Posts

Showing posts with the label Malware analysis

NanoCore Malware

Image
  Technical details of NanoCore Identification Sample didn’t exist in virus total as shown in figure below. The following table contains list of artifacts that had been analyzed within this document. PE timestamp SHA256 Size in bytes File name Description Thu Jun 25 03:38:24 2020 C0E3A49CBB496D4B77897BF1BBB7564391A37CEC 200.00 KB (204800 bytes) Debug.exe dropper   Summary NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework which has a lot of function to enable you steal any information to control current machine and sent it to C&C server. Important Note The initialize stage of current sample (NanoCore malware) is exactly the same code of malware njRAT. Link Njrat Code of NanoCore malware Code of Nirjart malware T...

Ransomware DearCry

Image
  Technical details of Ransomware DearCry Identification   Vendor Detection TrendMicro Ransom.Win32.DEARCRY.THCABBA McAfee Ransom-DearCry!CDDA3913408C Malwarebytes Ransom.DearCry   The following table contains list of artifacts that had been analyzed within this document. Summary DearCry is ransomware which encrypts files on a device and demands ransom in exchange for decryption. Technical details   Anti-Analysis It gets current system date and time as shown in figure below.   It starts new service called msupdate as shown in figure below. It generates key called “ d37fc1eabc6783a418d23a8d2ba5db5a " as shown in figure below. This hash will be note when ransoamware finished encryption files. It pushes two strings which related to communication with attack as shown in figure below. Email address konedieyp@airmail.cc or uenwonken@memail.c...