Overview
overview
7Static
static
3newdcnyash/DCRat.exe
windows11-21h2-x64
6newdcnyash...xa.dll
windows11-21h2-x64
3newdcnyash...BC.exe
windows11-21h2-x64
1newdcnyash...BT.exe
windows11-21h2-x64
1newdcnyash...LC.exe
windows11-21h2-x64
1newdcnyash...lt.exe
windows11-21h2-x64
1newdcnyash...C3.dll
windows11-21h2-x64
3newdcnyash...xt.dll
windows11-21h2-x64
3newdcnyash...64.dll
windows11-21h2-x64
3newdcnyash...on.exe
windows11-21h2-x64
1newdcnyash...ip.exe
windows11-21h2-x64
1newdcnyash...ib.dll
windows11-21h2-x64
1newdcnyash...le.exe
windows11-21h2-x64
7newdcnyash...or.exe
windows11-21h2-x64
7newdcnyash...nc.vbe
windows11-21h2-x64
1newdcnyash...ss.exe
windows11-21h2-x64
1newdcnyash...ar.exe
windows11-21h2-x64
3newdcnyash...ar.exe
windows11-21h2-x64
5newdcnyash...ce.exe
windows11-21h2-x64
7newdcnyash...lI.jar
windows11-21h2-x64
1newdcnyash...II.jar
windows11-21h2-x64
1newdcnyash...Il.jar
windows11-21h2-x64
1newdcnyash...II.jar
windows11-21h2-x64
1newdcnyash...II.jar
windows11-21h2-x64
1newdcnyash...ll.jar
windows11-21h2-x64
7newdcnyash...ll.jar
windows11-21h2-x64
1newdcnyash...ll.jar
windows11-21h2-x64
1newdcnyash...lI.jar
windows11-21h2-x64
1newdcnyash...lI.jar
windows11-21h2-x64
1newdcnyash...ll.jar
windows11-21h2-x64
1newdcnyash...II.jar
windows11-21h2-x64
1newdcnyash...er.bat
windows11-21h2-x64
7Analysis
-
max time kernel
3s -
platform
windows11-21h2_x64 -
resource
win11-20240704-en -
resource tags
arch:x64arch:x86image:win11-20240704-enlocale:en-usos:windows11-21h2-x64system -
submitted
05-07-2024 04:32
Static task
static1
Behavioral task
behavioral1
Sample
newdcnyash/DCRat.exe
Resource
win11-20240704-en
Behavioral task
behavioral2
Sample
newdcnyash/data/7zxa.dll
Resource
win11-20240704-en
Behavioral task
behavioral3
Sample
newdcnyash/data/DCRBC.exe
Resource
win11-20240704-en
Behavioral task
behavioral4
Sample
newdcnyash/data/DCRBT.exe
Resource
win11-20240704-en
Behavioral task
behavioral5
Sample
newdcnyash/data/DCRLC.exe
Resource
win11-20240704-en
Behavioral task
behavioral6
Sample
newdcnyash/data/Default.exe
Resource
win11-20240704-en
Behavioral task
behavioral7
Sample
newdcnyash/data/NCC3.dll
Resource
win11-20240704-en
Behavioral task
behavioral8
Sample
newdcnyash/data/RarExt.dll
Resource
win11-20240704-en
Behavioral task
behavioral9
Sample
newdcnyash/data/RarExt64.dll
Resource
win11-20240704-en
Behavioral task
behavioral10
Sample
newdcnyash/data/WinCon.exe
Resource
win11-20240508-en
Behavioral task
behavioral11
Sample
newdcnyash/data/Zip.exe
Resource
win11-20240704-en
Behavioral task
behavioral12
Sample
newdcnyash/data/dnlib.dll
Resource
win11-20240704-en
Behavioral task
behavioral13
Sample
newdcnyash/data/dotNET_Reactor.Console.exe
Resource
win11-20240704-en
Behavioral task
behavioral14
Sample
newdcnyash/data/dotNET_Reactor.exe
Resource
win11-20240704-en
Behavioral task
behavioral15
Sample
newdcnyash/data/enc.vbe
Resource
win11-20240704-en
Behavioral task
behavioral16
Sample
newdcnyash/data/mpress.exe
Resource
win11-20240704-en
Behavioral task
behavioral17
Sample
newdcnyash/data/rar.exe
Resource
win11-20240704-en
Behavioral task
behavioral18
Sample
newdcnyash/data/wrar.exe
Resource
win11-20240704-en
Behavioral task
behavioral19
Sample
newdcnyash/dcrat_updservice.exe
Resource
win11-20240704-en
Behavioral task
behavioral20
Sample
newdcnyash/lib/IIlIllIIlIllllIIIlIIlllIIIIIlIlllIIIIllllllIlIIlllIlIlIlllIIIlIIllIIIIlIllIlIlIlIlIlI.jar
Resource
win11-20240704-en
Behavioral task
behavioral21
Sample
newdcnyash/lib/IIllIIIIIlIlIIlIIIllIllllIIIlllIIIlIlIIlIlIllllIIlIIllIlIlIllIIIIIlIlllllllIIIIlIIlII.jar
Resource
win11-20240704-en
Behavioral task
behavioral22
Sample
newdcnyash/lib/IlIIIIllIIIIIIIIIllIlIllIIIlIIllIIlIIllIIlIlIIIIIIIIIIlllIIlIllIIIlIlIllIllIlIlIlIlIl.jar
Resource
win11-20240704-en
Behavioral task
behavioral23
Sample
newdcnyash/lib/IlIlIIIIIIlIIIIIIllIlIIlIllIllIlIIIlIllllIlIlllIIlIIllIllIIlIlllIIIllllIlIllIIIIIIIII.jar
Resource
win11-20240704-en
Behavioral task
behavioral24
Sample
newdcnyash/lib/IllIIIIIIIlllIIIlIlIllIIIIIllIllIlIIlIllIlIIlIllIIlIlIlIlllllllIIlllllllIIlIIIlIlIlII.jar
Resource
win11-20240704-en
Behavioral task
behavioral25
Sample
newdcnyash/lib/IllIIIIIIlIIIIIlIllIIIIlIlIIIIlIIllIIllIIlIlllIlIlIlIIIlllllIlllIllIIIlllllIlIlIlIlll.jar
Resource
win11-20240508-en
Behavioral task
behavioral26
Sample
newdcnyash/lib/IlllIIlllllIIllIIIlIIlIlIlIllllIlllIllllIIIIIlIllIIIIllIIlllIllIlIlIlIIIIllIllIIlllll.jar
Resource
win11-20240704-en
Behavioral task
behavioral27
Sample
newdcnyash/lib/lIIIIIIllIllllllIIlllIlIIIIlIIllllIIIIIIIIllIIIIIlIIIIIIIlllIIIIIIlIIIlIlIlIlIlIllIll.jar
Resource
win11-20240704-en
Behavioral task
behavioral28
Sample
newdcnyash/lib/lIIlIIlllIIIIIIlllIllIIIlIlIllIlllIlIllIllllIllIIIlIlIIIlIllIllIIlllIlllllIIIlIIlIIlI.jar
Resource
win11-20240704-en
Behavioral task
behavioral29
Sample
newdcnyash/lib/lIlllIIlIIlllIIllIIIlIIIIIlIlIlIIIIlIllIIlllIlllIllIlllIlIlIlllIIllIIllIIIlIllIIIlllI.jar
Resource
win11-20240704-en
Behavioral task
behavioral30
Sample
newdcnyash/lib/llIlIlIIlllIllIlllIlIIIlIIIIlllIIIllIllllIIIIIIIIlllIlIIlllIIllIIllIlIIIllIIIIlIIlIll.jar
Resource
win11-20240704-en
Behavioral task
behavioral31
Sample
newdcnyash/lib/llIlIllIllIllIlIlllIlllIIIllllllIlIIlIllIlIlIlllIllIIIIIlllIIlIIlIllllIIIlllIllIIlIII.jar
Resource
win11-20240704-en
General
-
Target
newdcnyash/data/NCC3.dll
-
Size
72KB
-
MD5
aa84f91edd922e7b3bb979e663c94f1a
-
SHA1
da46b9962a6c6cceef38c3e11b8b5bc9c1b536fa
-
SHA256
38274608d5a4b53ec22f8099f798ba46ce0ed41db65a33dfb3853f0dbf849f6f
-
SHA512
88392fc77a0300ece306908867be38011530d9eefdf003452ba86d82f2fa4a61c2b27a199f376ac307c095beaa4f52cefcab59c8b28fa187c0bca13f55f2d98b
-
SSDEEP
1536:a44UF/3qab79HtYDAD5MPEBq9iNv6qfSOBHfVW:a44G3fRMPiuuv6qqOBHfVW
Malware Config
Signatures
-
Program crash 1 IoCs
Processes:
WerFault.exepid pid_target process target process 1392 1572 WerFault.exe rundll32.exe -
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
rundll32.exedescription pid process target process PID 1540 wrote to memory of 1572 1540 rundll32.exe rundll32.exe PID 1540 wrote to memory of 1572 1540 rundll32.exe rundll32.exe PID 1540 wrote to memory of 1572 1540 rundll32.exe rundll32.exe
Processes
-
C:\Windows\system32\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\newdcnyash\data\NCC3.dll,#11⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\newdcnyash\data\NCC3.dll,#12⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 1572 -s 4523⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 204 -p 1572 -ip 15721⤵