.RegSvcs.exe.68b0000.28.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x3d99:$x2: NanoCore.ClientPluginHost
  • 0x4dce:$s4: PipeCreated
  • 0x3d86:$s5: IClientLoggingHost
12.2.RegSvcs.exe.67c0000.21.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x6da5:$x1: NanoCore.ClientPluginHost
  • 0x6dd2:$x2: IClientNetworkHost
12.2.RegSvcs.exe.67c0000.21.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x6da5:$x2: NanoCore.ClientPluginHost
  • 0x7d74:$s2: FileCommand
  • 0xc776:$s4: PipeCreated
  • 0x6dbf:$s5: IClientLoggingHost
12.3.RegSvcs.exe.4a2a9ed.2.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x605:$x1: NanoCore.ClientPluginHost
  • 0x3bd6:$x1: NanoCore.ClientPluginHost
  • 0x63e:$x2: IClientNetworkHost
Click to see the 132 entries

Sigma Overview

System Summary:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, ProcessId: 6228, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
Sigma detected: Scheduled temp file as task from temp locationShow sources
Source: Process startedAuthor: Joe Security: Data: Command: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\LGKyjAEnmfdSo' /XML 'C:\Users\user\AppData\Local\Temp\tmpE049.tmp', CommandLine: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\LGKyjAEnmfdSo' /XML 'C:\Users\user\AppData\Local\Temp\tmpE049.tmp', CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: 'C:\Users\user\Desktop\wDIaJji4Vv.exe' , ParentImage: C:\Users\user\Desktop\wDIaJji4Vv.exe, ParentProcessId: 2788, ProcessCommandLine: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\LGKyjAEnmfdSo' /XML 'C:\Users\user\AppData\Local\Temp\tmpE049.tmp', ProcessId: 3120

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Found malware configurationShow sources
Source: 0000000C.00000002.482083953.000000000466E000.00000004.00000001.sdmpMalware Configuration Extractor: NanoCore {"Version": "1.2.2.0", "Mutex": "282cf72b-8a92-4c1b-b768-b591a1e0", "Group": "jobo", "Domain1": "james12.ddns.net", "Domain2": "127.0.0.1", "Port": 6060, "KeyboardLogging": "Enable", "RunOnStartup": "Enable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "", "BackupDNSServer": ""}
Multi AV Scanner detection for dropped fileShow sources
Source: C:\Users\user\AppData\Roaming\LGKyjAEnmfdSo.exeReversingLabs: Detection: 25%
Multi AV Scanner detection for submitted fileShow sources
Source: wDIaJji4Vv.exeVirustotal: Detection: 60%Perma Link
Source: wDIaJji4Vv.exeReversingLabs: Detection: 25%
Yara detected Nanocore RATShow sources
Source: Yara matchFile source: 00000000.00000002.221605771.0000000004202000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 0000000C.00000002.482083953.000000000466E000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 0000000C.00000002.467839599.0000000000402000.00000040.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 0000000C.00000002.484199869.0000000005EC0000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: Process Memory Space: wDIaJji4Vv.exe PID: 2788, type: MEMORY
Source: Yara matchFile source: Process Memory Space: RegSvcs.exe PID: 6228, type: MEMORY
Source: Yara matchFile source: 12.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 12.2.RegSvcs.exe.5ec0000.18.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.wDIaJji4Vv.exe.435a108.4.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 12.2.RegSvcs.exe.4676f00.9.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.wDIaJji4Vv.exe.4262458.3.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 12.2.RegSvcs.exe.5ec0000.18.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 12.2.RegSvcs.exe.467b529.8.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.wDIaJji4Vv.exe.4202638.5.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.wDIaJji4Vv.exe.435a108.4.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 12.2.RegSvcs.exe.4676f00.9.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 12.2.RegSvcs.exe.5ec4629.17.raw.unpack, type: UNPACKEDPE
Machine Learning detection for dropped fileShow sources
Source: C:\Users\user\AppData\Roaming\LGKyjAEnmfdSo.exeJoe Sandbox ML: detected
Machine Learning detection for sampleShow sources
Source: wDIaJji4Vv.exeJoe Sandbox ML: detected
Source: 12.2.RegSvcs.exe.400000.0.unpackAvira: Label: TR/Dropper.MSIL.Gen7
Source: 12.2.RegSvcs.exe.5ec0000.18.unpackAvira: Label: TR/NanoCore.fadte
Source: 12.2.RegSvcs.exe.4676f00.9.unpackAvira: Label: TR/NanoCore.fadte
Source: wDIaJji4Vv.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Source: C:\Users\user\Desktop\wDIaJji4Vv.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dllJump to behavior
Source: wDIaJji4Vv.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb_RO source: RegSvcs.exe, 0000000C.00000002.475547237.0000000003125000.00000004.00000040.sdmp
Source: Binary string: System.pdbL source: RegSvcs.exe, 0000000C.00000002.475547237.0000000003125000.00000004.00000040.sdmp
Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\MyNanoCore RemoteScripting\MyClientPlugin\obj\Debug\MyClientPluginNew.pdb source: RegSvcs.exe, 0000000C.00000002.484797009.0000000006840000.00000004.00000001.sdmp
Source: Binary string: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.pdb source: RegSvcs.exe, 0000000C.00000002.475547237.0000000003125000.00000004.00000040.sdmp
Source: Binary string: System.EnterpriseServices.Wrapper.pdb source: dhcpmon.exe, 0000000E.00000002.253699119.0000000004FA0000.00000002.00000001.sdmp
Source: Binary string: C:\Windows\dll\System.pdbws source: RegSvcs.exe, 0000000C.00000002.475547237.0000000003125000.00000004.00000040.sdmp
Source: Binary string: indows\System.pdbpdbtem.pdbE= source: RegSvcs.exe, 0000000C.00000002.475547237.0000000003125000.00000004.00000040.sdmp
Source: Binary string: indows\RegSvcs.pdbpdbvcs.pdb source: RegSvcs.exe, 0000000C.00000002.475547237.0000000003125000.00000004.00000040.sdmp
Source: Binary string: C:\Windows\symbols\exe\RegSvcs.pdb source: RegSvcs.exe, 0000000C.00000002.475547237.0000000003125000.00000004.00000040.sdmp
Source: Binary string: RegSvcs.pdb source: dhcpmon.exe, dhcpmon.exe.12.dr
Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: RegSvcs.exe, 0000000C.00000003.451562866.0000000004A08000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\NanoCoreStressTester\NanoCoreStressTester\obj\Debug\NanoCoreStressTester.pdb source: RegSvcs.exe, 0000000C.00000003.451562866.0000000004A08000.00000004.00000001.sdmp
Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: RegSvcs.exe, 0000000C.00000003.451562866.0000000004A08000.00000004.00000001.sdmp
Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: RegSvcs.exe, 0000000C.00000002.484889407.0000000006880000.00000004.00000001.sdmp
Source: Binary string: System.pdbX source: RegSvcs.exe, 0000000C.00000002.475547237.0000000003125000.00000004.00000040.sdmp
Source: Binary string: mscorrc.pdb source: wDIaJji4Vv.exe, 00000000.00000002.224866978.00000000053A0000.00000002.00000001.sdmp, RegSvcs.exe, 0000000C.00000002.483961085.0000000005BC0000.00000002.00000001.sdmp
Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: RegSvcs.exe, 0000000C.00000003.451562866.0000000004A08000.00000004.00000001.sdmp
Source: C:\Users\user\Desktop\wDIaJji4Vv.exeCode function: 4x nop then add dword ptr [ebp-04h], 01h0_2_05330C48
Source: C:\Users\user\Desktop\wDIaJji4Vv.exeCode function: 4x nop then mov dword ptr [ebp-1Ch], 00000000h0_2_0533C9C8
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeCode function: 4x nop then lea esp, dword ptr [ebp-0Ch]12_2_06B381F6
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeCode function: 4x nop then lea esp, dword ptr [ebp-0Ch]12_2_06B381F8
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeCode function: 4x nop then mov esp, ebp12_2_06B34370

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49715 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49721 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49722 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49725 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49729 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49730 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49732 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49734 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49735 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49743 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49753 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49754 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49755 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49756 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49759 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49760 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49761 -> 79.134.225.7:6060
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49762 -> 79.134.225.7:6060
C2 URLs / IPs found in malware configurationShow sources
Source: Malware configuration extractorURLs: james12.ddns.net
Source: Malware configuration extractorURLs: 127.0.0.1
Uses dynamic DNS servicesShow sources
Source: unknownDNS query: name: james12.ddns.net
Source: global trafficTCP traffic: 192.168.2.3:49715 -> 79.134.225.7:6060
Source: Joe Sandbox ViewIP Address: 79.134.225.7 79.134.225.7
Source: Joe Sandbox ViewASN Name: FINK-TELECOM-SERVICESCH FINK-TELECOM-SERVICESCH
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: unknownUDP traffic detected without corresponding DNS query: 37.235.1.174
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeCode function: 12_2_058A2AE6 WSARecv,12_2_058A2AE6
Source: unknownDNS traffic detected: queries for: james12.ddns.net
Source: powershell.exe, 00000007.00000003.220596810.00000000032B3000.00000004.00000001.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: RegSvcs.exe, 0000000C.00000002.484889407.0000000006880000.00000004.00000001.sdmpString found in binary or memory: http://google.com
Source: wDIaJji4Vv.exeString found in binary or memory: http://www.fileden.com/files/2011/10/5/3204996/curver.txt
Source: powershell.exe, 00000002.00000003.278956963.00000000053E8000.00000004.00000001.sdmpString found in binary or memory: https://go.microX%
Source: wDIaJji4Vv.exe, 00000000.00000002.217455924.0000000003191000.00000004.00000001.sdmpString found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css