2018-01-12 - NANOCORE RAT

NOTICE:

ASSOCIATED FILES:

  • 2018-01-12-NanoCore-RAT-infection-traffic.pcap   (415,958 bytes)
  • 2018-01-11-NanoCore-RAT-malspam-0034-UTC.eml   (635,772 bytes)
  • TNT SHIPMENT INFORMATION.exe   (1,968,344 bytes)
  • TNT SHIPMENT INFORMATION.r14   (466,579 bytes)
  • filename.exe   (1,968,344 bytes)
  • filename.vbs   (1,016 bytes)

 

EMAIL


Shown above:  Screenshot of the email.

 

EMAIL INFORMATION:

 


Shown above:  Extracting the malware from the attached RAR archive.

 

TRAFFIC


Shown above:  Infection traffic filtered in Wireshark.

 

INFECTION TRAFFIC:

 

MALWARE

RAR ARCHIVE FROM LINK IN THE EMAIL:

EXE FILE (NANOCORE RAT) EXTRACTED FROM THE RAR ARCHIVE:

NANOCORE RAT ARTIFACTS FROM THE INFECTED WINDOWS HOST:

WINDOWS REGISTRY ENTRY FOR PERSISTENCE:

 

IMAGES


Shown above:  Alerts from Sguil in Security Onion using Suricata and the EmergingThreats Pro (ETPRO) ruleset.

 


Shown above:  Registry key and associated files on the infected Windows host.

 

Click here to return to the main page.