Loading ...

Play interactive tourEdit tour

Windows Analysis Report R6093846s-Invoice-Receipt.exe

Overview

General Information

Sample Name:R6093846s-Invoice-Receipt.exe
Analysis ID:452642
MD5:cd0645cb78b55f0babbdbc4d51f23bd8
SHA1:f5221832b2b4b7338bc21e42f7e2c983d82dbdf4
SHA256:5b618273e08f4e9633ec359cff551345d0dabf0c64da9d3b5437d1c88c4bd226
Tags:exeNanoCoreRAT
Infos:

Most interesting Screenshot:

Detection

Nanocore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected Nanocore Rat
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: NanoCore
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Nanocore RAT
.NET source code contains potential unpacker
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Antivirus or Machine Learning detection for unpacked file
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Installs a raw input device (often for capturing keystrokes)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains strange resources
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Tries to load missing DLLs
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

Process Tree

  • System is w10x64
  • R6093846s-Invoice-Receipt.exe (PID: 5520 cmdline: 'C:\Users\user\Desktop\R6093846s-Invoice-Receipt.exe' MD5: CD0645CB78B55F0BABBDBC4D51F23BD8)
    • schtasks.exe (PID: 5288 cmdline: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\UALCBPTejUQxQ' /XML 'C:\Users\user\AppData\Local\Temp\tmpCCAD.tmp' MD5: 15FF7D8324231381BAD48A052F85DF04)
      • conhost.exe (PID: 5812 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • RegSvcs.exe (PID: 6204 cmdline: {path} MD5: 2867A3817C9245F7CF518524DFD18F28)
    • RegSvcs.exe (PID: 6232 cmdline: {path} MD5: 2867A3817C9245F7CF518524DFD18F28)
  • cleanup

Malware Configuration

Threatname: NanoCore

{"Version": "1.2.2.0", "Mutex": "f8dffc54-5ec5-4013-9de8-d8d85368", "Group": "CODEDBASE", "Domain1": "omaprilcode.duckdns.org", "Domain2": "omaprilcode.duckdns.org", "Port": 8090, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000014.00000002.485019554.0000000006B10000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x5b99:$x1: NanoCore.ClientPluginHost
  • 0x5bb3:$x2: IClientNetworkHost
00000014.00000002.485019554.0000000006B10000.00000004.00000001.sdmpNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x5b99:$x2: NanoCore.ClientPluginHost
  • 0x6bce:$s4: PipeCreated
  • 0x5b86:$s5: IClientLoggingHost
00000014.00000002.484978078.0000000006AF0000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x59eb:$x1: NanoCore.ClientPluginHost
  • 0x5b48:$x2: IClientNetworkHost
00000014.00000002.484978078.0000000006AF0000.00000004.00000001.sdmpNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x59eb:$x2: NanoCore.ClientPluginHost
  • 0x6941:$s3: PipeExists
  • 0x5be1:$s4: PipeCreated
  • 0x5a05:$s5: IClientLoggingHost
00000014.00000002.483826250.0000000005440000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0xe75:$x1: NanoCore.ClientPluginHost
  • 0xe8f:$x2: IClientNetworkHost
Click to see the 45 entries

Unpacked PEs

SourceRuleDescriptionAuthorStrings
20.2.RegSvcs.exe.6b30000.32.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x170b:$x1: NanoCore.ClientPluginHost
  • 0x1725:$x2: IClientNetworkHost
20.2.RegSvcs.exe.6b30000.32.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x170b:$x2: NanoCore.ClientPluginHost
  • 0x34b6:$s4: PipeCreated
  • 0x16f8:$s5: IClientLoggingHost
20.2.RegSvcs.exe.6190000.23.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x2dbb:$x1: NanoCore.ClientPluginHost
  • 0x2de5:$x2: IClientNetworkHost
20.2.RegSvcs.exe.6190000.23.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x2dbb:$x2: NanoCore.ClientPluginHost
  • 0x4c6b:$s4: PipeCreated
20.2.RegSvcs.exe.6a80000.24.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x6da5:$x1: NanoCore.ClientPluginHost
  • 0x6dd2:$x2: IClientNetworkHost
Click to see the 114 entries

Sigma Overview

AV Detection:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe, ProcessId: 6232, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

E-Banking Fraud:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe, ProcessId: 6232, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

Stealing of Sensitive Information:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe, ProcessId: 6232, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

Remote Access Functionality:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe, ProcessId: 6232, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Found malware configurationShow sources
Source: 00000014.00000002.479043770.0000000003891000.00000004.00000001.sdmpMalware Configuration Extractor: NanoCore {"Version": "1.2.2.0", "Mutex": "f8dffc54-5ec5-4013-9de8-d8d85368", "Group": "CODEDBASE", "Domain1": "omaprilcode.duckdns.org", "Domain2": "omaprilcode.duckdns.org", "Port": 8090, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}
Multi AV Scanner detection for domain / URLShow sources
Source: omaprilcode.duckdns.orgVirustotal: Detection: 8%Perma Link
Source: omaprilcode.duckdns.orgVirustotal: Detection: 8%Perma Link
Multi AV Scanner detection for dropped fileShow sources
Source: C:\Users\user\AppData\Roaming\UALCBPTejUQxQ.exeReversingLabs: Detection: 32%
Multi AV Scanner detection for submitted fileShow sources
Source: R6093846s-Invoice-Receipt.exeReversingLabs: Detection: 32%
Yara detected Nanocore RATShow sources
Source: Yara matchFile source: 20.2.RegSvcs.exe.5b90000.20.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.448b680.14.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.38dff64.5.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.5b90000.20.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.432aae0.11.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.R6093846s-Invoice-Receipt.exe.385f080.2.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 0.2.R6093846s-Invoice-Receipt.exe.385f080.2.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.38dff64.5.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.38e458d.7.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.5b94629.21.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.432f109.13.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.38db12e.6.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.448b680.14.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.4325caa.12.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.420b931.10.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.448fca9.16.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.448684a.15.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.432aae0.11.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.422c192.8.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 20.2.RegSvcs.exe.4217b65.9.raw.unpack, type: UNPACKEDPE
Source: Yara matchFile source: 00000014.00000002.484104685.0000000005B90000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000014.00000002.480562084.0000000004325000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000014.00000002.470391681.0000000000402000.00000040.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000014.00000002.479043770.0000000003891000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000014.00000002.480703873.0000000004486000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000000.00000002.305161176.000000000396B000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000014.00000002.474458367.0000000002891000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000014.00000002.480187851.0000000004161000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: 00000000.00000002.304879840.0000000003759000.00000004.00000001.sdmp, type: MEMORY
Source: Yara matchFile source: Process Memory Space: RegSvcs.exe PID: 6232, type: MEMORY
Machine Learning detection for dropped fileShow sources
Source: C:\Users\user\AppData\Roaming\UALCBPTejUQxQ.exeJoe Sandbox ML: detected
Machine Learning detection for sampleShow sources
Source: R6093846s-Invoice-Receipt.exeJoe Sandbox ML: detected
Source: 20.2.RegSvcs.exe.5b90000.20.unpackAvira: Label: TR/NanoCore.fadte
Source: 20.2.RegSvcs.exe.400000.0.unpackAvira: Label: TR/Dropper.MSIL.Gen7
Source: R6093846s-Invoice-Receipt.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Source: R6093846s-Invoice-Receipt.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\MyNanoCore RemoteScripting\MyClientPlugin\obj\Debug\MyClientPluginNew.pdb source: RegSvcs.exe, 00000014.00000002.480187851.0000000004161000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: RegSvcs.exe, 00000014.00000002.480562084.0000000004325000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Daan\source\repos\NanoExploit\ClientTest\obj\Debug\ClientTest.pdb source: RegSvcs.exe, 00000014.00000002.480562084.0000000004325000.00000004.00000001.sdmp
Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: RegSvcs.exe, 00000014.00000002.480562084.0000000004325000.00000004.00000001.sdmp
Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: RegSvcs.exe, 00000014.00000002.480562084.0000000004325000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Daan\source\repos\NanoExploit\ClientTest\obj\Debug\ClientTest.pdbS.m. _._CorDllMainmscoree.dll source: RegSvcs.exe, 00000014.00000002.480562084.0000000004325000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: RegSvcs.exe, 00000014.00000002.480562084.0000000004325000.00000004.00000001.sdmp
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exeCode function: 4x nop then lea esp, dword ptr [ebp-08h]20_2_06BA1D80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exeCode function: 4x nop then lea esp, dword ptr [ebp-08h]20_2_06BA1D72

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49727 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49737 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49740 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49746 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49747 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49748 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49749 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49752 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49753 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49754 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49755 -> 185.244.26.194:8090
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49756 -> 185.244.26.194:8090
C2 URLs / IPs found in malware configurationShow sources
Source: Malware configuration extractorURLs: omaprilcode.duckdns.org
Uses dynamic DNS servicesShow sources
Source: unknownDNS query: name: omaprilcode.duckdns.org
Source: global trafficTCP traffic: 192.168.2.3:49727 -> 185.244.26.194:8090
Source: Joe Sandbox ViewASN Name: VAMU-ASIP-TRANSITVAMURU VAMU-ASIP-TRANSITVAMURU
Source: unknownDNS traffic detected: queries for: omaprilcode.duckdns.org
Source: R6093846s-Invoice-Receipt.exe, 00000000.00000002.318334259.000000000BCB2000.00000004.00000001.sdmpString found in binary or memory: http://fontfabrik.com
Source: RegSvcs.exe, 00000014.00000002.480562084.0000000004325000.00000004.00000001.sdmpString found in binary or memory: http://google.com
Source: R6093846s-Invoice-Receipt.exe, 00000000.00000002.297808598.0000000002751000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name