32.2.dhcpmon.exe.3a46662.7.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.3a46662.7.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
4.2.swift copy.exe.6cd0000.15.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2205:$x1: NanoCore.ClientPluginHost
- 0x223e:$x2: IClientNetworkHost
|
4.2.swift copy.exe.6cd0000.15.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2205:$x2: NanoCore.ClientPluginHost
- 0x2320:$s4: PipeCreated
- 0x221f:$s5: IClientLoggingHost
|
4.2.swift copy.exe.5c30000.11.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
4.2.swift copy.exe.5c30000.11.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
32.2.dhcpmon.exe.294b9ec.2.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.294b9ec.2.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
4.2.swift copy.exe.32918cc.2.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
4.2.swift copy.exe.32918cc.2.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
1.2.swift copy.exe.4a6f510.6.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
1.2.swift copy.exe.4a6f510.6.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
1.2.swift copy.exe.4a6f510.6.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.swift copy.exe.4a6f510.6.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
4.2.swift copy.exe.43b2894.6.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
4.2.swift copy.exe.43b2894.6.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
1.2.swift copy.exe.4a6f510.6.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
1.2.swift copy.exe.4a6f510.6.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
1.2.swift copy.exe.4a6f510.6.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
32.2.dhcpmon.exe.294b9ec.2.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d57:$x1: NanoCore.ClientPluginHost
- 0x1fc7b:$x1: NanoCore.ClientPluginHost
- 0x27be9:$x1: NanoCore.ClientPluginHost
- 0x2dc04:$x1: NanoCore.ClientPluginHost
- 0x356bb:$x1: NanoCore.ClientPluginHost
- 0x407f1:$x1: NanoCore.ClientPluginHost
- 0x4c5df:$x1: NanoCore.ClientPluginHost
- 0x5842e:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d90:$x2: IClientNetworkHost
- 0x1fcb4:$x2: IClientNetworkHost
- 0x27c22:$x2: IClientNetworkHost
- 0x356f4:$x2: IClientNetworkHost
- 0x4080b:$x2: IClientNetworkHost
- 0x4c5f9:$x2: IClientNetworkHost
- 0x5846b:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.294b9ec.2.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x8ba5:$x2: NanoCore.ClientPluginHost
- 0x15d57:$x2: NanoCore.ClientPluginHost
- 0x1fc7b:$x2: NanoCore.ClientPluginHost
- 0x27be9:$x2: NanoCore.ClientPluginHost
- 0x2dc04:$x2: NanoCore.ClientPluginHost
- 0x356bb:$x2: NanoCore.ClientPluginHost
- 0x407f1:$x2: NanoCore.ClientPluginHost
- 0x4c5df:$x2: NanoCore.ClientPluginHost
- 0x5842e:$x2: NanoCore.ClientPluginHost
- 0x9b74:$s2: FileCommand
- 0xe576:$s4: PipeCreated
- 0x15e74:$s4: PipeCreated
- 0x1fd7f:$s4: PipeCreated
- 0x27d04:$s4: PipeCreated
- 0x2dce2:$s4: PipeCreated
- 0x35806:$s4: PipeCreated
- 0x41826:$s4: PipeCreated
- 0x4e38a:$s4: PipeCreated
- 0x5b881:$s4: PipeCreated
- 0x8bbf:$s5: IClientLoggingHost
- 0x15d71:$s5: IClientLoggingHost
|
32.2.dhcpmon.exe.294b9ec.2.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a9f:$a: NanoCore
- 0x15af8:$a: NanoCore
- 0x15b2b:$a: NanoCore
- 0x15d57:$a: NanoCore
- 0x15dd3:$a: NanoCore
- 0x163ec:$a: NanoCore
- 0x16535:$a: NanoCore
- 0x16a09:$a: NanoCore
- 0x16cf0:$a: NanoCore
- 0x16d07:$a: NanoCore
- 0x1fc7b:$a: NanoCore
- 0x1fcf7:$a: NanoCore
- 0x225da:$a: NanoCore
- 0x27be9:$a: NanoCore
- 0x27c63:$a: NanoCore
- 0x2dc04:$a: NanoCore
- 0x2dc4e:$a: NanoCore
- 0x2e8a8:$a: NanoCore
|
4.2.swift copy.exe.6d00000.17.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x39eb:$x1: NanoCore.ClientPluginHost
- 0x3a24:$x2: IClientNetworkHost
|
4.2.swift copy.exe.6d00000.17.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x39eb:$x2: NanoCore.ClientPluginHost
- 0x3b36:$s4: PipeCreated
- 0x3a05:$s5: IClientLoggingHost
|
32.2.dhcpmon.exe.3a52894.6.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.3a52894.6.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
4.2.swift copy.exe.5b40000.9.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
4.2.swift copy.exe.5b40000.9.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
4.2.swift copy.exe.6ce0000.16.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x13a8:$x1: NanoCore.ClientPluginHost
|
4.2.swift copy.exe.6ce0000.16.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x13a8:$x2: NanoCore.ClientPluginHost
- 0x1486:$s4: PipeCreated
- 0x13c2:$s5: IClientLoggingHost
|
29.2.dhcpmon.exe.29132a0.2.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14e71:$x1: NanoCore.ClientPluginHost
- 0x22023:$x1: NanoCore.ClientPluginHost
- 0x2bf47:$x1: NanoCore.ClientPluginHost
- 0x33eb5:$x1: NanoCore.ClientPluginHost
- 0x39ed0:$x1: NanoCore.ClientPluginHost
- 0x41987:$x1: NanoCore.ClientPluginHost
- 0x4cabd:$x1: NanoCore.ClientPluginHost
- 0x588ab:$x1: NanoCore.ClientPluginHost
- 0x646fa:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14e9e:$x2: IClientNetworkHost
- 0x2205c:$x2: IClientNetworkHost
- 0x2bf80:$x2: IClientNetworkHost
- 0x33eee:$x2: IClientNetworkHost
- 0x419c0:$x2: IClientNetworkHost
- 0x4cad7:$x2: IClientNetworkHost
- 0x588c5:$x2: IClientNetworkHost
- 0x64737:$x2: IClientNetworkHost
|
29.2.dhcpmon.exe.29132a0.2.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x4bbb:$x2: NanoCore.ClientPluginHost
- 0x14e71:$x2: NanoCore.ClientPluginHost
- 0x22023:$x2: NanoCore.ClientPluginHost
- 0x2bf47:$x2: NanoCore.ClientPluginHost
- 0x33eb5:$x2: NanoCore.ClientPluginHost
- 0x39ed0:$x2: NanoCore.ClientPluginHost
- 0x41987:$x2: NanoCore.ClientPluginHost
- 0x4cabd:$x2: NanoCore.ClientPluginHost
- 0x588ab:$x2: NanoCore.ClientPluginHost
- 0x646fa:$x2: NanoCore.ClientPluginHost
- 0x15e40:$s2: FileCommand
- 0x6a6b:$s4: PipeCreated
- 0x1a842:$s4: PipeCreated
- 0x22140:$s4: PipeCreated
- 0x2c04b:$s4: PipeCreated
- 0x33fd0:$s4: PipeCreated
- 0x39fae:$s4: PipeCreated
- 0x41ad2:$s4: PipeCreated
- 0x4daf2:$s4: PipeCreated
- 0x5a656:$s4: PipeCreated
- 0x67b4d:$s4: PipeCreated
|
29.2.dhcpmon.exe.29132a0.2.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14e4b:$a: NanoCore
- 0x14e71:$a: NanoCore
- 0x14ecd:$a: NanoCore
- 0x21d6b:$a: NanoCore
- 0x21dc4:$a: NanoCore
- 0x21df7:$a: NanoCore
- 0x22023:$a: NanoCore
- 0x2209f:$a: NanoCore
- 0x226b8:$a: NanoCore
- 0x22801:$a: NanoCore
- 0x22cd5:$a: NanoCore
- 0x22fbc:$a: NanoCore
- 0x22fd3:$a: NanoCore
- 0x2bf47:$a: NanoCore
- 0x2bfc3:$a: NanoCore
- 0x2e8a6:$a: NanoCore
- 0x33eb5:$a: NanoCore
- 0x33f2f:$a: NanoCore
|
4.2.swift copy.exe.6cd0000.15.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x605:$x1: NanoCore.ClientPluginHost
- 0x63e:$x2: IClientNetworkHost
|
4.2.swift copy.exe.6cd0000.15.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x605:$x2: NanoCore.ClientPluginHost
- 0x720:$s4: PipeCreated
- 0x61f:$s5: IClientLoggingHost
|
14.2.dhcpmon.exe.4d231b0.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
14.2.dhcpmon.exe.4d231b0.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
14.2.dhcpmon.exe.4d231b0.4.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
14.2.dhcpmon.exe.4d231b0.4.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
4.2.swift copy.exe.6d00000.17.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1deb:$x1: NanoCore.ClientPluginHost
- 0x1e24:$x2: IClientNetworkHost
|
4.2.swift copy.exe.6d00000.17.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1deb:$x2: NanoCore.ClientPluginHost
- 0x1f36:$s4: PipeCreated
- 0x1e05:$s5: IClientLoggingHost
|
14.2.dhcpmon.exe.46af9b0.2.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1551dd:$x1: NanoCore.ClientPluginHost
- 0x15521a:$x2: IClientNetworkHost
- 0x158d4d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
14.2.dhcpmon.exe.46af9b0.2.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
14.2.dhcpmon.exe.46af9b0.2.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x154f45:$a: NanoCore
- 0x154f55:$a: NanoCore
- 0x155189:$a: NanoCore
- 0x15519d:$a: NanoCore
- 0x1551dd:$a: NanoCore
- 0x154fa4:$b: ClientPlugin
- 0x1551a6:$b: ClientPlugin
- 0x1551e6:$b: ClientPlugin
- 0x1550cb:$c: ProjectData
- 0x155ad2:$d: DESCrypto
- 0x15d49e:$e: KeepAlive
- 0x15b48c:$g: LogClientMessage
- 0x157687:$i: get_Connected
- 0x155e08:$j: #=q
- 0x155e38:$j: #=q
- 0x155e54:$j: #=q
- 0x155e84:$j: #=q
- 0x155ea0:$j: #=q
- 0x155ebc:$j: #=q
- 0x155eec:$j: #=q
- 0x155f08:$j: #=q
|
12.2.dhcpmon.exe.47231b0.5.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
12.2.dhcpmon.exe.47231b0.5.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
12.2.dhcpmon.exe.47231b0.5.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.2.dhcpmon.exe.47231b0.5.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
4.2.swift copy.exe.328c9d8.3.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x9aaf:$x1: NanoCore.ClientPluginHost
- 0x19ce1:$x1: NanoCore.ClientPluginHost
- 0x26e5b:$x1: NanoCore.ClientPluginHost
- 0x30cbb:$x1: NanoCore.ClientPluginHost
- 0x38bf1:$x1: NanoCore.ClientPluginHost
- 0x3ebd4:$x1: NanoCore.ClientPluginHost
- 0x46653:$x1: NanoCore.ClientPluginHost
- 0x51645:$x1: NanoCore.ClientPluginHost
- 0x5d3fb:$x1: NanoCore.ClientPluginHost
- 0x6918a:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x9ad9:$x2: IClientNetworkHost
- 0x19d0e:$x2: IClientNetworkHost
- 0x26e94:$x2: IClientNetworkHost
- 0x30cf4:$x2: IClientNetworkHost
- 0x38c2a:$x2: IClientNetworkHost
- 0x4668c:$x2: IClientNetworkHost
- 0x5165f:$x2: IClientNetworkHost
- 0x5d415:$x2: IClientNetworkHost
- 0x691c7:$x2: IClientNetworkHost
|
4.2.swift copy.exe.328c9d8.3.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x9a8a:$a: NanoCore
- 0x9aaf:$a: NanoCore
- 0x9b08:$a: NanoCore
- 0x19cbb:$a: NanoCore
- 0x19ce1:$a: NanoCore
- 0x19d3d:$a: NanoCore
- 0x26ba3:$a: NanoCore
- 0x26bfc:$a: NanoCore
- 0x26c2f:$a: NanoCore
- 0x26e5b:$a: NanoCore
- 0x26ed7:$a: NanoCore
- 0x274f0:$a: NanoCore
- 0x27639:$a: NanoCore
- 0x27b0d:$a: NanoCore
- 0x27df4:$a: NanoCore
- 0x27e0b:$a: NanoCore
- 0x30cbb:$a: NanoCore
|
4.2.swift copy.exe.5c30000.11.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
|
4.2.swift copy.exe.5c30000.11.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x8ba5:$x2: NanoCore.ClientPluginHost
- 0x9b74:$s2: FileCommand
- 0xe576:$s4: PipeCreated
- 0x8bbf:$s5: IClientLoggingHost
|
14.2.dhcpmon.exe.4d231b0.4.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
14.2.dhcpmon.exe.4d231b0.4.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
14.2.dhcpmon.exe.4d231b0.4.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
14.2.dhcpmon.exe.4d231b0.4.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
4.2.swift copy.exe.5ca0000.12.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
|
4.2.swift copy.exe.5ca0000.12.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x16e3:$x2: NanoCore.ClientPluginHost
- 0x1800:$s4: PipeCreated
- 0x16fd:$s5: IClientLoggingHost
|
29.2.dhcpmon.exe.291f56c.3.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d57:$x1: NanoCore.ClientPluginHost
- 0x1fc7b:$x1: NanoCore.ClientPluginHost
- 0x27be9:$x1: NanoCore.ClientPluginHost
- 0x2dc04:$x1: NanoCore.ClientPluginHost
- 0x356bb:$x1: NanoCore.ClientPluginHost
- 0x407f1:$x1: NanoCore.ClientPluginHost
- 0x4c5df:$x1: NanoCore.ClientPluginHost
- 0x5842e:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d90:$x2: IClientNetworkHost
- 0x1fcb4:$x2: IClientNetworkHost
- 0x27c22:$x2: IClientNetworkHost
- 0x356f4:$x2: IClientNetworkHost
- 0x4080b:$x2: IClientNetworkHost
- 0x4c5f9:$x2: IClientNetworkHost
- 0x5846b:$x2: IClientNetworkHost
|
29.2.dhcpmon.exe.291f56c.3.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x8ba5:$x2: NanoCore.ClientPluginHost
- 0x15d57:$x2: NanoCore.ClientPluginHost
- 0x1fc7b:$x2: NanoCore.ClientPluginHost
- 0x27be9:$x2: NanoCore.ClientPluginHost
- 0x2dc04:$x2: NanoCore.ClientPluginHost
- 0x356bb:$x2: NanoCore.ClientPluginHost
- 0x407f1:$x2: NanoCore.ClientPluginHost
- 0x4c5df:$x2: NanoCore.ClientPluginHost
- 0x5842e:$x2: NanoCore.ClientPluginHost
- 0x9b74:$s2: FileCommand
- 0xe576:$s4: PipeCreated
- 0x15e74:$s4: PipeCreated
- 0x1fd7f:$s4: PipeCreated
- 0x27d04:$s4: PipeCreated
- 0x2dce2:$s4: PipeCreated
- 0x35806:$s4: PipeCreated
- 0x41826:$s4: PipeCreated
- 0x4e38a:$s4: PipeCreated
- 0x5b881:$s4: PipeCreated
- 0x8bbf:$s5: IClientLoggingHost
- 0x15d71:$s5: IClientLoggingHost
|
29.2.dhcpmon.exe.291f56c.3.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a9f:$a: NanoCore
- 0x15af8:$a: NanoCore
- 0x15b2b:$a: NanoCore
- 0x15d57:$a: NanoCore
- 0x15dd3:$a: NanoCore
- 0x163ec:$a: NanoCore
- 0x16535:$a: NanoCore
- 0x16a09:$a: NanoCore
- 0x16cf0:$a: NanoCore
- 0x16d07:$a: NanoCore
- 0x1fc7b:$a: NanoCore
- 0x1fcf7:$a: NanoCore
- 0x225da:$a: NanoCore
- 0x27be9:$a: NanoCore
- 0x27c63:$a: NanoCore
- 0x2dc04:$a: NanoCore
- 0x2dc4e:$a: NanoCore
- 0x2e8a8:$a: NanoCore
|
4.2.swift copy.exe.329db14.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d1f:$x1: NanoCore.ClientPluginHost
- 0x1fb7f:$x1: NanoCore.ClientPluginHost
- 0x27ab5:$x1: NanoCore.ClientPluginHost
- 0x2da98:$x1: NanoCore.ClientPluginHost
- 0x35517:$x1: NanoCore.ClientPluginHost
- 0x40509:$x1: NanoCore.ClientPluginHost
- 0x4c2bf:$x1: NanoCore.ClientPluginHost
- 0x5804e:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d58:$x2: IClientNetworkHost
- 0x1fbb8:$x2: IClientNetworkHost
- 0x27aee:$x2: IClientNetworkHost
- 0x35550:$x2: IClientNetworkHost
- 0x40523:$x2: IClientNetworkHost
- 0x4c2d9:$x2: IClientNetworkHost
- 0x5808b:$x2: IClientNetworkHost
|
4.2.swift copy.exe.329db14.4.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a67:$a: NanoCore
- 0x15ac0:$a: NanoCore
- 0x15af3:$a: NanoCore
- 0x15d1f:$a: NanoCore
- 0x15d9b:$a: NanoCore
- 0x163b4:$a: NanoCore
- 0x164fd:$a: NanoCore
- 0x169d1:$a: NanoCore
- 0x16cb8:$a: NanoCore
- 0x16ccf:$a: NanoCore
- 0x1fb7f:$a: NanoCore
- 0x1fbfb:$a: NanoCore
- 0x224de:$a: NanoCore
- 0x27ab5:$a: NanoCore
- 0x27b2f:$a: NanoCore
- 0x2da98:$a: NanoCore
- 0x2dae2:$a: NanoCore
- 0x2e73c:$a: NanoCore
|
32.2.dhcpmon.exe.3a52894.6.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d0e:$x1: NanoCore.ClientPluginHost
- 0x1fb60:$x1: NanoCore.ClientPluginHost
- 0x27a86:$x1: NanoCore.ClientPluginHost
- 0x2da57:$x1: NanoCore.ClientPluginHost
- 0x354c5:$x1: NanoCore.ClientPluginHost
- 0x404a2:$x1: NanoCore.ClientPluginHost
- 0x4c244:$x1: NanoCore.ClientPluginHost
- 0x6171c:$x1: NanoCore.ClientPluginHost
- 0x8997e:$x1: NanoCore.ClientPluginHost
- 0x98dbe:$x1: NanoCore.ClientPluginHost
- 0xb1161:$x1: NanoCore.ClientPluginHost
- 0xd93af:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d47:$x2: IClientNetworkHost
- 0x1fb99:$x2: IClientNetworkHost
- 0x27abf:$x2: IClientNetworkHost
- 0x354fe:$x2: IClientNetworkHost
- 0x404bc:$x2: IClientNetworkHost
- 0x4c25e:$x2: IClientNetworkHost
- 0x61749:$x2: IClientNetworkHost
|
4.2.swift copy.exe.6cc0000.14.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3f0b:$x1: NanoCore.ClientPluginHost
- 0x3f44:$x2: IClientNetworkHost
|
4.2.swift copy.exe.6cc0000.14.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3f0b:$x2: NanoCore.ClientPluginHost
- 0x400f:$s4: PipeCreated
- 0x3f25:$s5: IClientLoggingHost
|
29.2.dhcpmon.exe.3a22894.5.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
4.2.swift copy.exe.5b50000.10.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
|
4.2.swift copy.exe.5b50000.10.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x4bbb:$x2: NanoCore.ClientPluginHost
- 0x6a6b:$s4: PipeCreated
|
32.2.dhcpmon.exe.293f720.3.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.293f720.3.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
29.2.dhcpmon.exe.3a16662.7.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14dd7:$x1: NanoCore.ClientPluginHost
- 0x21f40:$x1: NanoCore.ClientPluginHost
- 0x2bd92:$x1: NanoCore.ClientPluginHost
- 0x33cb8:$x1: NanoCore.ClientPluginHost
- 0x39c89:$x1: NanoCore.ClientPluginHost
- 0x416f7:$x1: NanoCore.ClientPluginHost
- 0x4c6d4:$x1: NanoCore.ClientPluginHost
- 0x58476:$x1: NanoCore.ClientPluginHost
- 0x6d94e:$x1: NanoCore.ClientPluginHost
- 0x95bb0:$x1: NanoCore.ClientPluginHost
- 0xa4ff0:$x1: NanoCore.ClientPluginHost
- 0xbd393:$x1: NanoCore.ClientPluginHost
- 0xe55e1:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14e04:$x2: IClientNetworkHost
- 0x21f79:$x2: IClientNetworkHost
- 0x2bdcb:$x2: IClientNetworkHost
- 0x33cf1:$x2: IClientNetworkHost
- 0x41730:$x2: IClientNetworkHost
- 0x4c6ee:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.293a6e4.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x9bf7:$x1: NanoCore.ClientPluginHost
- 0x19ead:$x1: NanoCore.ClientPluginHost
- 0x2705f:$x1: NanoCore.ClientPluginHost
- 0x30f83:$x1: NanoCore.ClientPluginHost
- 0x38ef1:$x1: NanoCore.ClientPluginHost
- 0x3ef0c:$x1: NanoCore.ClientPluginHost
- 0x469c3:$x1: NanoCore.ClientPluginHost
- 0x51af9:$x1: NanoCore.ClientPluginHost
- 0x5d8e7:$x1: NanoCore.ClientPluginHost
- 0x69736:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x9c21:$x2: IClientNetworkHost
- 0x19eda:$x2: IClientNetworkHost
- 0x27098:$x2: IClientNetworkHost
- 0x30fbc:$x2: IClientNetworkHost
- 0x38f2a:$x2: IClientNetworkHost
- 0x469fc:$x2: IClientNetworkHost
- 0x51b13:$x2: IClientNetworkHost
- 0x5d901:$x2: IClientNetworkHost
- 0x69773:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.293a6e4.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x9bf7:$x2: NanoCore.ClientPluginHost
- 0x19ead:$x2: NanoCore.ClientPluginHost
- 0x2705f:$x2: NanoCore.ClientPluginHost
- 0x30f83:$x2: NanoCore.ClientPluginHost
- 0x38ef1:$x2: NanoCore.ClientPluginHost
- 0x3ef0c:$x2: NanoCore.ClientPluginHost
- 0x469c3:$x2: NanoCore.ClientPluginHost
- 0x51af9:$x2: NanoCore.ClientPluginHost
- 0x5d8e7:$x2: NanoCore.ClientPluginHost
- 0x69736:$x2: NanoCore.ClientPluginHost
- 0x1ae7c:$s2: FileCommand
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xbaa7:$s4: PipeCreated
- 0x1f87e:$s4: PipeCreated
- 0x2717c:$s4: PipeCreated
- 0x31087:$s4: PipeCreated
- 0x3900c:$s4: PipeCreated
- 0x3efea:$s4: PipeCreated
- 0x46b0e:$s4: PipeCreated
|
32.2.dhcpmon.exe.293a6e4.4.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x9bd2:$a: NanoCore
- 0x9bf7:$a: NanoCore
- 0x9c50:$a: NanoCore
- 0x19e87:$a: NanoCore
- 0x19ead:$a: NanoCore
- 0x19f09:$a: NanoCore
- 0x26da7:$a: NanoCore
- 0x26e00:$a: NanoCore
- 0x26e33:$a: NanoCore
- 0x2705f:$a: NanoCore
- 0x270db:$a: NanoCore
- 0x276f4:$a: NanoCore
- 0x2783d:$a: NanoCore
- 0x27d11:$a: NanoCore
- 0x27ff8:$a: NanoCore
- 0x2800f:$a: NanoCore
- 0x30f83:$a: NanoCore
|
4.2.swift copy.exe.6cc0000.14.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b0b:$x1: NanoCore.ClientPluginHost
- 0x5b44:$x2: IClientNetworkHost
|
4.2.swift copy.exe.6cc0000.14.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5b0b:$x2: NanoCore.ClientPluginHost
- 0x5c0f:$s4: PipeCreated
- 0x5b25:$s5: IClientLoggingHost
|
32.2.dhcpmon.exe.3a52894.6.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
32.2.dhcpmon.exe.3a52894.6.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a56:$a: NanoCore
- 0x15aaf:$a: NanoCore
- 0x15ae2:$a: NanoCore
- 0x15d0e:$a: NanoCore
- 0x15d8a:$a: NanoCore
- 0x163a3:$a: NanoCore
- 0x164ec:$a: NanoCore
- 0x169c0:$a: NanoCore
- 0x16ca7:$a: NanoCore
- 0x16cbe:$a: NanoCore
- 0x1fb60:$a: NanoCore
- 0x1fbdc:$a: NanoCore
- 0x224bf:$a: NanoCore
- 0x27a86:$a: NanoCore
- 0x27b00:$a: NanoCore
- 0x2c69d:$a: NanoCore
- 0x2da57:$a: NanoCore
- 0x2daa1:$a: NanoCore
|
29.2.dhcpmon.exe.3a16662.7.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
29.2.dhcpmon.exe.3a22894.5.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
29.2.dhcpmon.exe.3a16662.7.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14db1:$a: NanoCore
- 0x14dd7:$a: NanoCore
- 0x14e33:$a: NanoCore
- 0x21c88:$a: NanoCore
- 0x21ce1:$a: NanoCore
- 0x21d14:$a: NanoCore
- 0x21f40:$a: NanoCore
- 0x21fbc:$a: NanoCore
- 0x225d5:$a: NanoCore
- 0x2271e:$a: NanoCore
- 0x22bf2:$a: NanoCore
- 0x22ed9:$a: NanoCore
- 0x22ef0:$a: NanoCore
- 0x2bd92:$a: NanoCore
- 0x2be0e:$a: NanoCore
- 0x2e6f1:$a: NanoCore
- 0x33cb8:$a: NanoCore
- 0x33d32:$a: NanoCore
|
32.2.dhcpmon.exe.400000.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
32.2.dhcpmon.exe.400000.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
32.2.dhcpmon.exe.400000.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
32.2.dhcpmon.exe.400000.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
32.2.dhcpmon.exe.3a46662.7.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14dd7:$x1: NanoCore.ClientPluginHost
- 0x21f40:$x1: NanoCore.ClientPluginHost
- 0x2bd92:$x1: NanoCore.ClientPluginHost
- 0x33cb8:$x1: NanoCore.ClientPluginHost
- 0x39c89:$x1: NanoCore.ClientPluginHost
- 0x416f7:$x1: NanoCore.ClientPluginHost
- 0x4c6d4:$x1: NanoCore.ClientPluginHost
- 0x58476:$x1: NanoCore.ClientPluginHost
- 0x6d94e:$x1: NanoCore.ClientPluginHost
- 0x95bb0:$x1: NanoCore.ClientPluginHost
- 0xa4ff0:$x1: NanoCore.ClientPluginHost
- 0xbd393:$x1: NanoCore.ClientPluginHost
- 0xe55e1:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14e04:$x2: IClientNetworkHost
- 0x21f79:$x2: IClientNetworkHost
- 0x2bdcb:$x2: IClientNetworkHost
- 0x33cf1:$x2: IClientNetworkHost
- 0x41730:$x2: IClientNetworkHost
- 0x4c6ee:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.3a46662.7.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
32.2.dhcpmon.exe.3a46662.7.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14db1:$a: NanoCore
- 0x14dd7:$a: NanoCore
- 0x14e33:$a: NanoCore
- 0x21c88:$a: NanoCore
- 0x21ce1:$a: NanoCore
- 0x21d14:$a: NanoCore
- 0x21f40:$a: NanoCore
- 0x21fbc:$a: NanoCore
- 0x225d5:$a: NanoCore
- 0x2271e:$a: NanoCore
- 0x22bf2:$a: NanoCore
- 0x22ed9:$a: NanoCore
- 0x22ef0:$a: NanoCore
- 0x2bd92:$a: NanoCore
- 0x2be0e:$a: NanoCore
- 0x2e6f1:$a: NanoCore
- 0x33cb8:$a: NanoCore
- 0x33d32:$a: NanoCore
|
4.2.swift copy.exe.5b50000.10.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
4.2.swift copy.exe.5b50000.10.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
12.2.dhcpmon.exe.47231b0.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
12.2.dhcpmon.exe.47231b0.5.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
12.2.dhcpmon.exe.47231b0.5.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
12.2.dhcpmon.exe.47231b0.5.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
29.2.dhcpmon.exe.3a16662.7.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
29.2.dhcpmon.exe.3a16662.7.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
29.2.dhcpmon.exe.29132a0.2.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
29.2.dhcpmon.exe.29132a0.2.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
4.2.swift copy.exe.400000.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
4.2.swift copy.exe.400000.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
4.2.swift copy.exe.400000.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.swift copy.exe.400000.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
4.2.swift copy.exe.43a6662.7.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
4.2.swift copy.exe.43a6662.7.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
29.2.dhcpmon.exe.291f56c.3.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
29.2.dhcpmon.exe.291f56c.3.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
4.2.swift copy.exe.329db14.4.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
4.2.swift copy.exe.329db14.4.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
29.2.dhcpmon.exe.3a11836.6.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x99e7:$x1: NanoCore.ClientPluginHost
- 0x19c03:$x1: NanoCore.ClientPluginHost
- 0x26d6c:$x1: NanoCore.ClientPluginHost
- 0x30bbe:$x1: NanoCore.ClientPluginHost
- 0x38ae4:$x1: NanoCore.ClientPluginHost
- 0x3eab5:$x1: NanoCore.ClientPluginHost
- 0x46523:$x1: NanoCore.ClientPluginHost
- 0x51500:$x1: NanoCore.ClientPluginHost
- 0x5d2a2:$x1: NanoCore.ClientPluginHost
- 0x7277a:$x1: NanoCore.ClientPluginHost
- 0x9a9dc:$x1: NanoCore.ClientPluginHost
- 0xa9e1c:$x1: NanoCore.ClientPluginHost
- 0xc21bf:$x1: NanoCore.ClientPluginHost
- 0xea40d:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x9a11:$x2: IClientNetworkHost
- 0x19c30:$x2: IClientNetworkHost
- 0x26da5:$x2: IClientNetworkHost
- 0x30bf7:$x2: IClientNetworkHost
- 0x38b1d:$x2: IClientNetworkHost
|
29.2.dhcpmon.exe.3a11836.6.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
29.2.dhcpmon.exe.3a11836.6.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x99c2:$a: NanoCore
- 0x99e7:$a: NanoCore
- 0x9a40:$a: NanoCore
- 0x19bdd:$a: NanoCore
- 0x19c03:$a: NanoCore
- 0x19c5f:$a: NanoCore
- 0x26ab4:$a: NanoCore
- 0x26b0d:$a: NanoCore
- 0x26b40:$a: NanoCore
- 0x26d6c:$a: NanoCore
- 0x26de8:$a: NanoCore
- 0x27401:$a: NanoCore
- 0x2754a:$a: NanoCore
- 0x27a1e:$a: NanoCore
- 0x27d05:$a: NanoCore
- 0x27d1c:$a: NanoCore
- 0x30bbe:$a: NanoCore
|
29.2.dhcpmon.exe.400000.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
29.2.dhcpmon.exe.400000.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
29.2.dhcpmon.exe.400000.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
29.2.dhcpmon.exe.400000.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
32.2.dhcpmon.exe.293f720.3.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14e71:$x1: NanoCore.ClientPluginHost
- 0x22023:$x1: NanoCore.ClientPluginHost
- 0x2bf47:$x1: NanoCore.ClientPluginHost
- 0x33eb5:$x1: NanoCore.ClientPluginHost
- 0x39ed0:$x1: NanoCore.ClientPluginHost
- 0x41987:$x1: NanoCore.ClientPluginHost
- 0x4cabd:$x1: NanoCore.ClientPluginHost
- 0x588ab:$x1: NanoCore.ClientPluginHost
- 0x646fa:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14e9e:$x2: IClientNetworkHost
- 0x2205c:$x2: IClientNetworkHost
- 0x2bf80:$x2: IClientNetworkHost
- 0x33eee:$x2: IClientNetworkHost
- 0x419c0:$x2: IClientNetworkHost
- 0x4cad7:$x2: IClientNetworkHost
- 0x588c5:$x2: IClientNetworkHost
- 0x64737:$x2: IClientNetworkHost
|
32.2.dhcpmon.exe.293f720.3.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x4bbb:$x2: NanoCore.ClientPluginHost
- 0x14e71:$x2: NanoCore.ClientPluginHost
- 0x22023:$x2: NanoCore.ClientPluginHost
- 0x2bf47:$x2: NanoCore.ClientPluginHost
- 0x33eb5:$x2: NanoCore.ClientPluginHost
- 0x39ed0:$x2: NanoCore.ClientPluginHost
- 0x41987:$x2: NanoCore.ClientPluginHost
- 0x4cabd:$x2: NanoCore.ClientPluginHost
- 0x588ab:$x2: NanoCore.ClientPluginHost
- 0x646fa:$x2: NanoCore.ClientPluginHost
- 0x15e40:$s2: FileCommand
- 0x6a6b:$s4: PipeCreated
- 0x1a842:$s4: PipeCreated
- 0x22140:$s4: PipeCreated
- 0x2c04b:$s4: PipeCreated
- 0x33fd0:$s4: PipeCreated
- 0x39fae:$s4: PipeCreated
- 0x41ad2:$s4: PipeCreated
- 0x4daf2:$s4: PipeCreated
- 0x5a656:$s4: PipeCreated
- 0x67b4d:$s4: PipeCreated
|
32.2.dhcpmon.exe.293f720.3.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14e4b:$a: NanoCore
- 0x14e71:$a: NanoCore
- 0x14ecd:$a: NanoCore
- 0x21d6b:$a: NanoCore
- 0x21dc4:$a: NanoCore
- 0x21df7:$a: NanoCore
- 0x22023:$a: NanoCore
- 0x2209f:$a: NanoCore
- 0x226b8:$a: NanoCore
- 0x22801:$a: NanoCore
- 0x22cd5:$a: NanoCore
- 0x22fbc:$a: NanoCore
- 0x22fd3:$a: NanoCore
- 0x2bf47:$a: NanoCore
- 0x2bfc3:$a: NanoCore
- 0x2e8a6:$a: NanoCore
- 0x33eb5:$a: NanoCore
- 0x33f2f:$a: NanoCore
|
4.2.swift copy.exe.43a1836.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0x99e7:$x1: NanoCore.ClientPluginHost
- 0x19c03:$x1: NanoCore.ClientPluginHost
- 0x26d6c:$x1: NanoCore.ClientPluginHost
- 0x30bbe:$x1: NanoCore.ClientPluginHost
- 0x38ae4:$x1: NanoCore.ClientPluginHost
- 0x3eab5:$x1: NanoCore.ClientPluginHost
- 0x46523:$x1: NanoCore.ClientPluginHost
- 0x51500:$x1: NanoCore.ClientPluginHost
- 0x5d2a2:$x1: NanoCore.ClientPluginHost
- 0x7277a:$x1: NanoCore.ClientPluginHost
- 0x9a9dc:$x1: NanoCore.ClientPluginHost
- 0xa9e1c:$x1: NanoCore.ClientPluginHost
- 0xc21bf:$x1: NanoCore.ClientPluginHost
- 0xea40d:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
- 0x9a11:$x2: IClientNetworkHost
- 0x19c30:$x2: IClientNetworkHost
- 0x26da5:$x2: IClientNetworkHost
- 0x30bf7:$x2: IClientNetworkHost
- 0x38b1d:$x2: IClientNetworkHost
|
4.2.swift copy.exe.43a1836.5.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
4.2.swift copy.exe.43a1836.5.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x99c2:$a: NanoCore
- 0x99e7:$a: NanoCore
- 0x9a40:$a: NanoCore
- 0x19bdd:$a: NanoCore
- 0x19c03:$a: NanoCore
- 0x19c5f:$a: NanoCore
- 0x26ab4:$a: NanoCore
- 0x26b0d:$a: NanoCore
- 0x26b40:$a: NanoCore
- 0x26d6c:$a: NanoCore
- 0x26de8:$a: NanoCore
- 0x27401:$a: NanoCore
- 0x2754a:$a: NanoCore
- 0x27a1e:$a: NanoCore
- 0x27d05:$a: NanoCore
- 0x27d1c:$a: NanoCore
- 0x30bbe:$a: NanoCore
|
4.2.swift copy.exe.32918cc.2.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14ded:$x1: NanoCore.ClientPluginHost
- 0x21f67:$x1: NanoCore.ClientPluginHost
- 0x2bdc7:$x1: NanoCore.ClientPluginHost
- 0x33cfd:$x1: NanoCore.ClientPluginHost
- 0x39ce0:$x1: NanoCore.ClientPluginHost
- 0x4175f:$x1: NanoCore.ClientPluginHost
- 0x4c751:$x1: NanoCore.ClientPluginHost
- 0x58507:$x1: NanoCore.ClientPluginHost
- 0x64296:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14e1a:$x2: IClientNetworkHost
- 0x21fa0:$x2: IClientNetworkHost
- 0x2be00:$x2: IClientNetworkHost
- 0x33d36:$x2: IClientNetworkHost
- 0x41798:$x2: IClientNetworkHost
- 0x4c76b:$x2: IClientNetworkHost
- 0x58521:$x2: IClientNetworkHost
- 0x642d3:$x2: IClientNetworkHost
|
4.2.swift copy.exe.32918cc.2.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14dc7:$a: NanoCore
- 0x14ded:$a: NanoCore
- 0x14e49:$a: NanoCore
- 0x21caf:$a: NanoCore
|