12.2.hbvo9thTAX.exe.3dc7ce1.17.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3dc7ce1.17.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
13.2.dhcpmon.exe.3e03290.1.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
13.2.dhcpmon.exe.3e03290.1.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
13.2.dhcpmon.exe.3e03290.1.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
13.2.dhcpmon.exe.3e03290.1.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
12.2.hbvo9thTAX.exe.6d20000.34.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x41ee:$x1: NanoCore.ClientPluginHost
- 0x422b:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.6d20000.34.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x41ee:$x2: NanoCore.ClientPluginHost
- 0x7641:$s4: PipeCreated
- 0x4218:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.3cb28fe.14.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x170b:$x1: NanoCore.ClientPluginHost
- 0x1725:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3cb28fe.14.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x170b:$x2: NanoCore.ClientPluginHost
- 0x34b6:$s4: PipeCreated
- 0x16f8:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.2c335d0.7.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.2c335d0.7.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.5930000.28.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3d99:$x1: NanoCore.ClientPluginHost
- 0x3db3:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.5930000.28.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3d99:$x2: NanoCore.ClientPluginHost
- 0x4dce:$s4: PipeCreated
- 0x3d86:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3f63db8.7.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
12.3.hbvo9thTAX.exe.3f63db8.7.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3f63db8.7.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.2.hbvo9thTAX.exe.58c0000.26.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3deb:$x1: NanoCore.ClientPluginHost
- 0x3f48:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.58c0000.26.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3deb:$x2: NanoCore.ClientPluginHost
- 0x4d41:$s3: PipeExists
- 0x3fe1:$s4: PipeCreated
- 0x3e05:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.3dd3f15.15.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3dd3f15.15.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.4fc0000.20.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.4fc0000.20.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.5470000.22.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.5470000.22.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.5470000.22.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.2.hbvo9thTAX.exe.e50000.4.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x605:$x1: NanoCore.ClientPluginHost
- 0x63e:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.e50000.4.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x605:$x2: NanoCore.ClientPluginHost
- 0x720:$s4: PipeCreated
- 0x61f:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3ee9652.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x145e3:$x1: NanoCore.ClientPluginHost
- 0x2221d:$x1: NanoCore.ClientPluginHost
- 0x32439:$x1: NanoCore.ClientPluginHost
- 0x3f5a2:$x1: NanoCore.ClientPluginHost
- 0x45af0:$x1: NanoCore.ClientPluginHost
- 0x4bac1:$x1: NanoCore.ClientPluginHost
- 0x5552d:$x1: NanoCore.ClientPluginHost
- 0x5f958:$x1: NanoCore.ClientPluginHost
- 0x6a935:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x14610:$x2: IClientNetworkHost
- 0x22247:$x2: IClientNetworkHost
- 0x32466:$x2: IClientNetworkHost
- 0x3f5db:$x2: IClientNetworkHost
- 0x45b29:$x2: IClientNetworkHost
- 0x5568a:$x2: IClientNetworkHost
- 0x5f991:$x2: IClientNetworkHost
- 0x6a94f:$x2: IClientNetworkHost
|
12.3.hbvo9thTAX.exe.3ee9652.5.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x145e3:$x2: NanoCore.ClientPluginHost
- 0x2221d:$x2: NanoCore.ClientPluginHost
- 0x32439:$x2: NanoCore.ClientPluginHost
- 0x3f5a2:$x2: NanoCore.ClientPluginHost
- 0x45af0:$x2: NanoCore.ClientPluginHost
- 0x4bac1:$x2: NanoCore.ClientPluginHost
- 0x5552d:$x2: NanoCore.ClientPluginHost
- 0x5f958:$x2: NanoCore.ClientPluginHost
- 0x6a935:$x2: NanoCore.ClientPluginHost
- 0x33408:$s2: FileCommand
- 0x1261:$s3: PipeExists
- 0x56483:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0x156be:$s4: PipeCreated
- 0x240cd:$s4: PipeCreated
- 0x37e0a:$s4: PipeCreated
- 0x3f6bf:$s4: PipeCreated
- 0x45c0b:$s4: PipeCreated
- 0x4bb9f:$s4: PipeCreated
- 0x55723:$s4: PipeCreated
|
12.3.hbvo9thTAX.exe.3ee9652.5.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.3.hbvo9thTAX.exe.3ee9652.5.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x14599:$a: NanoCore
- 0x145ae:$a: NanoCore
- 0x145e3:$a: NanoCore
- 0x221f8:$a: NanoCore
- 0x2221d:$a: NanoCore
- 0x22276:$a: NanoCore
- 0x32413:$a: NanoCore
- 0x32439:$a: NanoCore
- 0x32495:$a: NanoCore
- 0x3f2ea:$a: NanoCore
- 0x3f343:$a: NanoCore
- 0x3f376:$a: NanoCore
- 0x3f5a2:$a: NanoCore
- 0x3f61e:$a: NanoCore
- 0x3fc37:$a: NanoCore
- 0x3fd80:$a: NanoCore
- 0x40254:$a: NanoCore
|
12.2.hbvo9thTAX.exe.e50000.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2205:$x1: NanoCore.ClientPluginHost
- 0x223e:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.e50000.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2205:$x2: NanoCore.ClientPluginHost
- 0x2320:$s4: PipeCreated
- 0x221f:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.3cbbb32.13.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1f1db:$x1: NanoCore.ClientPluginHost
- 0x2e61b:$x1: NanoCore.ClientPluginHost
- 0x1f1f5:$x2: IClientNetworkHost
- 0x2e658:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3cbbb32.13.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1f1db:$x2: NanoCore.ClientPluginHost
- 0x2e61b:$x2: NanoCore.ClientPluginHost
- 0x22518:$s4: PipeCreated
- 0x31a6e:$s4: PipeCreated
- 0x1f1c8:$s5: IClientLoggingHost
- 0x2e645:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.5820000.25.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.5820000.25.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x8ba5:$x2: NanoCore.ClientPluginHost
- 0x9b74:$s2: FileCommand
- 0xe576:$s4: PipeCreated
- 0x8bbf:$s5: IClientLoggingHost
|
13.2.dhcpmon.exe.3e03290.1.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x429ad:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x429ea:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x4651d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
13.2.dhcpmon.exe.3e03290.1.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x42725:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x429ad:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x43fe6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x43fda:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x44e8b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x4ac42:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
- 0x429d7:$s5: IClientLoggingHost
|
13.2.dhcpmon.exe.3e03290.1.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
13.2.dhcpmon.exe.3e03290.1.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0x42715:$a: NanoCore
- 0x42725:$a: NanoCore
- 0x42959:$a: NanoCore
- 0x4296d:$a: NanoCore
- 0x429ad:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x42774:$b: ClientPlugin
- 0x42976:$b: ClientPlugin
- 0x429b6:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x4289b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x432a2:$d: DESCrypto
- 0x1844e:$e: KeepAlive
|
12.2.hbvo9thTAX.exe.5810000.24.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.5810000.24.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
12.2.hbvo9thTAX.exe.3cb28fe.14.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x350b:$x1: NanoCore.ClientPluginHost
- 0x2840f:$x1: NanoCore.ClientPluginHost
- 0x3784f:$x1: NanoCore.ClientPluginHost
- 0x3525:$x2: IClientNetworkHost
- 0x28429:$x2: IClientNetworkHost
- 0x3788c:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3cb28fe.14.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x350b:$x2: NanoCore.ClientPluginHost
- 0x2840f:$x2: NanoCore.ClientPluginHost
- 0x3784f:$x2: NanoCore.ClientPluginHost
- 0x52b6:$s4: PipeCreated
- 0x2b74c:$s4: PipeCreated
- 0x3aca2:$s4: PipeCreated
- 0x34f8:$s5: IClientLoggingHost
- 0x283fc:$s5: IClientLoggingHost
- 0x37879:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.6ba0000.30.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x350b:$x1: NanoCore.ClientPluginHost
- 0x3525:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.6ba0000.30.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x350b:$x2: NanoCore.ClientPluginHost
- 0x52b6:$s4: PipeCreated
- 0x34f8:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3ef2ab1.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0x18dbe:$x1: NanoCore.ClientPluginHost
- 0x28fda:$x1: NanoCore.ClientPluginHost
- 0x36143:$x1: NanoCore.ClientPluginHost
- 0x3c691:$x1: NanoCore.ClientPluginHost
- 0x42662:$x1: NanoCore.ClientPluginHost
- 0x4c0ce:$x1: NanoCore.ClientPluginHost
- 0x564f9:$x1: NanoCore.ClientPluginHost
- 0x614d6:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
- 0x18de8:$x2: IClientNetworkHost
- 0x29007:$x2: IClientNetworkHost
- 0x3617c:$x2: IClientNetworkHost
- 0x3c6ca:$x2: IClientNetworkHost
- 0x4c22b:$x2: IClientNetworkHost
- 0x56532:$x2: IClientNetworkHost
- 0x614f0:$x2: IClientNetworkHost
|
12.3.hbvo9thTAX.exe.3ef2ab1.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0x18dbe:$x2: NanoCore.ClientPluginHost
- 0x28fda:$x2: NanoCore.ClientPluginHost
- 0x36143:$x2: NanoCore.ClientPluginHost
- 0x3c691:$x2: NanoCore.ClientPluginHost
- 0x42662:$x2: NanoCore.ClientPluginHost
- 0x4c0ce:$x2: NanoCore.ClientPluginHost
- 0x564f9:$x2: NanoCore.ClientPluginHost
- 0x614d6:$x2: NanoCore.ClientPluginHost
- 0x29fa9:$s2: FileCommand
- 0x4d024:$s3: PipeExists
- 0xc25f:$s4: PipeCreated
- 0x1ac6e:$s4: PipeCreated
- 0x2e9ab:$s4: PipeCreated
- 0x36260:$s4: PipeCreated
- 0x3c7ac:$s4: PipeCreated
- 0x42740:$s4: PipeCreated
- 0x4c2c4:$s4: PipeCreated
- 0x56644:$s4: PipeCreated
- 0x6250b:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3ef2ab1.4.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.3.hbvo9thTAX.exe.3ef2ab1.4.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xb13a:$a: NanoCore
- 0xb14f:$a: NanoCore
- 0xb184:$a: NanoCore
- 0x18d99:$a: NanoCore
- 0x18dbe:$a: NanoCore
- 0x18e17:$a: NanoCore
- 0x28fb4:$a: NanoCore
- 0x28fda:$a: NanoCore
- 0x29036:$a: NanoCore
- 0x35e8b:$a: NanoCore
- 0x35ee4:$a: NanoCore
- 0x35f17:$a: NanoCore
- 0x36143:$a: NanoCore
- 0x361bf:$a: NanoCore
- 0x367d8:$a: NanoCore
- 0x36921:$a: NanoCore
- 0x36df5:$a: NanoCore
- 0x370dc:$a: NanoCore
- 0x370f3:$a: NanoCore
- 0x3c691:$a: NanoCore
- 0x3c70b:$a: NanoCore
|
12.2.hbvo9thTAX.exe.6ba0000.30.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x170b:$x1: NanoCore.ClientPluginHost
- 0x1725:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.6ba0000.30.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x170b:$x2: NanoCore.ClientPluginHost
- 0x34b6:$s4: PipeCreated
- 0x16f8:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.df0000.3.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3f0b:$x1: NanoCore.ClientPluginHost
- 0x3f44:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.df0000.3.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3f0b:$x2: NanoCore.ClientPluginHost
- 0x400f:$s4: PipeCreated
- 0x3f25:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.58c0000.26.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x59eb:$x1: NanoCore.ClientPluginHost
- 0x5b48:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.58c0000.26.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x59eb:$x2: NanoCore.ClientPluginHost
- 0x6941:$s3: PipeExists
- 0x5be1:$s4: PipeCreated
- 0x5a05:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.2c47c04.9.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0xb563:$x1: NanoCore.ClientPluginHost
- 0x13469:$x1: NanoCore.ClientPluginHost
- 0x19444:$x1: NanoCore.ClientPluginHost
- 0x22edf:$x1: NanoCore.ClientPluginHost
- 0x2d2eb:$x1: NanoCore.ClientPluginHost
- 0x38305:$x1: NanoCore.ClientPluginHost
- 0x44083:$x1: NanoCore.ClientPluginHost
- 0x50046:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
- 0xb59c:$x2: IClientNetworkHost
- 0x134a2:$x2: IClientNetworkHost
- 0x2303c:$x2: IClientNetworkHost
- 0x2d324:$x2: IClientNetworkHost
- 0x3831f:$x2: IClientNetworkHost
- 0x4409d:$x2: IClientNetworkHost
- 0x50083:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.2c47c04.9.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x16e3:$x2: NanoCore.ClientPluginHost
- 0xb563:$x2: NanoCore.ClientPluginHost
- 0x13469:$x2: NanoCore.ClientPluginHost
- 0x19444:$x2: NanoCore.ClientPluginHost
- 0x22edf:$x2: NanoCore.ClientPluginHost
- 0x2d2eb:$x2: NanoCore.ClientPluginHost
- 0x38305:$x2: NanoCore.ClientPluginHost
- 0x44083:$x2: NanoCore.ClientPluginHost
- 0x50046:$x2: NanoCore.ClientPluginHost
- 0x23e35:$s3: PipeExists
- 0x1800:$s4: PipeCreated
- 0xb667:$s4: PipeCreated
- 0x13584:$s4: PipeCreated
- 0x19522:$s4: PipeCreated
- 0x230d5:$s4: PipeCreated
- 0x2d436:$s4: PipeCreated
- 0x3933a:$s4: PipeCreated
- 0x45e2e:$s4: PipeCreated
- 0x53499:$s4: PipeCreated
- 0x16fd:$s5: IClientLoggingHost
- 0xb57d:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.2c47c04.9.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x142b:$a: NanoCore
- 0x1484:$a: NanoCore
- 0x14b7:$a: NanoCore
- 0x16e3:$a: NanoCore
- 0x175f:$a: NanoCore
- 0x1d78:$a: NanoCore
- 0x1ec1:$a: NanoCore
- 0x2395:$a: NanoCore
- 0x267c:$a: NanoCore
- 0x2693:$a: NanoCore
- 0xb563:$a: NanoCore
- 0xb5df:$a: NanoCore
- 0xdec2:$a: NanoCore
- 0x13469:$a: NanoCore
- 0x134e3:$a: NanoCore
- 0x19444:$a: NanoCore
- 0x1948e:$a: NanoCore
- 0x1a0e8:$a: NanoCore
- 0x22edf:$a: NanoCore
- 0x22fc9:$a: NanoCore
- 0x23e40:$a: NanoCore
|
22.2.dhcpmon.exe.42095fe.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x145e3:$x1: NanoCore.ClientPluginHost
- 0x2d0af:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x14610:$x2: IClientNetworkHost
- 0x2d0dc:$x2: IClientNetworkHost
|
22.2.dhcpmon.exe.42095fe.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x145e3:$x2: NanoCore.ClientPluginHost
- 0x2d0af:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0x156be:$s4: PipeCreated
- 0x2e18a:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
- 0x145fd:$s5: IClientLoggingHost
- 0x2d0c9:$s5: IClientLoggingHost
|
22.2.dhcpmon.exe.42095fe.4.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
22.2.dhcpmon.exe.42095fe.4.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x14599:$a: NanoCore
- 0x145ae:$a: NanoCore
- 0x145e3:$a: NanoCore
- 0x2d065:$a: NanoCore
- 0x2d07a:$a: NanoCore
- 0x2d0af:$a: NanoCore
- 0xe41:$b: ClientPlugin
- 0xe7e:$b: ClientPlugin
- 0x177c:$b: ClientPlugin
- 0x1789:$b: ClientPlugin
- 0x14355:$b: ClientPlugin
- 0x14370:$b: ClientPlugin
- 0x143a0:$b: ClientPlugin
- 0x145b7:$b: ClientPlugin
- 0x145ec:$b: ClientPlugin
- 0x2ce21:$b: ClientPlugin
- 0x2ce3c:$b: ClientPlugin
|
12.2.hbvo9thTAX.exe.df0000.3.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b0b:$x1: NanoCore.ClientPluginHost
- 0x5b44:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.df0000.3.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5b0b:$x2: NanoCore.ClientPluginHost
- 0x5c0f:$s4: PipeCreated
- 0x5b25:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3eee488.3.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
12.3.hbvo9thTAX.exe.3eee488.3.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3eee488.3.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.2.hbvo9thTAX.exe.2c273c4.8.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14db1:$x1: NanoCore.ClientPluginHost
- 0x21f23:$x1: NanoCore.ClientPluginHost
- 0x2bda3:$x1: NanoCore.ClientPluginHost
- 0x33ca9:$x1: NanoCore.ClientPluginHost
- 0x39c84:$x1: NanoCore.ClientPluginHost
- 0x4371f:$x1: NanoCore.ClientPluginHost
- 0x4db2b:$x1: NanoCore.ClientPluginHost
- 0x58b45:$x1: NanoCore.ClientPluginHost
- 0x648c3:$x1: NanoCore.ClientPluginHost
- 0x70886:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14dde:$x2: IClientNetworkHost
- 0x21f5c:$x2: IClientNetworkHost
- 0x2bddc:$x2: IClientNetworkHost
- 0x33ce2:$x2: IClientNetworkHost
- 0x4387c:$x2: IClientNetworkHost
- 0x4db64:$x2: IClientNetworkHost
- 0x58b5f:$x2: IClientNetworkHost
- 0x648dd:$x2: IClientNetworkHost
- 0x708c3:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.2c273c4.8.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x4bbb:$x2: NanoCore.ClientPluginHost
- 0x14db1:$x2: NanoCore.ClientPluginHost
- 0x21f23:$x2: NanoCore.ClientPluginHost
- 0x2bda3:$x2: NanoCore.ClientPluginHost
- 0x33ca9:$x2: NanoCore.ClientPluginHost
- 0x39c84:$x2: NanoCore.ClientPluginHost
- 0x4371f:$x2: NanoCore.ClientPluginHost
- 0x4db2b:$x2: NanoCore.ClientPluginHost
- 0x58b45:$x2: NanoCore.ClientPluginHost
- 0x648c3:$x2: NanoCore.ClientPluginHost
- 0x70886:$x2: NanoCore.ClientPluginHost
- 0x15d80:$s2: FileCommand
- 0x44675:$s3: PipeExists
- 0x6a6b:$s4: PipeCreated
- 0x1a782:$s4: PipeCreated
- 0x22040:$s4: PipeCreated
- 0x2bea7:$s4: PipeCreated
- 0x33dc4:$s4: PipeCreated
- 0x39d62:$s4: PipeCreated
- 0x43915:$s4: PipeCreated
- 0x4dc76:$s4: PipeCreated
|
12.2.hbvo9thTAX.exe.2c273c4.8.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14d8b:$a: NanoCore
- 0x14db1:$a: NanoCore
- 0x14e0d:$a: NanoCore
- 0x21c6b:$a: NanoCore
- 0x21cc4:$a: NanoCore
- 0x21cf7:$a: NanoCore
- 0x21f23:$a: NanoCore
- 0x21f9f:$a: NanoCore
- 0x225b8:$a: NanoCore
- 0x22701:$a: NanoCore
- 0x22bd5:$a: NanoCore
- 0x22ebc:$a: NanoCore
- 0x22ed3:$a: NanoCore
- 0x2bda3:$a: NanoCore
- 0x2be1f:$a: NanoCore
- 0x2e702:$a: NanoCore
- 0x33ca9:$a: NanoCore
- 0x33d23:$a: NanoCore
|
22.2.dhcpmon.exe.31e3ac8.3.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
22.2.dhcpmon.exe.31e3ac8.3.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.3c0b529.10.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3c0b529.10.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0xc25f:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.3c0b529.10.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.3.hbvo9thTAX.exe.3ecc004.2.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
12.3.hbvo9thTAX.exe.3ecc004.2.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
12.2.hbvo9thTAX.exe.3dc7ce1.17.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14dd9:$x1: NanoCore.ClientPluginHost
- 0x21f44:$x1: NanoCore.ClientPluginHost
- 0x2bd98:$x1: NanoCore.ClientPluginHost
- 0x33cc0:$x1: NanoCore.ClientPluginHost
- 0x39c93:$x1: NanoCore.ClientPluginHost
- 0x43701:$x1: NanoCore.ClientPluginHost
- 0x4db2e:$x1: NanoCore.ClientPluginHost
- 0x58b0d:$x1: NanoCore.ClientPluginHost
- 0x648b1:$x1: NanoCore.ClientPluginHost
- 0x897b7:$x1: NanoCore.ClientPluginHost
- 0x98bf9:$x1: NanoCore.ClientPluginHost
- 0xc0202:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14e06:$x2: IClientNetworkHost
- 0x21f7d:$x2: IClientNetworkHost
- 0x2bdd1:$x2: IClientNetworkHost
- 0x33cf9:$x2: IClientNetworkHost
- 0x4385e:$x2: IClientNetworkHost
- 0x4db67:$x2: IClientNetworkHost
- 0x58b27:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3dc7ce1.17.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14db3:$a: NanoCore
- 0x14dd9:$a: NanoCore
- 0x14e35:$a: NanoCore
- 0x21c8c:$a: NanoCore
- 0x21ce5:$a: NanoCore
- 0x21d18:$a: NanoCore
- 0x21f44:$a: NanoCore
- 0x21fc0:$a: NanoCore
- 0x225d9:$a: NanoCore
- 0x22722:$a: NanoCore
- 0x22bf6:$a: NanoCore
- 0x22edd:$a: NanoCore
- 0x22ef4:$a: NanoCore
- 0x2bd98:$a: NanoCore
- 0x2be14:$a: NanoCore
- 0x2e6f7:$a: NanoCore
- 0x33cc0:$a: NanoCore
- 0x33d3a:$a: NanoCore
|
12.2.hbvo9thTAX.exe.5810000.24.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.5810000.24.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x4bbb:$x2: NanoCore.ClientPluginHost
- 0x6a6b:$s4: PipeCreated
|
12.2.hbvo9thTAX.exe.58d0000.27.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x39eb:$x1: NanoCore.ClientPluginHost
- 0x3a24:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.58d0000.27.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x39eb:$x2: NanoCore.ClientPluginHost
- 0x3b36:$s4: PipeCreated
- 0x3a05:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.5470000.22.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.5470000.22.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.5470000.22.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.hbvo9thTAX.exe.42c1cc8.1.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
1.2.hbvo9thTAX.exe.42c1cc8.1.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
1.2.hbvo9thTAX.exe.42c1cc8.1.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.hbvo9thTAX.exe.42c1cc8.1.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
12.2.hbvo9thTAX.exe.3cc07d1.12.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1a53c:$x1: NanoCore.ClientPluginHost
- 0x2997c:$x1: NanoCore.ClientPluginHost
- 0x1a556:$x2: IClientNetworkHost
- 0x299b9:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3cc07d1.12.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1a53c:$x2: NanoCore.ClientPluginHost
- 0x2997c:$x2: NanoCore.ClientPluginHost
- 0x1d879:$s4: PipeCreated
- 0x2cdcf:$s4: PipeCreated
- 0x1a529:$s5: IClientLoggingHost
- 0x299a6:$s5: IClientLoggingHost
|
22.2.dhcpmon.exe.31d14d0.2.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
22.2.dhcpmon.exe.31d14d0.2.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3f63db8.7.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.3.hbvo9thTAX.exe.3f63db8.7.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xf763:$a: NanoCore
- 0xf778:$a: NanoCore
- 0xf7ad:$a: NanoCore
- 0x1d3c2:$a: NanoCore
- 0x1d3e7:$a: NanoCore
- 0x1d440:$a: NanoCore
- 0x2d5dd:$a: NanoCore
- 0x2d603:$a: NanoCore
- 0x2d65f:$a: NanoCore
- 0x3a4b4:$a: NanoCore
- 0x3a50d:$a: NanoCore
- 0x3a540:$a: NanoCore
- 0x3a76c:$a: NanoCore
- 0x3a7e8:$a: NanoCore
- 0x3ae01:$a: NanoCore
- 0x3af4a:$a: NanoCore
- 0x3b41e:$a: NanoCore
- 0x3b705:$a: NanoCore
- 0x3b71c:$a: NanoCore
- 0x40cba:$a: NanoCore
- 0x40d34:$a: NanoCore
|
12.3.hbvo9thTAX.exe.3eb37d8.1.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0x1d3e7:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
- 0x1d411:$x2: IClientNetworkHost
|
12.3.hbvo9thTAX.exe.3eb37d8.1.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x1d3e7:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0x1f297:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
12.3.hbvo9thTAX.exe.3eb37d8.1.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
22.2.dhcpmon.exe.4212a5d.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0x23c50:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
- 0x23c7d:$x2: IClientNetworkHost
|
22.2.dhcpmon.exe.4212a5d.5.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0x23c50:$x2: NanoCore.ClientPluginHost
- 0xc25f:$s4: PipeCreated
- 0x24d2b:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
- 0x23c6a:$s5: IClientLoggingHost
|
22.2.dhcpmon.exe.4212a5d.5.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.2.hbvo9thTAX.exe.5930000.28.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b99:$x1: NanoCore.ClientPluginHost
- 0x5bb3:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.5930000.28.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5b99:$x2: NanoCore.ClientPluginHost
- 0x6bce:$s4: PipeCreated
- 0x5b86:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.3dd3f15.15.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d10:$x1: NanoCore.ClientPluginHost
- 0x1fb64:$x1: NanoCore.ClientPluginHost
- 0x27a8c:$x1: NanoCore.ClientPluginHost
- 0x2da5f:$x1: NanoCore.ClientPluginHost
- 0x374cd:$x1: NanoCore.ClientPluginHost
- 0x418fa:$x1: NanoCore.ClientPluginHost
- 0x4c8d9:$x1: NanoCore.ClientPluginHost
- 0x5867d:$x1: NanoCore.ClientPluginHost
- 0x7d583:$x1: NanoCore.ClientPluginHost
- 0x8c9c5:$x1: NanoCore.ClientPluginHost
- 0xb3fce:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d49:$x2: IClientNetworkHost
- 0x1fb9d:$x2: IClientNetworkHost
- 0x27ac5:$x2: IClientNetworkHost
- 0x3762a:$x2: IClientNetworkHost
- 0x41933:$x2: IClientNetworkHost
- 0x4c8f3:$x2: IClientNetworkHost
- 0x58697:$x2: IClientNetworkHost
- 0x7d59d:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3dd3f15.15.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a58:$a: NanoCore
- 0x15ab1:$a: NanoCore
- 0x15ae4:$a: NanoCore
- 0x15d10:$a: NanoCore
- 0x15d8c:$a: NanoCore
- 0x163a5:$a: NanoCore
- 0x164ee:$a: NanoCore
- 0x169c2:$a: NanoCore
- 0x16ca9:$a: NanoCore
- 0x16cc0:$a: NanoCore
- 0x1fb64:$a: NanoCore
- 0x1fbe0:$a: NanoCore
- 0x224c3:$a: NanoCore
- 0x27a8c:$a: NanoCore
- 0x27b06:$a: NanoCore
- 0x2c6a3:$a: NanoCore
- 0x2da5f:$a: NanoCore
- 0x2daa9:$a: NanoCore
|
12.2.hbvo9thTAX.exe.3cbbb32.13.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1d3db:$x1: NanoCore.ClientPluginHost
- 0x1d3f5:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.3cbbb32.13.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1d3db:$x2: NanoCore.ClientPluginHost
- 0x20718:$s4: PipeCreated
- 0x1d3c8:$s5: IClientLoggingHost
|
22.2.dhcpmon.exe.420e434.6.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0x28279:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
- 0x282a6:$x2: IClientNetworkHost
|
22.2.dhcpmon.exe.420e434.6.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x28279:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0x29354:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
- 0x28293:$s5: IClientLoggingHost
|
22.2.dhcpmon.exe.420e434.6.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.2.hbvo9thTAX.exe.2c273c4.8.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.2c273c4.8.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
12.2.hbvo9thTAX.exe.6bb0000.31.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1f1db:$x1: NanoCore.ClientPluginHost
- 0x1f1f5:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.6bb0000.31.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1f1db:$x2: NanoCore.ClientPluginHost
- 0x22518:$s4: PipeCreated
- 0x1f1c8:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.58d0000.27.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1deb:$x1: NanoCore.ClientPluginHost
- 0x1e24:$x2: IClientNetworkHost
|
12.2.hbvo9thTAX.exe.58d0000.27.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1deb:$x2: NanoCore.ClientPluginHost
- 0x1f36:$s4: PipeCreated
- 0x1e05:$s5: IClientLoggingHost
|
12.2.hbvo9thTAX.exe.ea0000.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x13a8:$x1: NanoCore.ClientPluginHost
|
|