Loading ...

Play interactive tourEdit tour

Windows Analysis Report BXym2eR0YTBKKsB.exe

Overview

General Information

Sample Name:BXym2eR0YTBKKsB.exe
Analysis ID:527362
MD5:c57dd0f3a3495b72307cd6bbe8ed0654
SHA1:792488219eb873bd7517d7b31622f3a6d6071aa9
SHA256:debeb2b87fcaf1274ea62f5ed9f7b47f8128662b7b766729c5b3aa5b3a5ab7f5
Tags:exe
Infos:

Most interesting Screenshot:

Detection

Nanocore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Sigma detected: NanoCore
Yara detected AntiVM3
Detected Nanocore Rat
Multi AV Scanner detection for dropped file
Yara detected Nanocore RAT
Connects to many ports of the same IP (likely port scanning)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Sigma detected: Suspicius Add Task From User AppData Temp
Machine Learning detection for sample
.NET source code contains potential unpacker
Injects a PE file into a foreign processes
.NET source code contains very large strings
Machine Learning detection for dropped file
Hides that the sample has been downloaded from the Internet (zone.identifier)
Uses schtasks.exe or at.exe to add and modify task schedules
Uses dynamic DNS services
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
One or more processes crash
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Installs a raw input device (often for capturing keystrokes)
Sample file is different than original file name gathered from version info
Drops PE files
Tries to load missing DLLs
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Detected TCP or UDP traffic on non-standard ports
Checks if the current process is being debugged
Binary contains a suspicious time stamp
Creates a process in suspended mode (likely to inject code)

Classification

Process Tree

  • System is w10x64
  • BXym2eR0YTBKKsB.exe (PID: 6240 cmdline: "C:\Users\user\Desktop\BXym2eR0YTBKKsB.exe" MD5: C57DD0F3A3495B72307CD6BBE8ED0654)
    • schtasks.exe (PID: 1312 cmdline: C:\Windows\System32\schtasks.exe" /Create /TN "Updates\fuZNBNvJ" /XML "C:\Users\user\AppData\Local\Temp\tmpD2C1.tmp MD5: 15FF7D8324231381BAD48A052F85DF04)
      • conhost.exe (PID: 6420 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • BXym2eR0YTBKKsB.exe (PID: 7036 cmdline: {path} MD5: C57DD0F3A3495B72307CD6BBE8ED0654)
      • schtasks.exe (PID: 3180 cmdline: schtasks.exe" /create /f /tn "DHCP Monitor" /xml "C:\Users\user\AppData\Local\Temp\tmp4F8A.tmp MD5: 15FF7D8324231381BAD48A052F85DF04)
        • conhost.exe (PID: 5052 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • schtasks.exe (PID: 7112 cmdline: schtasks.exe" /create /f /tn "DHCP Monitor Task" /xml "C:\Users\user\AppData\Local\Temp\tmp57C8.tmp MD5: 15FF7D8324231381BAD48A052F85DF04)
        • conhost.exe (PID: 7088 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • BXym2eR0YTBKKsB.exe (PID: 7080 cmdline: C:\Users\user\Desktop\BXym2eR0YTBKKsB.exe 0 MD5: C57DD0F3A3495B72307CD6BBE8ED0654)
    • schtasks.exe (PID: 2132 cmdline: C:\Windows\System32\schtasks.exe" /Create /TN "Updates\fuZNBNvJ" /XML "C:\Users\user\AppData\Local\Temp\tmp11CD.tmp MD5: 15FF7D8324231381BAD48A052F85DF04)
      • conhost.exe (PID: 2148 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • dhcpmon.exe (PID: 5388 cmdline: "C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe" 0 MD5: C57DD0F3A3495B72307CD6BBE8ED0654)
  • dhcpmon.exe (PID: 5680 cmdline: "C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe" MD5: C57DD0F3A3495B72307CD6BBE8ED0654)
    • dw20.exe (PID: 7124 cmdline: dw20.exe -x -s 1116 MD5: 8D10DA8A3E11747E51F23C882C22BBC3)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000007.00000002.562022450.0000000003F87000.00000004.00000001.sdmpJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
    00000007.00000002.562022450.0000000003F87000.00000004.00000001.sdmpNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
    • 0x8a7d:$a: NanoCore
    • 0x8ad6:$a: NanoCore
    • 0x8b13:$a: NanoCore
    • 0x8b8c:$a: NanoCore
    • 0xe121:$a: NanoCore
    • 0xe16b:$a: NanoCore
    • 0xe355:$a: NanoCore
    • 0x21c74:$a: NanoCore
    • 0x21c89:$a: NanoCore
    • 0x21cbe:$a: NanoCore
    • 0x3ac13:$a: NanoCore
    • 0x3ac28:$a: NanoCore
    • 0x3ac5d:$a: NanoCore
    • 0x8adf:$b: ClientPlugin
    • 0x8b1c:$b: ClientPlugin
    • 0x941a:$b: ClientPlugin
    • 0x9427:$b: ClientPlugin
    • 0xdeba:$b: ClientPlugin
    • 0xe12a:$b: ClientPlugin
    • 0xe174:$b: ClientPlugin
    • 0x21a30:$b: ClientPlugin
    0000000C.00000002.364841713.0000000003701000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0x112c7d:$x1: NanoCore.ClientPluginHost
    • 0x14729d:$x1: NanoCore.ClientPluginHost
    • 0x112cba:$x2: IClientNetworkHost
    • 0x1472da:$x2: IClientNetworkHost
    • 0x1167ed:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
    • 0x14ae0d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
    0000000C.00000002.364841713.0000000003701000.00000004.00000001.sdmpJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
      0000000C.00000002.364841713.0000000003701000.00000004.00000001.sdmpNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
      • 0x1129e5:$a: NanoCore
      • 0x1129f5:$a: NanoCore
      • 0x112c29:$a: NanoCore
      • 0x112c3d:$a: NanoCore
      • 0x112c7d:$a: NanoCore
      • 0x147005:$a: NanoCore
      • 0x147015:$a: NanoCore
      • 0x147249:$a: NanoCore
      • 0x14725d:$a: NanoCore
      • 0x14729d:$a: NanoCore
      • 0x112a44:$b: ClientPlugin
      • 0x112c46:$b: ClientPlugin
      • 0x112c86:$b: ClientPlugin
      • 0x147064:$b: ClientPlugin
      • 0x147266:$b: ClientPlugin
      • 0x1472a6:$b: ClientPlugin
      • 0x112b6b:$c: ProjectData
      • 0x14718b:$c: ProjectData
      • 0x1de261:$c: ProjectData
      • 0x113572:$d: DESCrypto
      • 0x147b92:$d: DESCrypto
      Click to see the 59 entries

      Unpacked PEs

      SourceRuleDescriptionAuthorStrings
      7.2.BXym2eR0YTBKKsB.exe.5a60000.8.raw.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
      • 0x1646:$x1: NanoCore.ClientPluginHost
      7.2.BXym2eR0YTBKKsB.exe.5a60000.8.raw.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
      • 0x1646:$x2: NanoCore.ClientPluginHost
      • 0x1724:$s4: PipeCreated
      • 0x1660:$s5: IClientLoggingHost
      16.2.BXym2eR0YTBKKsB.exe.3c3ec9e.5.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
      • 0x4083:$x1: NanoCore.ClientPluginHost
      16.2.BXym2eR0YTBKKsB.exe.3c3ec9e.5.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
      • 0x4083:$x2: NanoCore.ClientPluginHost
      • 0x4161:$s4: PipeCreated
      • 0x409d:$s5: IClientLoggingHost
      16.2.BXym2eR0YTBKKsB.exe.2c189d8.3.raw.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
      • 0x1646:$x1: NanoCore.ClientPluginHost
      Click to see the 120 entries

      Sigma Overview

      AV Detection:

      barindex
      Sigma detected: NanoCoreShow sources
      Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\Desktop\BXym2eR0YTBKKsB.exe, ProcessId: 7036, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

      E-Banking Fraud:

      bar