=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

4Y85lSOUJ0.exe

Status: finished
Submission Time: 2022-01-14 14:15:23 +01:00
Malicious
Trojan
Spyware
Evader
Nanocore MercurialGrabber

Comments

Tags

  • exe
  • NanoCore
  • RAT

Details

  • Analysis ID:
    553230
  • API (Web) ID:
    920752
  • Analysis Started:
    2022-01-14 14:15:25 +01:00
  • Analysis Finished:
    2022-01-14 14:26:25 +01:00
  • MD5:
    4f439877b84b51b8caa48ae81e1d2363
  • SHA1:
    defde1263c0ca2d604226cff86e4045a28650ab4
  • SHA256:
    b05b740309562ab6160cc3eb8ed2f0dd839d53c6c71f67bf40aeeb3f580eeb0a
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
51/69

malicious
30/35

malicious
27/28

malicious

IPs

IP Country Detection
162.159.137.232
United States
208.95.112.1
United States
23.128.64.141
United States

Domains

Name IP Detection
discord.com
162.159.137.232
ip-api.com
208.95.112.1
ip4.seeip.org
23.128.64.141

URLs

Name Detection
https://discord.com
https://discord.com/api/webhooks/927987281703350292/hNa4BC1580ABvkRj9aSBy9rORGnNfCEHIauFtOCPo1WWv1cp
Click to see the 23 hidden entries
https://discord.com/api/webhooks/927987281703350292/hNa4BC1580ABvkRj9aSBy9rORGnNfCEHIauFtOCPo1WWv1cprxylpPM2dUs4LrksljK7
https://ip4.seeip.org/
https://discordapp.com/api/v8/users/
https://i.imgur.com/vgxBhmx.pngultipart/form-data
https://www.countryflags.io/CH/flat/48.png
http://ip-api.com//json/84.17.52.18
https://ip4.seeip.org
http://discord.com
https://ip4.seeip.orgx
https://www.countryflags.io/
http://ip-api.comx
https://cdn.discordapp.com/attachments/923954670580420641/931537240771944498/passwords.txt
http://ip-api.com//json/
https://discord.com8
https://discord.comx
http://ip-api.com
https://cdn.discordapp.com/attachments/923954670580420641/931537246346162207/Capture.jpg
https://media.discordapp.net/attachments/923954670580420641/931537240771944498/passwords.txt
https://cdn.discordapp.com/avatars/
https://i.imgur.com/vgxBhmx.png
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://media.discordapp.net/attachments/923954670580420641/931537246346162207/Capture.jpg
http://ip4.seeip.org

Dropped files

Name File Type Hashes Detection
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\ProgramData\nano.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\ProgramData\output.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 6 hidden entries
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\4Y85lSOUJ0.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
ISO-8859 text, with NEL line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\output.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\Capture.jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3
#
C:\Users\user\AppData\Local\Temp\login.db
SQLite 3.x database, last written using SQLite version 3032001
#
\Device\ConDrv
ASCII text, with very long lines, with CRLF line terminators
#