Loading ...

Play interactive tourEdit tour

Analysis Report ANS_309487487_#049844874.exe

Overview

General Information

Sample Name:ANS_309487487_#049844874.exe
Analysis ID:383118
MD5:203109ad6d2efdca0bf52cab63a7ce6a
SHA1:471d5a99a2e8bfe03a9e119b327c45b6994ffaf6
SHA256:5e7e5b02d1de0da6b91520884a92af6f7597fd2e39ec5b714ba089815785ad74
Infos:

Most interesting Screenshot:

Detection

Nanocore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected Nanocore Rat
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Sigma detected: NanoCore
Sigma detected: Scheduled temp file as task from temp location
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected AntiVM3
Yara detected Nanocore RAT
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Antivirus or Machine Learning detection for unpacked file
Contains capabilities to detect virtual machines
Contains long sleeps (>= 3 min)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
IP address seen in connection with other malware
Installs a raw input device (often for capturing keystrokes)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

Startup

  • System is w10x64
  • ANS_309487487_#049844874.exe (PID: 5688 cmdline: 'C:\Users\user\Desktop\ANS_309487487_#049844874.exe' MD5: 203109AD6D2EFDCA0BF52CAB63A7CE6A)
    • schtasks.exe (PID: 4012 cmdline: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\zgEmPmIdAWvDGJ' /XML 'C:\Users\user\AppData\Local\Temp\tmpDC3C.tmp' MD5: 15FF7D8324231381BAD48A052F85DF04)
      • conhost.exe (PID: 5592 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • RegSvcs.exe (PID: 5404 cmdline: {path} MD5: 2867A3817C9245F7CF518524DFD18F28)
      • schtasks.exe (PID: 4904 cmdline: 'schtasks.exe' /create /f /tn 'DHCP Monitor' /xml 'C:\Users\user\AppData\Local\Temp\tmp6007.tmp' MD5: 15FF7D8324231381BAD48A052F85DF04)
        • conhost.exe (PID: 5864 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • schtasks.exe (PID: 4132 cmdline: 'schtasks.exe' /create /f /tn 'DHCP Monitor Task' /xml 'C:\Users\user\AppData\Local\Temp\tmp6940.tmp' MD5: 15FF7D8324231381BAD48A052F85DF04)
        • conhost.exe (PID: 4500 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • RegSvcs.exe (PID: 5400 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe 0 MD5: 2867A3817C9245F7CF518524DFD18F28)
    • conhost.exe (PID: 5564 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • dhcpmon.exe (PID: 5824 cmdline: 'C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe' 0 MD5: 2867A3817C9245F7CF518524DFD18F28)
    • conhost.exe (PID: 5864 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • dhcpmon.exe (PID: 6360 cmdline: 'C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe' MD5: 2867A3817C9245F7CF518524DFD18F28)
    • conhost.exe (PID: 6368 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • cleanup

Malware Configuration

Threatname: NanoCore

{"Version": "1.2.2.0", "Mutex": "15fbba02-3f99-4e02-884c-0827498f", "Group": "1118", "Domain1": "myhustle.duckdns.org", "Domain2": "", "Port": 1118, "KeyboardLogging": "Enable", "RunOnStartup": "Enable", "RequestElevation": "Disable", "BypassUAC": "Enable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4", "BypassUserAccountControlData": "<?xml version=\"1.0\" encoding=\"UTF-16\"?>\r\n<Task version=\"1.2\" xmlns=\"http://schemas.microsoft.com/windows/2004/02/mit/task\">\r\n  <RegistrationInfo />\r\n  <Triggers />\r\n  <Principals>\r\n    <Principal id=\"Author\">\r\n      <LogonType>InteractiveToken</LogonType>\r\n      <RunLevel>HighestAvailable</RunLevel>\r\n    </Principal>\r\n  </Principals>\r\n  <Settings>\r\n    <MultipleInstancesPolicy>Parallel</MultipleInstancesPolicy>\r\n    <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>\r\n    <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>\r\n    <AllowHardTerminate>true</AllowHardTerminate>\r\n    <StartWhenAvailable>false</StartWhenAvailable>\r\n    <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>\r\n    <IdleSettings>\r\n      <StopOnIdleEnd>false</StopOnIdleEnd>\r\n      <RestartOnIdle>false</RestartOnIdle>\r\n    </IdleSettings>\r\n    <AllowStartOnDemand>true</AllowStartOnDemand>\r\n    <Enabled>true</Enabled>\r\n    <Hidden>false</Hidden>\r\n    <RunOnlyIfIdle>false</RunOnlyIfIdle>\r\n    <WakeToRun>false</WakeToRun>\r\n    <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>\r\n    <Priority>4</Priority>\r\n  </Settings>\r\n  <Actions Context=\"Author\">\r\n    <Exec>\r\n      <Command>\"#EXECUTABLEPATH\"</Command>\r\n      <Arguments>$(Arg0)</Arguments>\r\n    </Exec>\r\n  </Actions>\r\n</Task"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000004.00000002.497078079.0000000006CF0000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x8ba5:$x1: NanoCore.ClientPluginHost
  • 0x8bd2:$x2: IClientNetworkHost
00000004.00000002.497078079.0000000006CF0000.00000004.00000001.sdmpNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x8ba5:$x2: NanoCore.ClientPluginHost
  • 0x9b74:$s2: FileCommand
  • 0xe576:$s4: PipeCreated
  • 0x8bbf:$s5: IClientLoggingHost
00000004.00000002.497210658.0000000006D50000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x13a8:$x1: NanoCore.ClientPluginHost
00000004.00000002.497210658.0000000006D50000.00000004.00000001.sdmpNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x13a8:$x2: NanoCore.ClientPluginHost
  • 0x1486:$s4: PipeCreated
  • 0x13c2:$s5: IClientLoggingHost
00000004.00000002.497223355.0000000006D60000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x59eb:$x1: NanoCore.ClientPluginHost
  • 0x5b48:$x2: IClientNetworkHost
Click to see the 43 entries

Unpacked PEs

SourceRuleDescriptionAuthorStrings
4.2.RegSvcs.exe.6d80000.25.raw.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x5b99:$x1: NanoCore.ClientPluginHost
  • 0x5bb3:$x2: IClientNetworkHost
4.2.RegSvcs.exe.6d80000.25.raw.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x5b99:$x2: NanoCore.ClientPluginHost
  • 0x6bce:$s4: PipeCreated
  • 0x5b86:$s5: IClientLoggingHost
4.2.RegSvcs.exe.64e0000.14.raw.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0xe75:$x1: NanoCore.ClientPluginHost
  • 0xe8f:$x2: IClientNetworkHost
4.2.RegSvcs.exe.64e0000.14.raw.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0xe75:$x2: NanoCore.ClientPluginHost
  • 0x1261:$s3: PipeExists
  • 0x1136:$s4: PipeCreated
  • 0xeb0:$s5: IClientLoggingHost
4.2.RegSvcs.exe.6df0000.30.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x41ee:$x1: NanoCore.ClientPluginHost
  • 0x422b:$x2: IClientNetworkHost
Click to see the 104 entries

Sigma Overview

System Summary:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe, ProcessId: 5404, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
Sigma detected: Scheduled temp file as task from temp locationShow sources
Source: Process startedAuthor: Joe Security: Data: Command: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\zgEmPmIdAWvDGJ' /XML 'C:\Users\user\AppData\Local\Temp\tmpDC3C.tmp', CommandLine: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\zgEmPmIdAWvDGJ' /XML 'C:\Users\user\AppData\Local\Temp\tmpDC3C.tmp', CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: 'C:\Users\user\Desktop\ANS_309487487_#049844874.exe' , ParentImage: C:\Users\user\Desktop\ANS_309487487_#049844874.exe, ParentProcessId: 5688, ProcessCommandLine: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\zgEmPmIdAWvDGJ' /XML 'C:\Users\user\AppData\Local\Temp\tmpDC3C.tmp', ProcessId: 4012

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Found malware configurationShow sources
Source: 00000004.00000002.490957634.0000000003FE9000.00000004.00000001.sdmpMalware Configuration Extractor: NanoCore {"Version": "1.2.2.0", "Mutex": "15fbba02-3f99-4e02-884c-0827498f", "Group": "1118", "Domain1": "myhustle.duckdns.org", "Domain2": "", "Port": 1118, "KeyboardLogging": "Enable", "RunOnStartup": "Enable", "RequestElevation": "Disable", "BypassUAC": "Enable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4", "BypassUserAccountControlData": "<?xml version=\"1.0\" encoding=\"UTF-16\"?>\r\n<Task version=\"1.2\" xmlns=\"http://schemas.microsoft.com/windows/2004/02/mit/task\">\r\n <RegistrationInfo />\r\n <Triggers />\r\n <Principals>\r\n <Principal id=\"Author\">\r\n <LogonType>InteractiveToken</LogonType>\r\n <RunLevel>HighestAvailable</RunLevel>\r\n </Principal>\r\n </Principals>\r\n <Settings>\r\n <MultipleInstancesPolicy>Parallel</MultipleInstancesPolicy>\r\n <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>\r\n <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>\r\n <AllowHardTerminate>true</AllowHardTerminate>\r\n <StartWhenAvailable>false</StartWhenAvailable>\r\n <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>\r\n <IdleSettings>\r\n <StopOnIdleEnd>false</StopOnIdleEnd>\r\n <RestartOnIdle>false</RestartOnIdle>\r\n </IdleSettings>\r\n <AllowStartOnDemand>true</AllowStartOnDemand>\r\n <Enabled>true</Enabled>\r\n <Hidden>false</Hidden>\r\n <RunOnlyIfIdle>false</RunOnlyIfIdle>\r\n <WakeToRun>false</WakeToRun>\r\n <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>\r\n <Priority>4</Priority>\r\n </Settings>\r\n <Actions Context=\"Author\">\r\n <Exec>\r\n <Command>\"#EXECUTABLEPATH\"</Command>\r\n <Arguments>$(Arg0)</Arguments>\r\n </Exec>\r\n </Actions>\r\n</Task"}
Multi AV Scanner detection for dropped fileShow sources
Source: C:\Users\user\AppData\Roaming\zgEmPmIdAWvDGJ.exeReversingLabs: Detection: 37%
Yara detected Nanocore RATShow sources
Source: Yara matchFile source: 00000000.00000002.245770427.0000000004612000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000000.00000002.245029737.0000000004459000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000004.00000002.484801611.0000000000402000.00000040.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000004.00000002.496231866.0000000006570000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000004.00000002.493121486.00000000043CC000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000004.00000002.488658155.0000000002FA1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000004.00000002.490957634.0000000003FE9000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: Process Memory Space: RegSvcs.exe PID: 5404, type: MEMORY
Source: Yara matchFile source: 4.2.RegSvcs.exe.43d1030.9.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.3ff0624.3.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.3ff0624.3.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.ANS_309487487_#049844874.exe.485ffb8.4.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.3feb7ee.2.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.3ff4c4d.4.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.6574629.16.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.6570000.15.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.6570000.15.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.ANS_309487487_#049844874.exe.485ffb8.4.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.43cc1fa.8.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.43d5659.10.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.ANS_309487487_#049844874.exe.461f788.2.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.ANS_309487487_#049844874.exe.47b8168.3.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 4.2.RegSvcs.exe.43d1030.9.raw.unpack, type: UNPACKEDPE
Source: 4.2.RegSvcs.exe.400000.0.unpackAvira: Label: TR/Dropper.MSIL.Gen7
Source: 4.2.RegSvcs.exe.6570000.15.unpackAvira: Label: TR/NanoCore.fadte
Source: ANS_309487487_#049844874.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Source: ANS_309487487_#049844874.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: RegSvcs.pdb, source: RegSvcs.exe, 00000004.00000003.250320525.00000000012C8000.00000004.00000001.sdmp, dhcpmon.exe, 0000000E.00000002.266011315.0000000000042000.00000002.00020000.sdmp, dhcpmon.exe, 00000011.00000002.281116598.00000000002A2000.00000002.00020000.sdmp, dhcpmon.exe.4.dr
Source: Binary string: Svcs.pdbE source: RegSvcs.exe, 00000004.00000002.486523461.0000000001275000.00000004.00000020.sdmp
Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb,h source: RegSvcs.exe, 00000004.00000002.486523461.0000000001275000.00000004.00000020.sdmp
Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\MyNanoCore RemoteScripting\MyClientPlugin\obj\Debug\MyClientPluginNew.pdb source: RegSvcs.exe, 00000004.00000002.492533618.0000000004168000.00000004.00000001.sdmp
Source: Binary string: RegSvcs.pdb source: dhcpmon.exe, dhcpmon.exe.4.dr
Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: RegSvcs.exe, 00000004.00000002.492533618.0000000004168000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\NanoCoreStressTester\NanoCoreStressTester\obj\Debug\NanoCoreStressTester.pdb source: RegSvcs.exe, 00000004.00000002.492533618.0000000004168000.00000004.00000001.sdmp
Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: RegSvcs.exe, 00000004.00000002.492533618.0000000004168000.00000004.00000001.sdmp
Source: Binary string: System.pdb source: RegSvcs.exe, 00000004.00000003.303453473.0000000006798000.00000004.00000001.sdmp
Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: RegSvcs.exe, 00000004.00000002.492533618.0000000004168000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: RegSvcs.exe, 00000004.00000002.492533618.0000000004168000.00000004.00000001.sdmp
Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb^h/ source: RegSvcs.exe, 00000004.00000002.486523461.0000000001275000.00000004.00000020.sdmp
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]4_2_0692C120

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49709 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49715 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49719 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49720 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49722 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49723 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49724 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49726 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49735 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49736 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49738 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49740 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49741 -> 185.140.53.9:1118
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49742 -> 185.140.53.9:1118
C2 URLs / IPs found in malware configurationShow sources
Source: Malware configuration extractorURLs:
Source: Malware configuration extractorURLs: myhustle.duckdns.org
Uses dynamic DNS servicesShow sources
Source: unknownDNS query: name: myhustle.duckdns.org
Source: global trafficTCP traffic: 192.168.2.5:49709 -> 185.140.53.9:1118
Source: Joe Sandbox ViewIP Address: 185.140.53.9 185.140.53.9
Source: Joe Sandbox ViewASN Name: DAVID_CRAIGGG DAVID_CRAIGGG
Source: unknownDNS traffic detected: queries for: myhustle.duckdns.org
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://fontfabrik.com
Source: RegSvcs.exe, 00000004.00000002.492533618.0000000004168000.00000004.00000001.sdmpString found in binary or memory: http://google.com
Source: ANS_309487487_#049844874.exe, 00000000.00000002.257735814.0000000009877000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.carterandcone.coml
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fontbureau.com
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.fonts.com
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.goodfont.co.kr
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.sajatypeworks.com
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.sakkal.com
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.sandoll.co.kr
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.tiro.com
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.typography.netD
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.urwpp.deDPlease
Source: ANS_309487487_#049844874.exe, 00000000.00000002.251783792.0000000006360000.00000002.00000001.sdmpString found in binary or memory: http://www.zhongyicts.com.cn