1.2.PAYMENT COPY.exe.780000.16.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5fee:$x1: NanoCore.ClientPluginHost
- 0x602b:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.780000.16.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5fee:$x2: NanoCore.ClientPluginHost
- 0x9441:$s4: PipeCreated
- 0x6018:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.27b2a64.22.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1deb:$x1: NanoCore.ClientPluginHost
- 0x1e24:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.27b2a64.22.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1deb:$x2: NanoCore.ClientPluginHost
- 0x1f36:$s4: PipeCreated
- 0x1e05:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.400000.1.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x251e5:$x1: NanoCore.ClientPluginHost
- 0x25222:$x2: IClientNetworkHost
- 0x28d55:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
1.2.PAYMENT COPY.exe.400000.1.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x24f5d:$x1: NanoCore Client.exe
- 0x251e5:$x2: NanoCore.ClientPluginHost
- 0x2681e:$s1: PluginCommand
- 0x26812:$s2: FileCommand
- 0x276c3:$s3: PipeExists
- 0x2d47a:$s4: PipeCreated
- 0x2520f:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.400000.1.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.PAYMENT COPY.exe.400000.1.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x24f4d:$a: NanoCore
- 0x24f5d:$a: NanoCore
- 0x25191:$a: NanoCore
- 0x251a5:$a: NanoCore
- 0x251e5:$a: NanoCore
- 0x24fac:$b: ClientPlugin
- 0x251ae:$b: ClientPlugin
- 0x251ee:$b: ClientPlugin
- 0x250d3:$c: ProjectData
- 0x25ada:$d: DESCrypto
- 0x2d4a6:$e: KeepAlive
- 0x2b494:$g: LogClientMessage
- 0x2768f:$i: get_Connected
- 0x25e10:$j: #=q
- 0x25e40:$j: #=q
- 0x25e5c:$j: #=q
- 0x25e8c:$j: #=q
- 0x25ea8:$j: #=q
- 0x25ec4:$j: #=q
- 0x25ef4:$j: #=q
- 0x25f10:$j: #=q
|
1.2.PAYMENT COPY.exe.700000.10.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x39eb:$x1: NanoCore.ClientPluginHost
- 0x3a24:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.700000.10.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x39eb:$x2: NanoCore.ClientPluginHost
- 0x3b36:$s4: PipeCreated
- 0x3a05:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.47b0000.9.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.2.dhcpmon.exe.47b0000.9.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.47b0000.9.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.2.dhcpmon.exe.47b0000.9.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
1.2.PAYMENT COPY.exe.3430821.25.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.3430821.25.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0xc25f:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.3430821.25.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.2.dhcpmon.exe.565f58.2.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.2.dhcpmon.exe.565f58.2.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.565f58.2.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.2.dhcpmon.exe.565f58.2.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
1.2.PAYMENT COPY.exe.750000.14.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1f1db:$x1: NanoCore.ClientPluginHost
- 0x1f1f5:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.750000.14.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1f1db:$x2: NanoCore.ClientPluginHost
- 0x22518:$s4: PipeCreated
- 0x1f1c8:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.4e30000.10.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.2.dhcpmon.exe.4e30000.10.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.4e30000.10.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.2.dhcpmon.exe.4e30000.10.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
1.2.PAYMENT COPY.exe.37b0e8f.29.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x39eb:$x1: NanoCore.ClientPluginHost
- 0x3a24:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.37b0e8f.29.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x39eb:$x2: NanoCore.ClientPluginHost
- 0x3b36:$s4: PipeCreated
- 0x3a05:$s5: IClientLoggingHost
|
8.2.PAYMENT COPY.exe.243cc68.3.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
8.2.PAYMENT COPY.exe.243cc68.3.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
8.2.PAYMENT COPY.exe.400000.0.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x251e5:$x1: NanoCore.ClientPluginHost
- 0x25222:$x2: IClientNetworkHost
- 0x28d55:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
8.2.PAYMENT COPY.exe.400000.0.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x24f5d:$x1: NanoCore Client.exe
- 0x251e5:$x2: NanoCore.ClientPluginHost
- 0x2681e:$s1: PluginCommand
- 0x26812:$s2: FileCommand
- 0x276c3:$s3: PipeExists
- 0x2d47a:$s4: PipeCreated
- 0x2520f:$s5: IClientLoggingHost
|
8.2.PAYMENT COPY.exe.400000.0.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
8.2.PAYMENT COPY.exe.400000.0.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x24f4d:$a: NanoCore
- 0x24f5d:$a: NanoCore
- 0x25191:$a: NanoCore
- 0x251a5:$a: NanoCore
- 0x251e5:$a: NanoCore
- 0x24fac:$b: ClientPlugin
- 0x251ae:$b: ClientPlugin
- 0x251ee:$b: ClientPlugin
- 0x250d3:$c: ProjectData
- 0x25ada:$d: DESCrypto
- 0x2d4a6:$e: KeepAlive
- 0x2b494:$g: LogClientMessage
- 0x2768f:$i: get_Connected
- 0x25e10:$j: #=q
- 0x25e40:$j: #=q
- 0x25e5c:$j: #=q
- 0x25e8c:$j: #=q
- 0x25ea8:$j: #=q
- 0x25ec4:$j: #=q
- 0x25ef4:$j: #=q
- 0x25f10:$j: #=q
|
15.2.dhcpmon.exe.565f58.2.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.2.dhcpmon.exe.565f58.2.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.565f58.2.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.2.dhcpmon.exe.565f58.2.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
1.2.PAYMENT COPY.exe.342c1f8.24.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.342c1f8.24.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.342c1f8.24.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.2.PAYMENT COPY.exe.2a80000.6.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1d9e5:$x1: NanoCore.ClientPluginHost
- 0x1da22:$x2: IClientNetworkHost
- 0x21555:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.2.PAYMENT COPY.exe.2a80000.6.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1d75d:$x1: NanoCore Client.exe
- 0x1d9e5:$x2: NanoCore.ClientPluginHost
- 0x1f01e:$s1: PluginCommand
- 0x1f012:$s2: FileCommand
- 0x1fec3:$s3: PipeExists
- 0x25c7a:$s4: PipeCreated
- 0x1da0f:$s5: IClientLoggingHost
|
0.2.PAYMENT COPY.exe.2a80000.6.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.2.PAYMENT COPY.exe.2a80000.6.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x1d74d:$a: NanoCore
- 0x1d75d:$a: NanoCore
- 0x1d991:$a: NanoCore
- 0x1d9a5:$a: NanoCore
- 0x1d9e5:$a: NanoCore
- 0x1d7ac:$b: ClientPlugin
- 0x1d9ae:$b: ClientPlugin
- 0x1d9ee:$b: ClientPlugin
- 0x1d8d3:$c: ProjectData
- 0x1e2da:$d: DESCrypto
- 0x25ca6:$e: KeepAlive
- 0x23c94:$g: LogClientMessage
- 0x1fe8f:$i: get_Connected
- 0x1e610:$j: #=q
- 0x1e640:$j: #=q
- 0x1e65c:$j: #=q
- 0x1e68c:$j: #=q
- 0x1e6a8:$j: #=q
- 0x1e6c4:$j: #=q
- 0x1e6f4:$j: #=q
- 0x1e710:$j: #=q
|
1.2.PAYMENT COPY.exe.5b2488.2.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
1.2.PAYMENT COPY.exe.5b2488.2.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.5b2488.2.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.PAYMENT COPY.exe.5b2488.2.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x469c8:$b: ClientPlugin
- 0x60a7e:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
|
1.2.PAYMENT COPY.exe.5b2488.2.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
1.2.PAYMENT COPY.exe.5b2488.2.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.5b2488.2.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.PAYMENT COPY.exe.5b2488.2.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
8.1.PAYMENT COPY.exe.415058.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
8.1.PAYMENT COPY.exe.415058.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
8.1.PAYMENT COPY.exe.415058.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
8.1.PAYMENT COPY.exe.415058.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
14.2.dhcpmon.exe.2a50000.6.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1d9e5:$x1: NanoCore.ClientPluginHost
- 0x1da22:$x2: IClientNetworkHost
- 0x21555:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
14.2.dhcpmon.exe.2a50000.6.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1d75d:$x1: NanoCore Client.exe
- 0x1d9e5:$x2: NanoCore.ClientPluginHost
- 0x1f01e:$s1: PluginCommand
- 0x1f012:$s2: FileCommand
- 0x1fec3:$s3: PipeExists
- 0x25c7a:$s4: PipeCreated
- 0x1da0f:$s5: IClientLoggingHost
|
14.2.dhcpmon.exe.2a50000.6.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
14.2.dhcpmon.exe.2a50000.6.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x1d74d:$a: NanoCore
- 0x1d75d:$a: NanoCore
- 0x1d991:$a: NanoCore
- 0x1d9a5:$a: NanoCore
- 0x1d9e5:$a: NanoCore
- 0x1d7ac:$b: ClientPlugin
- 0x1d9ae:$b: ClientPlugin
- 0x1d9ee:$b: ClientPlugin
- 0x1d8d3:$c: ProjectData
- 0x1e2da:$d: DESCrypto
- 0x25ca6:$e: KeepAlive
- 0x23c94:$g: LogClientMessage
- 0x1fe8f:$i: get_Connected
- 0x1e610:$j: #=q
- 0x1e640:$j: #=q
- 0x1e65c:$j: #=q
- 0x1e68c:$j: #=q
- 0x1e6a8:$j: #=q
- 0x1e6c4:$j: #=q
- 0x1e6f4:$j: #=q
- 0x1e710:$j: #=q
|
8.1.PAYMENT COPY.exe.400000.1.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x215e5:$x1: NanoCore.ClientPluginHost
- 0x21622:$x2: IClientNetworkHost
- 0x25155:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
8.1.PAYMENT COPY.exe.400000.1.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2135d:$x1: NanoCore Client.exe
- 0x215e5:$x2: NanoCore.ClientPluginHost
- 0x22c1e:$s1: PluginCommand
- 0x22c12:$s2: FileCommand
- 0x23ac3:$s3: PipeExists
- 0x2987a:$s4: PipeCreated
- 0x2160f:$s5: IClientLoggingHost
|
8.1.PAYMENT COPY.exe.400000.1.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
8.1.PAYMENT COPY.exe.400000.1.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x2134d:$a: NanoCore
- 0x2135d:$a: NanoCore
- 0x21591:$a: NanoCore
- 0x215a5:$a: NanoCore
- 0x215e5:$a: NanoCore
- 0x213ac:$b: ClientPlugin
- 0x215ae:$b: ClientPlugin
- 0x215ee:$b: ClientPlugin
- 0x214d3:$c: ProjectData
- 0x21eda:$d: DESCrypto
- 0x298a6:$e: KeepAlive
- 0x27894:$g: LogClientMessage
- 0x23a8f:$i: get_Connected
- 0x22210:$j: #=q
- 0x22240:$j: #=q
- 0x2225c:$j: #=q
- 0x2228c:$j: #=q
- 0x222a8:$j: #=q
- 0x222c4:$j: #=q
- 0x222f4:$j: #=q
- 0x22310:$j: #=q
|
15.1.dhcpmon.exe.400000.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x215e5:$x1: NanoCore.ClientPluginHost
- 0x21622:$x2: IClientNetworkHost
- 0x25155:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.1.dhcpmon.exe.400000.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2135d:$x1: NanoCore Client.exe
- 0x215e5:$x2: NanoCore.ClientPluginHost
- 0x22c1e:$s1: PluginCommand
- 0x22c12:$s2: FileCommand
- 0x23ac3:$s3: PipeExists
- 0x2987a:$s4: PipeCreated
- 0x2160f:$s5: IClientLoggingHost
|
15.1.dhcpmon.exe.400000.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.1.dhcpmon.exe.400000.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x2134d:$a: NanoCore
- 0x2135d:$a: NanoCore
- 0x21591:$a: NanoCore
- 0x215a5:$a: NanoCore
- 0x215e5:$a: NanoCore
- 0x213ac:$b: ClientPlugin
- 0x215ae:$b: ClientPlugin
- 0x215ee:$b: ClientPlugin
- 0x214d3:$c: ProjectData
- 0x21eda:$d: DESCrypto
- 0x298a6:$e: KeepAlive
- 0x27894:$g: LogClientMessage
- 0x23a8f:$i: get_Connected
- 0x22210:$j: #=q
- 0x22240:$j: #=q
- 0x2225c:$j: #=q
- 0x2228c:$j: #=q
- 0x222a8:$j: #=q
- 0x222c4:$j: #=q
- 0x222f4:$j: #=q
- 0x22310:$j: #=q
|
1.2.PAYMENT COPY.exe.342c1f8.24.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.342c1f8.24.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.342c1f8.24.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.PAYMENT COPY.exe.6f0000.9.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x59eb:$x1: NanoCore.ClientPluginHost
- 0x5b48:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.6f0000.9.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x59eb:$x2: NanoCore.ClientPluginHost
- 0x6941:$s3: PipeExists
- 0x5be1:$s4: PipeCreated
- 0x5a05:$s5: IClientLoggingHost
|
14.2.dhcpmon.exe.2a61458.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
14.2.dhcpmon.exe.2a61458.5.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
14.2.dhcpmon.exe.2a61458.5.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
14.2.dhcpmon.exe.2a61458.5.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
0.2.PAYMENT COPY.exe.2a91458.5.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.2.PAYMENT COPY.exe.2a91458.5.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
0.2.PAYMENT COPY.exe.2a91458.5.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.2.PAYMENT COPY.exe.2a91458.5.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
1.2.PAYMENT COPY.exe.24228c4.18.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d1f:$x1: NanoCore.ClientPluginHost
- 0x1fb7f:$x1: NanoCore.ClientPluginHost
- 0x27ab5:$x1: NanoCore.ClientPluginHost
- 0x2da98:$x1: NanoCore.ClientPluginHost
- 0x37513:$x1: NanoCore.ClientPluginHost
- 0x4194f:$x1: NanoCore.ClientPluginHost
- 0x4c941:$x1: NanoCore.ClientPluginHost
- 0x586f7:$x1: NanoCore.ClientPluginHost
- 0x6444e:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d58:$x2: IClientNetworkHost
- 0x1fbb8:$x2: IClientNetworkHost
- 0x27aee:$x2: IClientNetworkHost
- 0x37670:$x2: IClientNetworkHost
- 0x41988:$x2: IClientNetworkHost
- 0x4c95b:$x2: IClientNetworkHost
- 0x58711:$x2: IClientNetworkHost
- 0x6448b:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.24228c4.18.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a67:$a: NanoCore
- 0x15ac0:$a: NanoCore
- 0x15af3:$a: NanoCore
- 0x15d1f:$a: NanoCore
- 0x15d9b:$a: NanoCore
- 0x163b4:$a: NanoCore
- 0x164fd:$a: NanoCore
- 0x169d1:$a: NanoCore
- 0x16cb8:$a: NanoCore
- 0x16ccf:$a: NanoCore
- 0x1fb7f:$a: NanoCore
- 0x1fbfb:$a: NanoCore
- 0x224de:$a: NanoCore
- 0x27ab5:$a: NanoCore
- 0x27b2f:$a: NanoCore
- 0x2da98:$a: NanoCore
- 0x2dae2:$a: NanoCore
- 0x2e73c:$a: NanoCore
|
1.2.PAYMENT COPY.exe.680000.4.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.680000.4.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.2436f00.20.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0xb543:$x1: NanoCore.ClientPluginHost
- 0x13479:$x1: NanoCore.ClientPluginHost
- 0x1945c:$x1: NanoCore.ClientPluginHost
- 0x22ed7:$x1: NanoCore.ClientPluginHost
- 0x2d313:$x1: NanoCore.ClientPluginHost
- 0x38305:$x1: NanoCore.ClientPluginHost
- 0x440bb:$x1: NanoCore.ClientPluginHost
- 0x4fe12:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
- 0xb57c:$x2: IClientNetworkHost
- 0x134b2:$x2: IClientNetworkHost
- 0x23034:$x2: IClientNetworkHost
- 0x2d34c:$x2: IClientNetworkHost
- 0x3831f:$x2: IClientNetworkHost
- 0x440d5:$x2: IClientNetworkHost
- 0x4fe4f:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.2436f00.20.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x142b:$a: NanoCore
- 0x1484:$a: NanoCore
- 0x14b7:$a: NanoCore
- 0x16e3:$a: NanoCore
- 0x175f:$a: NanoCore
- 0x1d78:$a: NanoCore
- 0x1ec1:$a: NanoCore
- 0x2395:$a: NanoCore
- 0x267c:$a: NanoCore
- 0x2693:$a: NanoCore
- 0xb543:$a: NanoCore
- 0xb5bf:$a: NanoCore
- 0xdea2:$a: NanoCore
- 0x13479:$a: NanoCore
- 0x134f3:$a: NanoCore
- 0x1945c:$a: NanoCore
- 0x194a6:$a: NanoCore
- 0x1a100:$a: NanoCore
- 0x22ed7:$a: NanoCore
- 0x22fc1:$a: NanoCore
- 0x23e38:$a: NanoCore
|
1.2.PAYMENT COPY.exe.365ec98.27.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1d3db:$x1: NanoCore.ClientPluginHost
- 0x1d3f5:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.365ec98.27.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1d3db:$x2: NanoCore.ClientPluginHost
- 0x20718:$s4: PipeCreated
- 0x1d3c8:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.27a65e4.21.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x59eb:$x1: NanoCore.ClientPluginHost
- 0xfe6b:$x1: NanoCore.ClientPluginHost
- 0x1aea1:$x1: NanoCore.ClientPluginHost
- 0x26c9b:$x1: NanoCore.ClientPluginHost
- 0x32a86:$x1: NanoCore.ClientPluginHost
- 0x5b48:$x2: IClientNetworkHost
- 0xfea4:$x2: IClientNetworkHost
- 0x1aebb:$x2: IClientNetworkHost
- 0x26cb5:$x2: IClientNetworkHost
- 0x32ac3:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.27a65e4.21.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x59eb:$x2: NanoCore.ClientPluginHost
- 0xfe6b:$x2: NanoCore.ClientPluginHost
- 0x1aea1:$x2: NanoCore.ClientPluginHost
- 0x26c9b:$x2: NanoCore.ClientPluginHost
- 0x32a86:$x2: NanoCore.ClientPluginHost
- 0x6941:$s3: PipeExists
- 0x5be1:$s4: PipeCreated
- 0xffb6:$s4: PipeCreated
- 0x1bed6:$s4: PipeCreated
- 0x28a46:$s4: PipeCreated
- 0x35ed9:$s4: PipeCreated
- 0x5a05:$s5: IClientLoggingHost
- 0xfe85:$s5: IClientLoggingHost
- 0x1ae8e:$s5: IClientLoggingHost
- 0x26c88:$s5: IClientLoggingHost
- 0x32ab0:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.27a65e4.21.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x59eb:$a: NanoCore
- 0x5ad5:$a: NanoCore
- 0x694c:$a: NanoCore
- 0xfb4b:$a: NanoCore
- 0xfbac:$a: NanoCore
- 0xfbef:$a: NanoCore
- 0xfc2f:$a: NanoCore
- 0xfe6b:$a: NanoCore
- 0xff0b:$a: NanoCore
- 0x106e3:$a: NanoCore
- 0x10cd6:$a: NanoCore
- 0x10e27:$a: NanoCore
- 0x11c81:$a: NanoCore
- 0x11ee8:$a: NanoCore
- 0x11efd:$a: NanoCore
- 0x11f1c:$a: NanoCore
- 0x1ae78:$a: NanoCore
- 0x1aea1:$a: NanoCore
- 0x26c72:$a: NanoCore
- 0x26c9b:$a: NanoCore
- 0x32a49:$a: NanoCore
|
1.2.PAYMENT COPY.exe.710000.11.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3d99:$x1: NanoCore.ClientPluginHost
- 0x3db3:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.710000.11.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3d99:$x2: NanoCore.ClientPluginHost
- 0x4dce:$s4: PipeCreated
- 0x3d86:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.415058.0.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
1.2.PAYMENT COPY.exe.415058.0.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.415058.0.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.PAYMENT COPY.exe.415058.0.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
1.2.PAYMENT COPY.exe.366d53c.26.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x10937:$x1: NanoCore.ClientPluginHost
- 0x10951:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.366d53c.26.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x10937:$x2: NanoCore.ClientPluginHost
- 0x13c74:$s4: PipeCreated
- 0x10924:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.400000.1.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x251e5:$x1: NanoCore.ClientPluginHost
- 0x25222:$x2: IClientNetworkHost
- 0x28d55:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.2.dhcpmon.exe.400000.1.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x24f5d:$x1: NanoCore Client.exe
- 0x251e5:$x2: NanoCore.ClientPluginHost
- 0x2681e:$s1: PluginCommand
- 0x26812:$s2: FileCommand
- 0x276c3:$s3: PipeExists
- 0x2d47a:$s4: PipeCreated
- 0x2520f:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.400000.1.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.2.dhcpmon.exe.400000.1.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x24f4d:$a: NanoCore
- 0x24f5d:$a: NanoCore
- 0x25191:$a: NanoCore
- 0x251a5:$a: NanoCore
- 0x251e5:$a: NanoCore
- 0x24fac:$b: ClientPlugin
- 0x251ae:$b: ClientPlugin
- 0x251ee:$b: ClientPlugin
- 0x250d3:$c: ProjectData
- 0x25ada:$d: DESCrypto
- 0x2d4a6:$e: KeepAlive
- 0x2b494:$g: LogClientMessage
- 0x2768f:$i: get_Connected
- 0x25e10:$j: #=q
- 0x25e40:$j: #=q
- 0x25e5c:$j: #=q
- 0x25e8c:$j: #=q
- 0x25ea8:$j: #=q
- 0x25ec4:$j: #=q
- 0x25ef4:$j: #=q
- 0x25f10:$j: #=q
|
8.2.PAYMENT COPY.exe.247b9ec.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
8.2.PAYMENT COPY.exe.247b9ec.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
15.1.dhcpmon.exe.415058.1.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.1.dhcpmon.exe.415058.1.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
15.1.dhcpmon.exe.415058.1.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.1.dhcpmon.exe.415058.1.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
1.2.PAYMENT COPY.exe.23bc994.17.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.23bc994.17.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
8.1.PAYMENT COPY.exe.400000.1.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x251e5:$x1: NanoCore.ClientPluginHost
- 0x25222:$x2: IClientNetworkHost
- 0x28d55:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
8.1.PAYMENT COPY.exe.400000.1.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x24f5d:$x1: NanoCore Client.exe
- 0x251e5:$x2: NanoCore.ClientPluginHost
- 0x2681e:$s1: PluginCommand
- 0x26812:$s2: FileCommand
- 0x276c3:$s3: PipeExists
- 0x2d47a:$s4: PipeCreated
- 0x2520f:$s5: IClientLoggingHost
|
8.1.PAYMENT COPY.exe.400000.1.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
8.1.PAYMENT COPY.exe.400000.1.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x24f4d:$a: NanoCore
- 0x24f5d:$a: NanoCore
- 0x25191:$a: NanoCore
- 0x251a5:$a: NanoCore
- 0x251e5:$a: NanoCore
- 0x24fac:$b: ClientPlugin
- 0x251ae:$b: ClientPlugin
- 0x251ee:$b: ClientPlugin
- 0x250d3:$c: ProjectData
- 0x25ada:$d: DESCrypto
- 0x2d4a6:$e: KeepAlive
- 0x2b494:$g: LogClientMessage
- 0x2768f:$i: get_Connected
- 0x25e10:$j: #=q
- 0x25e40:$j: #=q
- 0x25e5c:$j: #=q
- 0x25e8c:$j: #=q
- 0x25ea8:$j: #=q
- 0x25ec4:$j: #=q
- 0x25ef4:$j: #=q
- 0x25f10:$j: #=q
|
1.2.PAYMENT COPY.exe.27b2a64.22.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x39eb:$x1: NanoCore.ClientPluginHost
- 0xea21:$x1: NanoCore.ClientPluginHost
- 0x1a81b:$x1: NanoCore.ClientPluginHost
- 0x26606:$x1: NanoCore.ClientPluginHost
- 0x3a24:$x2: IClientNetworkHost
- 0xea3b:$x2: IClientNetworkHost
- 0x1a835:$x2: IClientNetworkHost
- 0x26643:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.27b2a64.22.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x39eb:$x2: NanoCore.ClientPluginHost
- 0xea21:$x2: NanoCore.ClientPluginHost
- 0x1a81b:$x2: NanoCore.ClientPluginHost
- 0x26606:$x2: NanoCore.ClientPluginHost
- 0x3b36:$s4: PipeCreated
- 0xfa56:$s4: PipeCreated
- 0x1c5c6:$s4: PipeCreated
- 0x29a59:$s4: PipeCreated
- 0x3a05:$s5: IClientLoggingHost
- 0xea0e:$s5: IClientLoggingHost
- 0x1a808:$s5: IClientLoggingHost
- 0x26630:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.27b2a64.22.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x36cb:$a: NanoCore
- 0x372c:$a: NanoCore
- 0x376f:$a: NanoCore
- 0x37af:$a: NanoCore
- 0x39eb:$a: NanoCore
- 0x3a8b:$a: NanoCore
- 0x4263:$a: NanoCore
- 0x4856:$a: NanoCore
- 0x49a7:$a: NanoCore
- 0x5801:$a: NanoCore
- 0x5a68:$a: NanoCore
- 0x5a7d:$a: NanoCore
- 0x5a9c:$a: NanoCore
- 0xe9f8:$a: NanoCore
- 0xea21:$a: NanoCore
- 0x1a7f2:$a: NanoCore
- 0x1a81b:$a: NanoCore
- 0x265c9:$a: NanoCore
- 0x265e1:$a: NanoCore
- 0x26606:$a: NanoCore
- 0x3741:$b: ClientPlugin
|
1.2.PAYMENT COPY.exe.75e8a4.15.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x10937:$x1: NanoCore.ClientPluginHost
- 0x10951:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.75e8a4.15.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x10937:$x2: NanoCore.ClientPluginHost
- 0x13c74:$s4: PipeCreated
- 0x10924:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.3295530.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.2.dhcpmon.exe.3295530.5.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.3295530.5.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.2.dhcpmon.exe.3295530.5.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
1.2.PAYMENT COPY.exe.730000.12.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x350b:$x1: NanoCore.ClientPluginHost
- 0x3525:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.730000.12.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x350b:$x2: NanoCore.ClientPluginHost
- 0x52b6:$s4: PipeCreated
- 0x34f8:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.37b0e8f.29.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1deb:$x1: NanoCore.ClientPluginHost
- 0x1e24:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.37b0e8f.29.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1deb:$x2: NanoCore.ClientPluginHost
- 0x1f36:$s4: PipeCreated
- 0x1e05:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.750000.14.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1d3db:$x1: NanoCore.ClientPluginHost
- 0x1d3f5:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.750000.14.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1d3db:$x2: NanoCore.ClientPluginHost
- 0x20718:$s4: PipeCreated
- 0x1d3c8:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.6c0000.7.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2205:$x1: NanoCore.ClientPluginHost
- 0x223e:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.6c0000.7.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2205:$x2: NanoCore.ClientPluginHost
- 0x2320:$s4: PipeCreated
- 0x221f:$s5: IClientLoggingHost
|
1.3.PAYMENT COPY.exe.387e041.1.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0x7c31:$x1: NanoCore.ClientPluginHost
- 0xdc02:$x1: NanoCore.ClientPluginHost
- 0x1766e:$x1: NanoCore.ClientPluginHost
- 0x21a99:$x1: NanoCore.ClientPluginHost
- 0x2ca76:$x1: NanoCore.ClientPluginHost
- 0x38818:$x1: NanoCore.ClientPluginHost
- 0x5d71c:$x1: NanoCore.ClientPluginHost
- 0x6cb5c:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
- 0x7c6a:$x2: IClientNetworkHost
- 0x177cb:$x2: IClientNetworkHost
- 0x21ad2:$x2: IClientNetworkHost
- 0x2ca90:$x2: IClientNetworkHost
- 0x38832:$x2: IClientNetworkHost
- 0x5d736:$x2: IClientNetworkHost
- 0x6cb99:$x2: IClientNetworkHost
|
1.3.PAYMENT COPY.exe.387e041.1.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x16e3:$x2: NanoCore.ClientPluginHost
- 0x7c31:$x2: NanoCore.ClientPluginHost
- 0xdc02:$x2: NanoCore.ClientPluginHost
- 0x1766e:$x2: NanoCore.ClientPluginHost
- 0x21a99:$x2: NanoCore.ClientPluginHost
- 0x2ca76:$x2: NanoCore.ClientPluginHost
- 0x38818:$x2: NanoCore.ClientPluginHost
- 0x5d71c:$x2: NanoCore.ClientPluginHost
- 0x6cb5c:$x2: NanoCore.ClientPluginHost
- 0x185c4:$s3: PipeExists
- 0x1800:$s4: PipeCreated
- 0x7d4c:$s4: PipeCreated
- 0xdce0:$s4: PipeCreated
- 0x17864:$s4: PipeCreated
- 0x21be4:$s4: PipeCreated
- 0x2daab:$s4: PipeCreated
- 0x3a5c3:$s4: PipeCreated
- 0x60a59:$s4: PipeCreated
- 0x6ffaf:$s4: PipeCreated
- 0x16fd:$s5: IClientLoggingHost
- 0x7c4b:$s5: IClientLoggingHost
|
1.3.PAYMENT COPY.exe.387e041.1.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x142b:$a: NanoCore
- 0x1484:$a: NanoCore
- 0x14b7:$a: NanoCore
- 0x16e3:$a: NanoCore
- 0x175f:$a: NanoCore
- 0x1d78:$a: NanoCore
- 0x1ec1:$a: NanoCore
- 0x2395:$a: NanoCore
- 0x267c:$a: NanoCore
- 0x2693:$a: NanoCore
- 0x7c31:$a: NanoCore
- 0x7cab:$a: NanoCore
- 0xc848:$a: NanoCore
- 0xdc02:$a: NanoCore
- 0xdc4c:$a: NanoCore
- 0xe8a6:$a: NanoCore
- 0x1766e:$a: NanoCore
- 0x17758:$a: NanoCore
- 0x185cf:$a: NanoCore
- 0x21779:$a: NanoCore
- 0x217da:$a: NanoCore
|
1.2.PAYMENT COPY.exe.415058.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
1.2.PAYMENT COPY.exe.415058.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
1.2.PAYMENT COPY.exe.415058.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.PAYMENT COPY.exe.415058.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
1.2.PAYMENT COPY.exe.24228c4.18.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.24228c4.18.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
8.2.PAYMENT COPY.exe.3497815.7.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0x24190:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
- 0x241bd:$x2: IClientNetworkHost
|
8.2.PAYMENT COPY.exe.3497815.7.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0x24190:$x2: NanoCore.ClientPluginHost
- 0xc25f:$s4: PipeCreated
- 0x2526b:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
- 0x241aa:$s5: IClientLoggingHost
|
8.2.PAYMENT COPY.exe.3497815.7.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.PAYMENT COPY.exe.660000.3.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
1.2.PAYMENT COPY.exe.660000.3.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
7.2.PAYMENT COPY.exe.2a60000.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x215e5:$x1: NanoCore.ClientPluginHost
- 0x21622:$x2: IClientNetworkHost
- 0x25155:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
7.2.PAYMENT COPY.exe.2a60000.5.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2135d:$x1: NanoCore Client.exe
- 0x215e5:$x2: NanoCore.ClientPluginHost
- 0x22c1e:$s1: PluginCommand
- 0x22c12:$s2: FileCommand
- 0x23ac3:$s3: PipeExists
- 0x2987a:$s4: PipeCreated
- 0x2160f:$s5: IClientLoggingHost
|
7.2.PAYMENT COPY.exe.2a60000.5.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
7.2.PAYMENT COPY.exe.2a60000.5.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x2134d:$a: NanoCore
- 0x2135d:$a: NanoCore
- 0x21591:$a: NanoCore
- 0x215a5:$a: NanoCore
- 0x215e5:$a: NanoCore
- 0x213ac:$b: ClientPlugin
- 0x215ae:$b: ClientPlugin
- 0x215ee:$b: ClientPlugin
- 0x214d3:$c: ProjectData
- 0x21eda:$d: DESCrypto
- 0x298a6:$e: KeepAlive
- 0x27894:$g: LogClientMessage
- 0x23a8f:$i: get_Connected
- 0x22210:$j: #=q
- 0x22240:$j: #=q
- 0x2225c:$j: #=q
- 0x2228c:$j: #=q
- 0x222a8:$j: #=q
- 0x222c4:$j: #=q
- 0x222f4:$j: #=q
- 0x22310:$j: #=q
|
8.2.PAYMENT COPY.exe.34931ec.8.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0x287b9:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
- 0x287e6:$x2: IClientNetworkHost
|
8.2.PAYMENT COPY.exe.34931ec.8.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x287b9:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0x29894:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
- 0x287d3:$s5: IClientLoggingHost
|
8.2.PAYMENT COPY.exe.34931ec.8.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.PAYMENT COPY.exe.6e0000.8.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x13a8:$x1: NanoCore.ClientPluginHost
|
1.2.PAYMENT COPY.exe.6e0000.8.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x13a8:$x2: NanoCore.ClientPluginHost
- 0x1486:$s4: PipeCreated
- 0x13c2:$s5: IClientLoggingHost
|
1.3.PAYMENT COPY.exe.3883a6d.2.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x605:$x1: NanoCore.ClientPluginHost
- 0x3bd6:$x1: NanoCore.ClientPluginHost
- 0x63e:$x2: IClientNetworkHost
|
1.3.PAYMENT COPY.exe.3883a6d.2.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x605:$x2: NanoCore.ClientPluginHost
- 0x3bd6:$x2: NanoCore.ClientPluginHost
- 0x720:$s4: PipeCreated
- 0x3cb4:$s4: PipeCreated
- 0x61f:$s5: IClientLoggingHost
- 0x3bf0:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.415058.0.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
15.2.dhcpmon.exe.415058.0.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
15.2.dhcpmon.exe.415058.0.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
15.2.dhcpmon.exe.415058.0.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
8.2.PAYMENT COPY.exe.34931ec.8.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
8.2.PAYMENT COPY.exe.34931ec.8.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
8.2.PAYMENT COPY.exe.34931ec.8.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
8.2.PAYMENT COPY.exe.348e3b6.6.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x145e3:$x1: NanoCore.ClientPluginHost
- 0x2d5ef:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x14610:$x2: IClientNetworkHost
- 0x2d61c:$x2: IClientNetworkHost
|
8.2.PAYMENT COPY.exe.348e3b6.6.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x145e3:$x2: NanoCore.ClientPluginHost
- 0x2d5ef:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0x156be:$s4: PipeCreated
- 0x2e6ca:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
- 0x145fd:$s5: IClientLoggingHost
- 0x2d609:$s5: IClientLoggingHost
|
8.2.PAYMENT COPY.exe.348e3b6.6.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
8.2.PAYMENT COPY.exe.348e3b6.6.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x14599:$a: NanoCore
- 0x145ae:$a: NanoCore
- 0x145e3:$a: NanoCore
- 0x2d5a5:$a: NanoCore
- 0x2d5ba:$a: NanoCore
- 0x2d5ef:$a: NanoCore
- 0xe41:$b: ClientPlugin
|