4.2.name.exe.31a89d8.4.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
4.2.name.exe.31a89d8.4.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
4.2.name.exe.455fab8.19.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
4.2.name.exe.455fab8.19.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
4.2.name.exe.455fab8.19.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.32dc3c4.7.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3f0b:$x1: NanoCore.ClientPluginHost
- 0x9230:$x1: NanoCore.ClientPluginHost
- 0x3f44:$x2: IClientNetworkHost
|
4.2.name.exe.32dc3c4.7.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3f0b:$x2: NanoCore.ClientPluginHost
- 0x9230:$x2: NanoCore.ClientPluginHost
- 0x400f:$s4: PipeCreated
- 0x930e:$s4: PipeCreated
- 0x3f25:$s5: IClientLoggingHost
- 0x924a:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7dcc70.3.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.3.wscript.exe.28c2f7dcc70.3.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7dcc70.3.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.3.wscript.exe.28c2f7dcc70.3.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
4.2.name.exe.60c0000.30.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x605:$x1: NanoCore.ClientPluginHost
- 0x63e:$x2: IClientNetworkHost
|
4.2.name.exe.60c0000.30.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x605:$x2: NanoCore.ClientPluginHost
- 0x720:$s4: PipeCreated
- 0x61f:$s5: IClientLoggingHost
|
4.2.name.exe.6050000.26.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
4.2.name.exe.6050000.26.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
4.2.name.exe.455fab8.19.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
4.2.name.exe.455fab8.19.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
4.2.name.exe.455fab8.19.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.6100000.33.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b99:$x1: NanoCore.ClientPluginHost
- 0x5bb3:$x2: IClientNetworkHost
|
4.2.name.exe.6100000.33.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5b99:$x2: NanoCore.ClientPluginHost
- 0x6bce:$s4: PipeCreated
- 0x5b86:$s5: IClientLoggingHost
|
4.2.name.exe.613e8a4.35.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x10937:$x1: NanoCore.ClientPluginHost
- 0x10951:$x2: IClientNetworkHost
|
4.2.name.exe.613e8a4.35.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x10937:$x2: NanoCore.ClientPluginHost
- 0x13c74:$s4: PipeCreated
- 0x10924:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7cbaf0.6.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1fa7d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
4.2.name.exe.5320000.20.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
4.2.name.exe.5320000.20.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
4.2.name.exe.53f0000.23.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
4.2.name.exe.53f0000.23.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
4.2.name.exe.53f0000.23.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.45640e1.18.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
|
4.2.name.exe.45640e1.18.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0xc25f:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
|
4.2.name.exe.45640e1.18.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.5320000.20.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
|
4.2.name.exe.5320000.20.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x4bbb:$x2: NanoCore.ClientPluginHost
- 0x6a6b:$s4: PipeCreated
|
4.2.name.exe.53f0000.23.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
4.2.name.exe.53f0000.23.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
4.2.name.exe.53f0000.23.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
3.2.file.exe.2912938.6.unpack | JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | |
4.2.name.exe.4127e02.11.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x145e3:$x1: NanoCore.ClientPluginHost
- 0x1e4dd:$x1: NanoCore.ClientPluginHost
- 0x31c4b:$x1: NanoCore.ClientPluginHost
- 0x3f885:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x14610:$x2: IClientNetworkHost
- 0x1e4f7:$x2: IClientNetworkHost
- 0x31c78:$x2: IClientNetworkHost
- 0x3f8af:$x2: IClientNetworkHost
|
4.2.name.exe.4127e02.11.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x145e3:$x2: NanoCore.ClientPluginHost
- 0x1e4dd:$x2: NanoCore.ClientPluginHost
- 0x31c4b:$x2: NanoCore.ClientPluginHost
- 0x3f885:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1e8c9:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0x156be:$s4: PipeCreated
- 0x1e79e:$s4: PipeCreated
- 0x32d26:$s4: PipeCreated
- 0x41735:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
- 0x145fd:$s5: IClientLoggingHost
- 0x1e518:$s5: IClientLoggingHost
- 0x31c65:$s5: IClientLoggingHost
|
4.2.name.exe.4127e02.11.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.4127e02.11.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x14599:$a: NanoCore
- 0x145ae:$a: NanoCore
- 0x145e3:$a: NanoCore
- 0x1e447:$a: NanoCore
- 0x1e4a0:$a: NanoCore
- 0x1e4dd:$a: NanoCore
- 0x1e556:$a: NanoCore
- 0x31c01:$a: NanoCore
- 0x31c16:$a: NanoCore
- 0x31c4b:$a: NanoCore
- 0x3f860:$a: NanoCore
- 0x3f885:$a: NanoCore
- 0x3f8de:$a: NanoCore
- 0xe41:$b: ClientPlugin
- 0xe7e:$b: ClientPlugin
- 0x177c:$b: ClientPlugin
- 0x1789:$b: ClientPlugin
|
4.0.name.exe.870000.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
4.0.name.exe.870000.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
4.0.name.exe.870000.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.0.name.exe.870000.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
4.2.name.exe.6100000.33.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3d99:$x1: NanoCore.ClientPluginHost
- 0x3db3:$x2: IClientNetworkHost
|
4.2.name.exe.6100000.33.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3d99:$x2: NanoCore.ClientPluginHost
- 0x4dce:$s4: PipeCreated
- 0x3d86:$s5: IClientLoggingHost
|
4.2.name.exe.32e7c4c.6.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x13a8:$x1: NanoCore.ClientPluginHost
- 0x7689:$x1: NanoCore.ClientPluginHost
- 0x11cef:$x1: NanoCore.ClientPluginHost
- 0x1c173:$x1: NanoCore.ClientPluginHost
- 0x271ad:$x1: NanoCore.ClientPluginHost
- 0x32fab:$x1: NanoCore.ClientPluginHost
- 0x3ed9e:$x1: NanoCore.ClientPluginHost
- 0x490c7:$x1: NanoCore.ClientPluginHost
- 0x4dee7:$x1: NanoCore.ClientPluginHost
- 0x76c2:$x2: IClientNetworkHost
- 0x11e4c:$x2: IClientNetworkHost
- 0x1c1ac:$x2: IClientNetworkHost
- 0x271c7:$x2: IClientNetworkHost
- 0x32fc5:$x2: IClientNetworkHost
- 0x3eddb:$x2: IClientNetworkHost
- 0x490e1:$x2: IClientNetworkHost
- 0x4df01:$x2: IClientNetworkHost
|
4.2.name.exe.32e7c4c.6.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x13a8:$x2: NanoCore.ClientPluginHost
- 0x7689:$x2: NanoCore.ClientPluginHost
- 0x11cef:$x2: NanoCore.ClientPluginHost
- 0x1c173:$x2: NanoCore.ClientPluginHost
- 0x271ad:$x2: NanoCore.ClientPluginHost
- 0x32fab:$x2: NanoCore.ClientPluginHost
- 0x3ed9e:$x2: NanoCore.ClientPluginHost
- 0x490c7:$x2: NanoCore.ClientPluginHost
- 0x4dee7:$x2: NanoCore.ClientPluginHost
- 0x12c45:$s3: PipeExists
- 0x494b3:$s3: PipeExists
- 0x4e2d3:$s3: PipeExists
- 0x1486:$s4: PipeCreated
- 0x77a4:$s4: PipeCreated
- 0x11ee5:$s4: PipeCreated
- 0x1c2be:$s4: PipeCreated
- 0x281e2:$s4: PipeCreated
- 0x34d56:$s4: PipeCreated
- 0x421f1:$s4: PipeCreated
- 0x49388:$s4: PipeCreated
- 0x4e1a8:$s4: PipeCreated
|
4.2.name.exe.32e7c4c.6.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x13a8:$a: NanoCore
- 0x13f2:$a: NanoCore
- 0x204c:$a: NanoCore
- 0x7689:$a: NanoCore
- 0x7703:$a: NanoCore
- 0x11cef:$a: NanoCore
- 0x11dd9:$a: NanoCore
- 0x12c50:$a: NanoCore
- 0x1be53:$a: NanoCore
- 0x1beb4:$a: NanoCore
- 0x1bef7:$a: NanoCore
- 0x1bf37:$a: NanoCore
- 0x1c173:$a: NanoCore
- 0x1c213:$a: NanoCore
- 0x1c9eb:$a: NanoCore
- 0x1cfde:$a: NanoCore
- 0x1d12f:$a: NanoCore
- 0x1df89:$a: NanoCore
- 0x1e1f0:$a: NanoCore
- 0x1e205:$a: NanoCore
- 0x1e224:$a: NanoCore
|
4.2.name.exe.6130000.37.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1f1db:$x1: NanoCore.ClientPluginHost
- 0x1f1f5:$x2: IClientNetworkHost
|
4.2.name.exe.6130000.37.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1f1db:$x2: NanoCore.ClientPluginHost
- 0x22518:$s4: PipeCreated
- 0x1f1c8:$s5: IClientLoggingHost
|
4.2.name.exe.60b0000.29.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x13a8:$x1: NanoCore.ClientPluginHost
|
4.2.name.exe.60b0000.29.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x13a8:$x2: NanoCore.ClientPluginHost
- 0x1486:$s4: PipeCreated
- 0x13c2:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7cbaf0.2.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1fa7d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
4.2.name.exe.6160000.38.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5fee:$x1: NanoCore.ClientPluginHost
- 0x602b:$x2: IClientNetworkHost
|
4.2.name.exe.6160000.38.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5fee:$x2: NanoCore.ClientPluginHost
- 0x9441:$s4: PipeCreated
- 0x6018:$s5: IClientLoggingHost
|
4.2.name.exe.60d0000.31.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x59eb:$x1: NanoCore.ClientPluginHost
- 0x5b48:$x2: IClientNetworkHost
|
4.2.name.exe.60d0000.31.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x59eb:$x2: NanoCore.ClientPluginHost
- 0x6941:$s3: PipeExists
- 0x5be1:$s4: PipeCreated
- 0x5a05:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7dcc70.5.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.3.wscript.exe.28c2f7dcc70.5.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7dcc70.5.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.3.wscript.exe.28c2f7dcc70.5.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
0.2.wscript.exe.28c2fc970e0.4.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.2.wscript.exe.28c2fc970e0.4.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
0.2.wscript.exe.28c2fc970e0.4.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.2.wscript.exe.28c2fc970e0.4.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
4.2.name.exe.60e0000.32.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x39eb:$x1: NanoCore.ClientPluginHost
- 0x3a24:$x2: IClientNetworkHost
|
4.2.name.exe.60e0000.32.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x39eb:$x2: NanoCore.ClientPluginHost
- 0x3b36:$s4: PipeCreated
- 0x3a05:$s5: IClientLoggingHost
|
4.2.name.exe.60d0000.31.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3deb:$x1: NanoCore.ClientPluginHost
- 0x3f48:$x2: IClientNetworkHost
|
4.2.name.exe.60d0000.31.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3deb:$x2: NanoCore.ClientPluginHost
- 0x4d41:$s3: PipeExists
- 0x3fe1:$s4: PipeCreated
- 0x3e05:$s5: IClientLoggingHost
|
4.2.name.exe.32d6944.8.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0xb58b:$x1: NanoCore.ClientPluginHost
- 0x126b0:$x1: NanoCore.ClientPluginHost
- 0x18991:$x1: NanoCore.ClientPluginHost
- 0x22ff7:$x1: NanoCore.ClientPluginHost
- 0x2d47b:$x1: NanoCore.ClientPluginHost
- 0x384b5:$x1: NanoCore.ClientPluginHost
- 0x442b3:$x1: NanoCore.ClientPluginHost
- 0x500a6:$x1: NanoCore.ClientPluginHost
- 0x5a3cf:$x1: NanoCore.ClientPluginHost
- 0x5f1ef:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
- 0xb5c4:$x2: IClientNetworkHost
- 0x189ca:$x2: IClientNetworkHost
- 0x23154:$x2: IClientNetworkHost
- 0x2d4b4:$x2: IClientNetworkHost
- 0x384cf:$x2: IClientNetworkHost
- 0x442cd:$x2: IClientNetworkHost
- 0x500e3:$x2: IClientNetworkHost
- 0x5a3e9:$x2: IClientNetworkHost
- 0x5f209:$x2: IClientNetworkHost
|
4.2.name.exe.32d6944.8.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x16e3:$x2: NanoCore.ClientPluginHost
- 0xb58b:$x2: NanoCore.ClientPluginHost
- 0x126b0:$x2: NanoCore.ClientPluginHost
- 0x18991:$x2: NanoCore.ClientPluginHost
- 0x22ff7:$x2: NanoCore.ClientPluginHost
- 0x2d47b:$x2: NanoCore.ClientPluginHost
- 0x384b5:$x2: NanoCore.ClientPluginHost
- 0x442b3:$x2: NanoCore.ClientPluginHost
- 0x500a6:$x2: NanoCore.ClientPluginHost
- 0x5a3cf:$x2: NanoCore.ClientPluginHost
- 0x5f1ef:$x2: NanoCore.ClientPluginHost
- 0x23f4d:$s3: PipeExists
- 0x5a7bb:$s3: PipeExists
- 0x5f5db:$s3: PipeExists
- 0x1800:$s4: PipeCreated
- 0xb68f:$s4: PipeCreated
- 0x1278e:$s4: PipeCreated
- 0x18aac:$s4: PipeCreated
- 0x231ed:$s4: PipeCreated
- 0x2d5c6:$s4: PipeCreated
- 0x394ea:$s4: PipeCreated
|
4.2.name.exe.32d6944.8.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x142b:$a: NanoCore
- 0x1484:$a: NanoCore
- 0x14b7:$a: NanoCore
- 0x16e3:$a: NanoCore
- 0x175f:$a: NanoCore
- 0x1d78:$a: NanoCore
- 0x1ec1:$a: NanoCore
- 0x2395:$a: NanoCore
- 0x267c:$a: NanoCore
- 0x2693:$a: NanoCore
- 0xb58b:$a: NanoCore
- 0xb607:$a: NanoCore
- 0xdeea:$a: NanoCore
- 0x126b0:$a: NanoCore
- 0x126fa:$a: NanoCore
- 0x13354:$a: NanoCore
- 0x18991:$a: NanoCore
- 0x18a0b:$a: NanoCore
- 0x22ff7:$a: NanoCore
- 0x230e1:$a: NanoCore
- 0x23f58:$a: NanoCore
|
4.2.name.exe.43a63d9.15.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
4.2.name.exe.43a63d9.15.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
0.3.wscript.exe.28c2f7cbaf0.8.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1fa7d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
4.2.name.exe.6050000.26.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
|
4.2.name.exe.6050000.26.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x8ba5:$x2: NanoCore.ClientPluginHost
- 0x9b74:$s2: FileCommand
- 0xe576:$s4: PipeCreated
- 0x8bbf:$s5: IClientLoggingHost
|
4.2.name.exe.4186ef8.12.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
4.2.name.exe.4186ef8.12.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
4.2.name.exe.4186ef8.12.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.60c0000.30.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2205:$x1: NanoCore.ClientPluginHost
- 0x223e:$x2: IClientNetworkHost
|
4.2.name.exe.60c0000.30.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2205:$x2: NanoCore.ClientPluginHost
- 0x2320:$s4: PipeCreated
- 0x221f:$s5: IClientLoggingHost
|
4.2.name.exe.43b260d.16.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
4.2.name.exe.43b260d.16.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
4.2.name.exe.412cc38.10.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0x196a7:$x1: NanoCore.ClientPluginHost
- 0x2ce15:$x1: NanoCore.ClientPluginHost
- 0x3aa4f:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
- 0x196c1:$x2: IClientNetworkHost
- 0x2ce42:$x2: IClientNetworkHost
- 0x3aa79:$x2: IClientNetworkHost
|
4.2.name.exe.412cc38.10.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x196a7:$x2: NanoCore.ClientPluginHost
- 0x2ce15:$x2: NanoCore.ClientPluginHost
- 0x3aa4f:$x2: NanoCore.ClientPluginHost
- 0x19a93:$s3: PipeExists
- 0x10888:$s4: PipeCreated
- 0x19968:$s4: PipeCreated
- 0x2def0:$s4: PipeCreated
- 0x3c8ff:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
- 0x196e2:$s5: IClientLoggingHost
- 0x2ce2f:$s5: IClientLoggingHost
|
4.2.name.exe.412cc38.10.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.412cc38.10.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xf763:$a: NanoCore
- 0xf778:$a: NanoCore
- 0xf7ad:$a: NanoCore
- 0x19611:$a: NanoCore
- 0x1966a:$a: NanoCore
- 0x196a7:$a: NanoCore
- 0x19720:$a: NanoCore
- 0x2cdcb:$a: NanoCore
- 0x2cde0:$a: NanoCore
- 0x2ce15:$a: NanoCore
- 0x3aa2a:$a: NanoCore
- 0x3aa4f:$a: NanoCore
- 0x3aaa8:$a: NanoCore
- 0xf51f:$b: ClientPlugin
- 0xf53a:$b: ClientPlugin
- 0xf56a:$b: ClientPlugin
- 0xf781:$b: ClientPlugin
- 0xf7b6:$b: ClientPlugin
- 0x19673:$b: ClientPlugin
- 0x196b0:$b: ClientPlugin
- 0x19fae:$b: ClientPlugin
|
4.2.name.exe.6134c9f.36.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1a53c:$x1: NanoCore.ClientPluginHost
- 0x1a556:$x2: IClientNetworkHost
|
4.2.name.exe.6134c9f.36.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1a53c:$x2: NanoCore.ClientPluginHost
- 0x1d879:$s4: PipeCreated
- 0x1a529:$s5: IClientLoggingHost
|
4.2.name.exe.60e0000.32.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1deb:$x1: NanoCore.ClientPluginHost
- 0x1e24:$x2: IClientNetworkHost
|
4.2.name.exe.60e0000.32.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1deb:$x2: NanoCore.ClientPluginHost
- 0x1f36:$s4: PipeCreated
- 0x1e05:$s5: IClientLoggingHost
|
4.2.name.exe.31a89d8.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14e19:$x1: NanoCore.ClientPluginHost
- 0x21fbf:$x1: NanoCore.ClientPluginHost
- 0x2be4b:$x1: NanoCore.ClientPluginHost
- 0x32f54:$x1: NanoCore.ClientPluginHost
- 0x39219:$x1: NanoCore.ClientPluginHost
- 0x43863:$x1: NanoCore.ClientPluginHost
- 0x4dccb:$x1: NanoCore.ClientPluginHost
- 0x58ce9:$x1: NanoCore.ClientPluginHost
- 0x64acb:$x1: NanoCore.ClientPluginHost
- 0x70886:$x1: NanoCore.ClientPluginHost
- 0x7a527:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14e46:$x2: IClientNetworkHost
- 0x21ff8:$x2: IClientNetworkHost
- 0x2be84:$x2: IClientNetworkHost
- 0x39252:$x2: IClientNetworkHost
- 0x439c0:$x2: IClientNetworkHost
- 0x4dd04:$x2: IClientNetworkHost
- 0x58d03:$x2: IClientNetworkHost
- 0x64ae5:$x2: IClientNetworkHost
|
4.2.name.exe.31a89d8.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x4bbb:$x2: NanoCore.ClientPluginHost
- 0x14e19:$x2: NanoCore.ClientPluginHost
- 0x21fbf:$x2: NanoCore.ClientPluginHost
- 0x2be4b:$x2: NanoCore.ClientPluginHost
- 0x32f54:$x2: NanoCore.ClientPluginHost
- 0x39219:$x2: NanoCore.ClientPluginHost
- 0x43863:$x2: NanoCore.ClientPluginHost
- 0x4dccb:$x2: NanoCore.ClientPluginHost
- 0x58ce9:$x2: NanoCore.ClientPluginHost
- 0x64acb:$x2: NanoCore.ClientPluginHost
- 0x70886:$x2: NanoCore.ClientPluginHost
- 0x7a527:$x2: NanoCore.ClientPluginHost
- 0x15de8:$s2: FileCommand
- 0x447b9:$s3: PipeExists
- 0x7a913:$s3: PipeExists
- 0x6a6b:$s4: PipeCreated
- 0x1a7ea:$s4: PipeCreated
- 0x220dc:$s4: PipeCreated
- 0x2bf4f:$s4: PipeCreated
- 0x33032:$s4: PipeCreated
- 0x39334:$s4: PipeCreated
|
4.2.name.exe.31a89d8.4.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14df3:$a: NanoCore
- 0x14e19:$a: NanoCore
- 0x14e75:$a: NanoCore
- 0x21d07:$a: NanoCore
- 0x21d60:$a: NanoCore
- 0x21d93:$a: NanoCore
- 0x21fbf:$a: NanoCore
- 0x2203b:$a: NanoCore
- 0x22654:$a: NanoCore
- 0x2279d:$a: NanoCore
- 0x22c71:$a: NanoCore
- 0x22f58:$a: NanoCore
- 0x22f6f:$a: NanoCore
- 0x2be4b:$a: NanoCore
- 0x2bec7:$a: NanoCore
- 0x2e7aa:$a: NanoCore
- 0x32f54:$a: NanoCore
- 0x32f9e:$a: NanoCore
|
0.3.wscript.exe.28c2f7dcc70.7.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.3.wscript.exe.28c2f7dcc70.7.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7dcc70.7.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.3.wscript.exe.28c2f7dcc70.7.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
4.2.name.exe.4131261.9.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0x1507e:$x1: NanoCore.ClientPluginHost
- 0x287ec:$x1: NanoCore.ClientPluginHost
- 0x36426:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
- 0x15098:$x2: IClientNetworkHost
- 0x28819:$x2: IClientNetworkHost
- 0x36450:$x2: IClientNetworkHost
|
4.2.name.exe.4131261.9.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0x1507e:$x2: NanoCore.ClientPluginHost
- 0x287ec:$x2: NanoCore.ClientPluginHost
- 0x36426:$x2: NanoCore.ClientPluginHost
- 0x1546a:$s3: PipeExists
- 0xc25f:$s4: PipeCreated
- 0x1533f:$s4: PipeCreated
- 0x298c7:$s4: PipeCreated
- 0x382d6:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
- 0x150b9:$s5: IClientLoggingHost
- 0x28806:$s5: IClientLoggingHost
|
4.2.name.exe.4131261.9.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.4131261.9.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xb13a:$a: NanoCore
- 0xb14f:$a: NanoCore
- 0xb184:$a: NanoCore
- 0x14fe8:$a: NanoCore
- 0x15041:$a: NanoCore
- 0x1507e:$a: NanoCore
- 0x150f7:$a: NanoCore
- 0x287a2:$a: NanoCore
- 0x287b7:$a: NanoCore
- 0x287ec:$a: NanoCore
- 0x36401:$a: NanoCore
- 0x36426:$a: NanoCore
- 0x3647f:$a: NanoCore
- 0xaef6:$b: ClientPlugin
- 0xaf11:$b: ClientPlugin
- 0xaf41:$b: ClientPlugin
- 0xb158:$b: ClientPlugin
- 0xb18d:$b: ClientPlugin
- 0x1504a:$b: ClientPlugin
- 0x15087:$b: ClientPlugin
- 0x15985:$b: ClientPlugin
|
4.2.name.exe.32dc3c4.7.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b0b:$x1: NanoCore.ClientPluginHost
- 0xcc30:$x1: NanoCore.ClientPluginHost
- 0x12f11:$x1: NanoCore.ClientPluginHost
- 0x1d577:$x1: NanoCore.ClientPluginHost
- 0x279fb:$x1: NanoCore.ClientPluginHost
- 0x32a35:$x1: NanoCore.ClientPluginHost
- 0x3e833:$x1: NanoCore.ClientPluginHost
- 0x4a626:$x1: NanoCore.ClientPluginHost
- 0x5494f:$x1: NanoCore.ClientPluginHost
- 0x5976f:$x1: NanoCore.ClientPluginHost
- 0x5b44:$x2: IClientNetworkHost
- 0x12f4a:$x2: IClientNetworkHost
- 0x1d6d4:$x2: IClientNetworkHost
- 0x27a34:$x2: IClientNetworkHost
- 0x32a4f:$x2: IClientNetworkHost
- 0x3e84d:$x2: IClientNetworkHost
- 0x4a663:$x2: IClientNetworkHost
- 0x54969:$x2: IClientNetworkHost
- 0x59789:$x2: IClientNetworkHost
|
4.2.name.exe.32dc3c4.7.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5b0b:$x2: NanoCore.ClientPluginHost
- 0xcc30:$x2: NanoCore.ClientPluginHost
- 0x12f11:$x2: NanoCore.ClientPluginHost
- 0x1d577:$x2: NanoCore.ClientPluginHost
- 0x279fb:$x2: NanoCore.ClientPluginHost
- 0x32a35:$x2: NanoCore.ClientPluginHost
- 0x3e833:$x2: NanoCore.ClientPluginHost
- 0x4a626:$x2: NanoCore.ClientPluginHost
- 0x5494f:$x2: NanoCore.ClientPluginHost
- 0x5976f:$x2: NanoCore.ClientPluginHost
- 0x1e4cd:$s3: PipeExists
- 0x54d3b:$s3: PipeExists
- 0x59b5b:$s3: PipeExists
- 0x5c0f:$s4: PipeCreated
- 0xcd0e:$s4: PipeCreated
- 0x1302c:$s4: PipeCreated
- 0x1d76d:$s4: PipeCreated
- 0x27b46:$s4: PipeCreated
- 0x33a6a:$s4: PipeCreated
- 0x405de:$s4: PipeCreated
- 0x4da79:$s4: PipeCreated
|
3.2.file.exe.da0000.1.unpack | JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | |
0.3.wscript.exe.28c2f7dcc70.1.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.3.wscript.exe.28c2f7dcc70.1.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7dcc70.1.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.3.wscript.exe.28c2f7dcc70.1.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
4.2.name.exe.6110000.34.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x350b:$x1: NanoCore.ClientPluginHost
- 0x3525:$x2: IClientNetworkHost
|
4.2.name.exe.6110000.34.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x350b:$x2: NanoCore.ClientPluginHost
- 0x52b6:$s4: PipeCreated
- 0x34f8:$s5: IClientLoggingHost
|
4.2.name.exe.32dc3c4.7.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x5b0b:$a: NanoCore
- 0x5b87:$a: NanoCore
- 0x846a:$a: NanoCore
- 0xcc30:$a: NanoCore
- 0xcc7a:$a: NanoCore
- 0xd8d4:$a: NanoCore
- 0x12f11:$a: NanoCore
- 0x12f8b:$a: NanoCore
- 0x1d577:$a: NanoCore
- 0x1d661:$a: NanoCore
- 0x1e4d8:$a: NanoCore
- 0x276db:$a: NanoCore
- 0x2773c:$a: NanoCore
- 0x2777f:$a: NanoCore
- 0x277bf:$a: NanoCore
- 0x279fb:$a: NanoCore
- 0x27a9b:$a: NanoCore
- 0x28273:$a: NanoCore
- 0x28866:$a: NanoCore
- 0x289b7:$a: NanoCore
- 0x29811:$a: NanoCore
|
4.2.name.exe.412cc38.10.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
4.2.name.exe.32e7c4c.6.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3889:$x1: NanoCore.ClientPluginHost
- 0x38c2:$x2: IClientNetworkHost
|
4.2.name.exe.412cc38.10.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
4.2.name.exe.32e7c4c.6.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3889:$x2: NanoCore.ClientPluginHost
- 0x39a4:$s4: PipeCreated
- 0x38a3:$s5: IClientLoggingHost
|
4.2.name.exe.412cc38.10.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.6130000.37.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1d3db:$x1: NanoCore.ClientPluginHost
- 0x1d3f5:$x2: IClientNetworkHost
|
4.2.name.exe.6130000.37.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1d3db:$x2: NanoCore.ClientPluginHost
- 0x20718:$s4: PipeCreated
- 0x1d3c8:$s5: IClientLoggingHost
|
4.2.name.exe.6160000.38.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x41ee:$x1: NanoCore.ClientPluginHost
- 0x422b:$x2: IClientNetworkHost
|
4.2.name.exe.6160000.38.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x41ee:$x2: NanoCore.ClientPluginHost
- 0x7641:$s4: PipeCreated
- 0x4218:$s5: IClientLoggingHost
|
4.2.name.exe.53f4629.24.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
|
4.2.name.exe.53f4629.24.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0xc25f:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
|
4.2.name.exe.53f4629.24.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.5350000.21.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
4.2.name.exe.5350000.21.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
4.2.name.exe.6070000.27.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
|
4.2.name.exe.6070000.27.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x16e3:$x2: NanoCore.ClientPluginHost
- 0x1800:$s4: PipeCreated
- 0x16fd:$s5: IClientLoggingHost
|
3.2.file.exe.da0000.1.raw.unpack | JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | |
4.2.name.exe.31b4c4c.5.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
4.2.name.exe.31b4c4c.5.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
4.2.name.exe.4186ef8.12.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
4.2.name.exe.4186ef8.12.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
4.2.name.exe.4186ef8.12.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.3.wscript.exe.28c2f7cbaf0.4.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1fa7d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
4.2.name.exe.6110000.34.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x170b:$x1: NanoCore.ClientPluginHost
- 0x1725:$x2: IClientNetworkHost
|
4.2.name.exe.6110000.34.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x170b:$x2: NanoCore.ClientPluginHost
- 0x34b6:$s4: PipeCreated
- 0x16f8:$s5: IClientLoggingHost
|
4.2.name.exe.6090000.28.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b0b:$x1: NanoCore.ClientPluginHost
- 0x5b44:$x2: IClientNetworkHost
|
4.2.name.exe.6090000.28.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5b0b:$x2: NanoCore.ClientPluginHost
- 0x5c0f:$s4: PipeCreated
- 0x5b25:$s5: IClientLoggingHost
|
4.2.name.exe.31c92b4.3.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0xb56f:$x1: NanoCore.ClientPluginHost
- 0x12678:$x1: NanoCore.ClientPluginHost
- 0x1893d:$x1: NanoCore.ClientPluginHost
- 0x22f87:$x1: NanoCore.ClientPluginHost
- 0x2d3ef:$x1: NanoCore.ClientPluginHost
- 0x3840d:$x1: NanoCore.ClientPluginHost
- 0x441ef:$x1: NanoCore.ClientPluginHost
- 0x4ffaa:$x1: NanoCore.ClientPluginHost
- 0x59c4b:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
- 0xb5a8:$x2: IClientNetworkHost
- 0x18976:$x2: IClientNetworkHost
- 0x230e4:$x2: IClientNetworkHost
- 0x2d428:$x2: IClientNetworkHost
- 0x38427:$x2: IClientNetworkHost
- 0x44209:$x2: IClientNetworkHost
- 0x4ffe7:$x2: IClientNetworkHost
- 0x59c65:$x2: IClientNetworkHost
|
4.2.name.exe.31c92b4.3.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x16e3:$x2: NanoCore.ClientPluginHost
- 0xb56f:$x2: NanoCore.ClientPluginHost
- 0x12678:$x2: NanoCore.ClientPluginHost
- 0x1893d:$x2: NanoCore.ClientPluginHost
- 0x22f87:$x2: NanoCore.ClientPluginHost
- 0x2d3ef:$x2: NanoCore.ClientPluginHost
- 0x3840d:$x2: NanoCore.ClientPluginHost
- 0x441ef:$x2: NanoCore.ClientPluginHost
- 0x4ffaa:$x2: NanoCore.ClientPluginHost
- 0x59c4b:$x2: NanoCore.ClientPluginHost
- 0x23edd:$s3: PipeExists
- 0x5a037:$s3: PipeExists
- 0x1800:$s4: PipeCreated
- 0xb673:$s4: PipeCreated
- 0x12756:$s4: PipeCreated
- 0x18a58:$s4: PipeCreated
- 0x2317d:$s4: PipeCreated
- 0x2d53a:$s4: PipeCreated
- 0x39442:$s4: PipeCreated
- 0x45f9a:$s4: PipeCreated
- 0x533fd:$s4: PipeCreated
|
4.2.name.exe.31c92b4.3.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x142b:$a: NanoCore
- 0x1484:$a: NanoCore
- 0x14b7:$a: NanoCore
- 0x16e3:$a: NanoCore
- 0x175f:$a: NanoCore
- 0x1d78:$a: NanoCore
- 0x1ec1:$a: NanoCore
- 0x2395:$a: NanoCore
- 0x267c:$a: NanoCore
- 0x2693:$a: NanoCore
- 0xb56f:$a: NanoCore
- 0xb5eb:$a: NanoCore
- 0xdece:$a: NanoCore
- 0x12678:$a: NanoCore
- 0x126c2:$a: NanoCore
- 0x1331c:$a: NanoCore
- 0x1893d:$a: NanoCore
- 0x189b7:$a: NanoCore
- 0x22f87:$a: NanoCore
- 0x23071:$a: NanoCore
- 0x23ee8:$a: NanoCore
|
4.2.name.exe.6090000.28.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3f0b:$x1: NanoCore.ClientPluginHost
- 0x3f44:$x2: IClientNetworkHost
|
4.2.name.exe.6090000.28.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3f0b:$x2: NanoCore.ClientPluginHost
- 0x400f:$s4: PipeCreated
- 0x3f25:$s5: IClientLoggingHost
|
0.3.wscript.exe.28c2f7cbaf0.10.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1fa7d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
4.2.name.exe.418b521.13.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
|
4.2.name.exe.418b521.13.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0xc25f:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
|
4.2.name.exe.418b521.13.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.455ac82.17.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x145e3:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x14610:$x2: IClientNetworkHost
|
4.2.name.exe.455ac82.17.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x145e3:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0x156be:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
- 0x145fd:$s5: IClientLoggingHost
|
4.2.name.exe.455ac82.17.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.455ac82.17.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x14599:$a: NanoCore
- 0x145ae:$a: NanoCore
- 0x145e3:$a: NanoCore
- 0xe41:$b: ClientPlugin
- 0xe7e:$b: ClientPlugin
- 0x177c:$b: ClientPlugin
- 0x1789:$b: ClientPlugin
- 0x14355:$b: ClientPlugin
- 0x14370:$b: ClientPlugin
- 0x143a0:$b: ClientPlugin
- 0x145b7:$b: ClientPlugin
- 0x145ec:$b: ClientPlugin
- 0x144cd:$c: ProjectData
- 0x12c9:$g: LogClientMessage
- 0x1249:$i: get_Connected
- 0x14e1c:$j: #=q
- 0x14e4c:$j: #=q
|
4.2.name.exe.870000.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
4.2.name.exe.870000.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
4.2.name.exe.870000.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.name.exe.870000.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
0.3.wscript.exe.28c2f7cbaf0.9.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1fa7d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.2.wscript.exe.28c2fc970e0.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0.2.wscript.exe.28c2fc970e0.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
0.2.wscript.exe.28c2fc970e0.4.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0.2.wscript.exe.28c2fc970e0.4.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
3.2.file.exe.2912938.6.raw.unpack | JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | |
4.2.name.exe.31b4c4c.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d4b:$x1: NanoCore.ClientPluginHost
- 0x1fbd7:$x1: NanoCore.ClientPluginHost
- 0x26ce0:$x1: NanoCore.ClientPluginHost
- 0x2cfa5:$x1: NanoCore.ClientPluginHost
- 0x375ef:$x1: NanoCore.ClientPluginHost
- 0x41a57:$x1: NanoCore.ClientPluginHost
- 0x4ca75:$x1: NanoCore.ClientPluginHost
- 0x58857:$x1: NanoCore.ClientPluginHost
- 0x64612:$x1: NanoCore.ClientPluginHost
- 0x6e2b3:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d84:$x2: IClientNetworkHost
- 0x1fc10:$x2: IClientNetworkHost
- 0x2cfde:$x2: IClientNetworkHost
- 0x3774c:$x2: IClientNetworkHost
- 0x41a90:$x2: IClientNetworkHost
- 0x4ca8f:$x2: IClientNetworkHost
- 0x58871:$x2: IClientNetworkHost
- 0x6464f:$x2: IClientNetworkHost
- 0x6e2cd:$x2: IClientNetworkHost
|
4.2.name.exe.31b4c4c.5.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x8ba5:$x2: NanoCore.ClientPluginHost
- 0x15d4b:$x2: NanoCore.ClientPluginHost
- 0x1fbd7:$x2: NanoCore.ClientPluginHost
- 0x26ce0:$x2: NanoCore.ClientPluginHost
- 0x2cfa5:$x2: NanoCore.ClientPluginHost
- 0x375ef:$x2: NanoCore.ClientPluginHost
- 0x41a57:$x2: NanoCore.ClientPluginHost
- 0x4ca75:$x2: NanoCore.ClientPluginHost
- 0x58857:$x2: NanoCore.ClientPluginHost
- 0x64612:$x2: NanoCore.ClientPluginHost
- 0x6e2b3:$x2: NanoCore.ClientPluginHost
- 0x9b74:$s2: FileCommand
- 0x38545:$s3: PipeExists
- 0x6e69f:$s3: PipeExists
- 0xe576:$s4: PipeCreated
- 0x15e68:$s4: PipeCreated
- 0x1fcdb:$s4: PipeCreated
- 0x26dbe:$s4: PipeCreated
- 0x2d0c0:$s4: PipeCreated
- 0x377e5:$s4: PipeCreated
- 0x41ba2:$s4: PipeCreated
|
4.2.name.exe.31b4c4c.5.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a93:$a: NanoCore
- 0x15aec:$a: NanoCore
- 0x15b1f:$a: NanoCore
- 0x15d4b:$a: NanoCore
- 0x15dc7:$a: NanoCore
- 0x163e0:$a: NanoCore
- 0x16529:$a: NanoCore
- 0x169fd:$a: NanoCore
- 0x16ce4:$a: NanoCore
- 0x16cfb:$a: NanoCore
- 0x1fbd7:$a: NanoCore
- 0x1fc53:$a: NanoCore
- 0x22536:$a: NanoCore
- 0x26ce0:$a: NanoCore
- 0x26d2a:$a: NanoCore
- 0x27984:$a: NanoCore
- 0x2cfa5:$a: NanoCore
- 0x2d01f:$a: NanoCore
|
4.2.name.exe.43a63d9.15.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14db3:$a: NanoCore
- 0x14dd9:$a: NanoCore
- 0x14e35:$a: NanoCore
- 0x21c8c:$a: NanoCore
- 0x21ce5:$a: NanoCore
- 0x21d18:$a: NanoCore
- 0x21f44:$a: NanoCore
- 0x21fc0:$a: NanoCore
- 0x225d9:$a: NanoCore
- 0x22722:$a: NanoCore
- 0x22bf6:$a: NanoCore
- 0x22edd:$a: NanoCore
- 0x22ef4:$a: NanoCore
- 0x2bd98:$a: NanoCore
- 0x2be14:$a: NanoCore
- 0x2e6f7:$a: NanoCore
- 0x31aa9:$a: NanoCore
- 0x32e65:$a: NanoCore
|
4.2.name.exe.3131398.2.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
4.2.name.exe.3131398.2.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
4.2.name.exe.43c6c3a.14.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x142b:$a: NanoCore
- 0x1484:$a: NanoCore
- 0x14b7:$a: NanoCore
- 0x16e3:$a: NanoCore
- 0x175f:$a: NanoCore
- 0x1d78:$a: NanoCore
- 0x1ec1:$a: NanoCore
- 0x2395:$a: NanoCore
- 0x267c:$a: NanoCore
- 0x2693:$a: NanoCore
- 0xb537:$a: NanoCore
- 0xb5b3:$a: NanoCore
- 0xde96:$a: NanoCore
- 0x11248:$a: NanoCore
- 0x12604:$a: NanoCore
- 0x1264e:$a: NanoCore
- 0x132a8:$a: NanoCore
- 0x1888f:$a: NanoCore
- 0x18909:$a: NanoCore
- 0x22ea0:$a: NanoCore
- 0x22f8a:$a: NanoCore
|
4.2.name.exe.43b260d.16.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a58:$a: NanoCore
- 0x15ab1:$a: NanoCore
- 0x15ae4:$a: NanoCore
- 0x15d10:$a: NanoCore
- 0x15d8c:$a: NanoCore
- 0x163a5:$a: NanoCore
- 0x164ee:$a: NanoCore
- 0x169c2:$a: NanoCore
- 0x16ca9:$a: NanoCore
- 0x16cc0:$a: NanoCore
- 0x1fb64:$a: NanoCore
- 0x1fbe0:$a: NanoCore
- 0x224c3:$a: NanoCore
- 0x25875:$a: NanoCore
- 0x26c31:$a: NanoCore
- 0x26c7b:$a: NanoCore
- 0x278d5:$a: NanoCore
- 0x2cebc:$a: NanoCore
|
Click to see the 168 entries |