9.2.sys30.exe.38bc03e.28.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
9.2.sys30.exe.38bc03e.28.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
9.2.sys30.exe.640000.6.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
9.2.sys30.exe.640000.6.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
7.2.sys30.exe.38e56c8.10.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
7.2.sys30.exe.38e56c8.10.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
7.2.sys30.exe.38e56c8.10.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
7.2.sys30.exe.38e56c8.10.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
9.2.sys30.exe.274d950.20.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
9.2.sys30.exe.274d950.20.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
9.2.sys30.exe.6a0000.7.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
|
9.2.sys30.exe.6a0000.7.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x16e3:$x2: NanoCore.ClientPluginHost
- 0x1800:$s4: PipeCreated
- 0x16fd:$s5: IClientLoggingHost
|
9.2.sys30.exe.377d06d.25.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
9.2.sys30.exe.377d06d.25.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
9.2.sys30.exe.bb0000.11.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x59eb:$x1: NanoCore.ClientPluginHost
- 0x5b48:$x2: IClientNetworkHost
|
9.2.sys30.exe.bb0000.11.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x59eb:$x2: NanoCore.ClientPluginHost
- 0x6941:$s3: PipeExists
- 0x5be1:$s4: PipeCreated
- 0x5a05:$s5: IClientLoggingHost
|
9.2.sys30.exe.d80000.15.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5fee:$x1: NanoCore.ClientPluginHost
- 0x602b:$x2: IClientNetworkHost
|
9.2.sys30.exe.d80000.15.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5fee:$x2: NanoCore.ClientPluginHost
- 0x9441:$s4: PipeCreated
- 0x6018:$s5: IClientLoggingHost
|
9.2.sys30.exe.397b2b6.32.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x350b:$x1: NanoCore.ClientPluginHost
- 0x2840f:$x1: NanoCore.ClientPluginHost
- 0x3784f:$x1: NanoCore.ClientPluginHost
- 0x3525:$x2: IClientNetworkHost
- 0x28429:$x2: IClientNetworkHost
- 0x3788c:$x2: IClientNetworkHost
|
9.2.sys30.exe.397b2b6.32.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x350b:$x2: NanoCore.ClientPluginHost
- 0x2840f:$x2: NanoCore.ClientPluginHost
- 0x3784f:$x2: NanoCore.ClientPluginHost
- 0x52b6:$s4: PipeCreated
- 0x2b74c:$s4: PipeCreated
- 0x3aca2:$s4: PipeCreated
- 0x34f8:$s5: IClientLoggingHost
- 0x283fc:$s5: IClientLoggingHost
- 0x37879:$s5: IClientLoggingHost
|
9.2.sys30.exe.564629.4.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
|
9.2.sys30.exe.564629.4.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0xc25f:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
|
9.2.sys30.exe.564629.4.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
9.2.sys30.exe.3770e39.27.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2dbb:$x1: NanoCore.ClientPluginHost
- 0x2de5:$x2: IClientNetworkHost
|
9.2.sys30.exe.3770e39.27.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2dbb:$x2: NanoCore.ClientPluginHost
- 0x4c6b:$s4: PipeCreated
|
9.2.sys30.exe.bb0000.11.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3deb:$x1: NanoCore.ClientPluginHost
- 0x3f48:$x2: IClientNetworkHost
|
9.2.sys30.exe.bb0000.11.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3deb:$x2: NanoCore.ClientPluginHost
- 0x4d41:$s3: PipeExists
- 0x3fe1:$s4: PipeCreated
- 0x3e05:$s5: IClientLoggingHost
|
9.2.sys30.exe.9f0000.9.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2205:$x1: NanoCore.ClientPluginHost
- 0x223e:$x2: IClientNetworkHost
|
9.2.sys30.exe.9f0000.9.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2205:$x2: NanoCore.ClientPluginHost
- 0x2320:$s4: PipeCreated
- 0x221f:$s5: IClientLoggingHost
|
9.2.sys30.exe.38bc03e.28.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d0e:$x1: NanoCore.ClientPluginHost
- 0x1c25c:$x1: NanoCore.ClientPluginHost
- 0x2222d:$x1: NanoCore.ClientPluginHost
- 0x2bc99:$x1: NanoCore.ClientPluginHost
- 0x360c4:$x1: NanoCore.ClientPluginHost
- 0x410a1:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d47:$x2: IClientNetworkHost
- 0x1c295:$x2: IClientNetworkHost
- 0x2bdf6:$x2: IClientNetworkHost
- 0x360fd:$x2: IClientNetworkHost
- 0x410bb:$x2: IClientNetworkHost
|
9.2.sys30.exe.38bc03e.28.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x8ba5:$x2: NanoCore.ClientPluginHost
- 0x15d0e:$x2: NanoCore.ClientPluginHost
- 0x1c25c:$x2: NanoCore.ClientPluginHost
- 0x2222d:$x2: NanoCore.ClientPluginHost
- 0x2bc99:$x2: NanoCore.ClientPluginHost
- 0x360c4:$x2: NanoCore.ClientPluginHost
- 0x410a1:$x2: NanoCore.ClientPluginHost
- 0x9b74:$s2: FileCommand
- 0x2cbef:$s3: PipeExists
- 0xe576:$s4: PipeCreated
- 0x15e2b:$s4: PipeCreated
- 0x1c377:$s4: PipeCreated
- 0x2230b:$s4: PipeCreated
- 0x2be8f:$s4: PipeCreated
- 0x3620f:$s4: PipeCreated
- 0x420d6:$s4: PipeCreated
- 0x8bbf:$s5: IClientLoggingHost
- 0x15d28:$s5: IClientLoggingHost
- 0x1c276:$s5: IClientLoggingHost
- 0x22247:$s5: IClientLoggingHost
- 0x2bcb3:$s5: IClientLoggingHost
|
9.2.sys30.exe.38bc03e.28.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a56:$a: NanoCore
- 0x15aaf:$a: NanoCore
- 0x15ae2:$a: NanoCore
- 0x15d0e:$a: NanoCore
- 0x15d8a:$a: NanoCore
- 0x163a3:$a: NanoCore
- 0x164ec:$a: NanoCore
- 0x169c0:$a: NanoCore
- 0x16ca7:$a: NanoCore
- 0x16cbe:$a: NanoCore
- 0x1c25c:$a: NanoCore
- 0x1c2d6:$a: NanoCore
- 0x20e73:$a: NanoCore
- 0x2222d:$a: NanoCore
- 0x22277:$a: NanoCore
- 0x22ed1:$a: NanoCore
- 0x2bc99:$a: NanoCore
- 0x2bd83:$a: NanoCore
|
9.2.sys30.exe.ba0000.10.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x13a8:$x1: NanoCore.ClientPluginHost
|
9.2.sys30.exe.ba0000.10.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x13a8:$x2: NanoCore.ClientPluginHost
- 0x1486:$s4: PipeCreated
- 0x13c2:$s5: IClientLoggingHost
|
9.2.sys30.exe.26ee188.22.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xddf:$a: NanoCore
- 0xe38:$a: NanoCore
- 0xe75:$a: NanoCore
- 0xeee:$a: NanoCore
- 0x6435e:$a: NanoCore
- 0x64383:$a: NanoCore
- 0x643dc:$a: NanoCore
- 0x7458f:$a: NanoCore
- 0x745b5:$a: NanoCore
- 0x74611:$a: NanoCore
- 0x81477:$a: NanoCore
- 0x814d0:$a: NanoCore
- 0x81503:$a: NanoCore
- 0x8172f:$a: NanoCore
- 0x817ab:$a: NanoCore
- 0x81dc4:$a: NanoCore
- 0x81f0d:$a: NanoCore
- 0x823e1:$a: NanoCore
- 0x826c8:$a: NanoCore
- 0x826df:$a: NanoCore
- 0x8b58f:$a: NanoCore
|
9.2.sys30.exe.560000.3.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
9.2.sys30.exe.560000.3.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
9.2.sys30.exe.560000.3.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
9.2.sys30.exe.740000.8.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3f0b:$x1: NanoCore.ClientPluginHost
- 0x3f44:$x2: IClientNetworkHost
|
9.2.sys30.exe.740000.8.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3f0b:$x2: NanoCore.ClientPluginHost
- 0x400f:$s4: PipeCreated
- 0x3f25:$s5: IClientLoggingHost
|
9.2.sys30.exe.396ce86.33.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b99:$x1: NanoCore.ClientPluginHost
- 0x1193b:$x1: NanoCore.ClientPluginHost
- 0x3683f:$x1: NanoCore.ClientPluginHost
- 0x45c7f:$x1: NanoCore.ClientPluginHost
- 0x5bb3:$x2: IClientNetworkHost
- 0x11955:$x2: IClientNetworkHost
- 0x36859:$x2: IClientNetworkHost
- 0x45cbc:$x2: IClientNetworkHost
|
9.2.sys30.exe.396ce86.33.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5b99:$x2: NanoCore.ClientPluginHost
- 0x1193b:$x2: NanoCore.ClientPluginHost
- 0x3683f:$x2: NanoCore.ClientPluginHost
- 0x45c7f:$x2: NanoCore.ClientPluginHost
- 0x6bce:$s4: PipeCreated
- 0x136e6:$s4: PipeCreated
- 0x39b7c:$s4: PipeCreated
- 0x490d2:$s4: PipeCreated
- 0x5b86:$s5: IClientLoggingHost
- 0x11928:$s5: IClientLoggingHost
- 0x3682c:$s5: IClientLoggingHost
- 0x45ca9:$s5: IClientLoggingHost
|
9.2.sys30.exe.2759b98.21.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x15d1f:$x1: NanoCore.ClientPluginHost
- 0x1fb7f:$x1: NanoCore.ClientPluginHost
- 0x27ab5:$x1: NanoCore.ClientPluginHost
- 0x2da98:$x1: NanoCore.ClientPluginHost
- 0x37513:$x1: NanoCore.ClientPluginHost
- 0x4194f:$x1: NanoCore.ClientPluginHost
- 0x4c941:$x1: NanoCore.ClientPluginHost
- 0x586f7:$x1: NanoCore.ClientPluginHost
- 0x6444e:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
- 0x15d58:$x2: IClientNetworkHost
- 0x1fbb8:$x2: IClientNetworkHost
- 0x27aee:$x2: IClientNetworkHost
- 0x37670:$x2: IClientNetworkHost
- 0x41988:$x2: IClientNetworkHost
- 0x4c95b:$x2: IClientNetworkHost
- 0x58711:$x2: IClientNetworkHost
- 0x6448b:$x2: IClientNetworkHost
|
9.2.sys30.exe.2759b98.21.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x8b7f:$a: NanoCore
- 0x8ba5:$a: NanoCore
- 0x8c01:$a: NanoCore
- 0x15a67:$a: NanoCore
- 0x15ac0:$a: NanoCore
- 0x15af3:$a: NanoCore
- 0x15d1f:$a: NanoCore
- 0x15d9b:$a: NanoCore
- 0x163b4:$a: NanoCore
- 0x164fd:$a: NanoCore
- 0x169d1:$a: NanoCore
- 0x16cb8:$a: NanoCore
- 0x16ccf:$a: NanoCore
- 0x1fb7f:$a: NanoCore
- 0x1fbfb:$a: NanoCore
- 0x224de:$a: NanoCore
- 0x27ab5:$a: NanoCore
- 0x27b2f:$a: NanoCore
- 0x2da98:$a: NanoCore
- 0x2dae2:$a: NanoCore
- 0x2e73c:$a: NanoCore
|
9.2.sys30.exe.dd4c9f.18.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1a53c:$x1: NanoCore.ClientPluginHost
- 0x1a556:$x2: IClientNetworkHost
|
9.2.sys30.exe.dd4c9f.18.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1a53c:$x2: NanoCore.ClientPluginHost
- 0x1d879:$s4: PipeCreated
- 0x1a529:$s5: IClientLoggingHost
|
9.2.sys30.exe.70000.0.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
9.2.sys30.exe.70000.0.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
9.2.sys30.exe.70000.0.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
9.2.sys30.exe.70000.0.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
9.2.sys30.exe.3a7eed1.34.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0x18dbe:$x1: NanoCore.ClientPluginHost
- 0x28fda:$x1: NanoCore.ClientPluginHost
- 0x36143:$x1: NanoCore.ClientPluginHost
- 0x3c691:$x1: NanoCore.ClientPluginHost
- 0x42662:$x1: NanoCore.ClientPluginHost
- 0x4c0ce:$x1: NanoCore.ClientPluginHost
- 0x564f9:$x1: NanoCore.ClientPluginHost
- 0x614d6:$x1: NanoCore.ClientPluginHost
- 0x6d278:$x1: NanoCore.ClientPluginHost
- 0x9217c:$x1: NanoCore.ClientPluginHost
- 0xa15bc:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
- 0x18de8:$x2: IClientNetworkHost
- 0x29007:$x2: IClientNetworkHost
- 0x3617c:$x2: IClientNetworkHost
- 0x3c6ca:$x2: IClientNetworkHost
- 0x4c22b:$x2: IClientNetworkHost
- 0x56532:$x2: IClientNetworkHost
- 0x614f0:$x2: IClientNetworkHost
- 0x6d292:$x2: IClientNetworkHost
|
9.2.sys30.exe.3a7eed1.34.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
9.2.sys30.exe.3a7eed1.34.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xb13a:$a: NanoCore
- 0xb14f:$a: NanoCore
- 0xb184:$a: NanoCore
- 0x18d99:$a: NanoCore
- 0x18dbe:$a: NanoCore
- 0x18e17:$a: NanoCore
- 0x28fb4:$a: NanoCore
- 0x28fda:$a: NanoCore
- 0x29036:$a: NanoCore
- 0x35e8b:$a: NanoCore
- 0x35ee4:$a: NanoCore
- 0x35f17:$a: NanoCore
- 0x36143:$a: NanoCore
- 0x361bf:$a: NanoCore
- 0x367d8:$a: NanoCore
- 0x36921:$a: NanoCore
- 0x36df5:$a: NanoCore
- 0x370dc:$a: NanoCore
- 0x370f3:$a: NanoCore
- 0x3c691:$a: NanoCore
- 0x3c70b:$a: NanoCore
|
9.2.sys30.exe.3964057.31.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x39eb:$x1: NanoCore.ClientPluginHost
- 0xe9c8:$x1: NanoCore.ClientPluginHost
- 0x1a76a:$x1: NanoCore.ClientPluginHost
- 0x3f66e:$x1: NanoCore.ClientPluginHost
- 0x4eaae:$x1: NanoCore.ClientPluginHost
- 0x3a24:$x2: IClientNetworkHost
- 0xe9e2:$x2: IClientNetworkHost
- 0x1a784:$x2: IClientNetworkHost
- 0x3f688:$x2: IClientNetworkHost
- 0x4eaeb:$x2: IClientNetworkHost
|
9.2.sys30.exe.3964057.31.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x39eb:$x2: NanoCore.ClientPluginHost
- 0xe9c8:$x2: NanoCore.ClientPluginHost
- 0x1a76a:$x2: NanoCore.ClientPluginHost
- 0x3f66e:$x2: NanoCore.ClientPluginHost
- 0x4eaae:$x2: NanoCore.ClientPluginHost
- 0x3b36:$s4: PipeCreated
- 0xf9fd:$s4: PipeCreated
- 0x1c515:$s4: PipeCreated
- 0x429ab:$s4: PipeCreated
- 0x51f01:$s4: PipeCreated
- 0x3a05:$s5: IClientLoggingHost
- 0xe9b5:$s5: IClientLoggingHost
- 0x1a757:$s5: IClientLoggingHost
- 0x3f65b:$s5: IClientLoggingHost
- 0x4ead8:$s5: IClientLoggingHost
|
9.2.sys30.exe.3964057.31.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x36cb:$a: NanoCore
- 0x372c:$a: NanoCore
- 0x376f:$a: NanoCore
- 0x37af:$a: NanoCore
- 0x39eb:$a: NanoCore
- 0x3a8b:$a: NanoCore
- 0x4263:$a: NanoCore
- 0x4856:$a: NanoCore
- 0x49a7:$a: NanoCore
- 0x5801:$a: NanoCore
- 0x5a68:$a: NanoCore
- 0x5a7d:$a: NanoCore
- 0x5a9c:$a: NanoCore
- 0xe99f:$a: NanoCore
- 0xe9c8:$a: NanoCore
- 0x1a741:$a: NanoCore
- 0x1a76a:$a: NanoCore
- 0x3f62d:$a: NanoCore
- 0x3f645:$a: NanoCore
- 0x3f66e:$a: NanoCore
- 0x4ea71:$a: NanoCore
|
9.2.sys30.exe.2759b98.21.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x6da5:$x1: NanoCore.ClientPluginHost
- 0x6dd2:$x2: IClientNetworkHost
|
9.2.sys30.exe.2759b98.21.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x6da5:$x2: NanoCore.ClientPluginHost
- 0x7d74:$s2: FileCommand
- 0xc776:$s4: PipeCreated
- 0x6dbf:$s5: IClientLoggingHost
|
9.2.sys30.exe.397b2b6.32.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x170b:$x1: NanoCore.ClientPluginHost
- 0x1725:$x2: IClientNetworkHost
|
9.2.sys30.exe.397b2b6.32.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x170b:$x2: NanoCore.ClientPluginHost
- 0x34b6:$s4: PipeCreated
- 0x16f8:$s5: IClientLoggingHost
|
7.2.sys30.exe.38e56c8.10.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
7.2.sys30.exe.38e56c8.10.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
7.2.sys30.exe.38e56c8.10.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
7.2.sys30.exe.38e56c8.10.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
9.2.sys30.exe.bd0000.13.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x3d99:$x1: NanoCore.ClientPluginHost
- 0x3db3:$x2: IClientNetworkHost
|
9.2.sys30.exe.bd0000.13.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x3d99:$x2: NanoCore.ClientPluginHost
- 0x4dce:$s4: PipeCreated
- 0x3d86:$s5: IClientLoggingHost
|
9.2.sys30.exe.640000.6.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x8ba5:$x1: NanoCore.ClientPluginHost
- 0x8bd2:$x2: IClientNetworkHost
|
9.2.sys30.exe.640000.6.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x8ba5:$x2: NanoCore.ClientPluginHost
- 0x9b74:$s2: FileCommand
- 0xe576:$s4: PipeCreated
- 0x8bbf:$s5: IClientLoggingHost
|
7.2.sys30.exe.38bd6a8.9.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
7.2.sys30.exe.38bd6a8.9.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
7.2.sys30.exe.38bd6a8.9.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
7.2.sys30.exe.38bd6a8.9.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
7.2.sys30.exe.39356e8.11.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
7.2.sys30.exe.39356e8.11.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
|
7.2.sys30.exe.39356e8.11.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
7.2.sys30.exe.39356e8.11.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x1844e:$e: KeepAlive
- 0x1643c:$g: LogClientMessage
- 0x12637:$i: get_Connected
- 0x10db8:$j: #=q
- 0x10de8:$j: #=q
- 0x10e04:$j: #=q
- 0x10e34:$j: #=q
- 0x10e50:$j: #=q
- 0x10e6c:$j: #=q
- 0x10e9c:$j: #=q
- 0x10eb8:$j: #=q
|
7.2.sys30.exe.38bd6a8.9.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1018d:$x1: NanoCore.ClientPluginHost
- 0x381ad:$x1: NanoCore.ClientPluginHost
- 0x101ca:$x2: IClientNetworkHost
- 0x381ea:$x2: IClientNetworkHost
- 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x3bd1d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
7.2.sys30.exe.38bd6a8.9.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xff05:$x1: NanoCore Client.exe
- 0x37f25:$x1: NanoCore Client.exe
- 0x1018d:$x2: NanoCore.ClientPluginHost
- 0x381ad:$x2: NanoCore.ClientPluginHost
- 0x117c6:$s1: PluginCommand
- 0x397e6:$s1: PluginCommand
- 0x117ba:$s2: FileCommand
- 0x397da:$s2: FileCommand
- 0x1266b:$s3: PipeExists
- 0x3a68b:$s3: PipeExists
- 0x18422:$s4: PipeCreated
- 0x40442:$s4: PipeCreated
- 0x101b7:$s5: IClientLoggingHost
- 0x381d7:$s5: IClientLoggingHost
|
7.2.sys30.exe.38bd6a8.9.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
7.2.sys30.exe.38bd6a8.9.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfef5:$a: NanoCore
- 0xff05:$a: NanoCore
- 0x10139:$a: NanoCore
- 0x1014d:$a: NanoCore
- 0x1018d:$a: NanoCore
- 0x37f15:$a: NanoCore
- 0x37f25:$a: NanoCore
- 0x38159:$a: NanoCore
- 0x3816d:$a: NanoCore
- 0x381ad:$a: NanoCore
- 0xff54:$b: ClientPlugin
- 0x10156:$b: ClientPlugin
- 0x10196:$b: ClientPlugin
- 0x37f74:$b: ClientPlugin
- 0x38176:$b: ClientPlugin
- 0x381b6:$b: ClientPlugin
- 0x1007b:$c: ProjectData
- 0x3809b:$c: ProjectData
- 0x10a82:$d: DESCrypto
- 0x38aa2:$d: DESCrypto
- 0x1844e:$e: KeepAlive
|
9.2.sys30.exe.37385c8.23.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
9.2.sys30.exe.37385c8.23.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
9.2.sys30.exe.37385c8.23.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
7.2.sys30.exe.39356e8.11.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe38d:$x1: NanoCore.ClientPluginHost
- 0xe3ca:$x2: IClientNetworkHost
- 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
7.2.sys30.exe.39356e8.11.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe105:$x1: NanoCore Client.exe
- 0xe38d:$x2: NanoCore.ClientPluginHost
- 0xf9c6:$s1: PluginCommand
- 0xf9ba:$s2: FileCommand
- 0x1086b:$s3: PipeExists
- 0x16622:$s4: PipeCreated
- 0xe3b7:$s5: IClientLoggingHost
|
7.2.sys30.exe.39356e8.11.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
7.2.sys30.exe.39356e8.11.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0f5:$a: NanoCore
- 0xe105:$a: NanoCore
- 0xe339:$a: NanoCore
- 0xe34d:$a: NanoCore
- 0xe38d:$a: NanoCore
- 0xe154:$b: ClientPlugin
- 0xe356:$b: ClientPlugin
- 0xe396:$b: ClientPlugin
- 0xe27b:$c: ProjectData
- 0xec82:$d: DESCrypto
- 0x1664e:$e: KeepAlive
- 0x1463c:$g: LogClientMessage
- 0x10837:$i: get_Connected
- 0xefb8:$j: #=q
- 0xefe8:$j: #=q
- 0xf004:$j: #=q
- 0xf034:$j: #=q
- 0xf050:$j: #=q
- 0xf06c:$j: #=q
- 0xf09c:$j: #=q
- 0xf0b8:$j: #=q
|
9.2.sys30.exe.d80000.15.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x41ee:$x1: NanoCore.ClientPluginHost
- 0x422b:$x2: IClientNetworkHost
|
9.2.sys30.exe.d80000.15.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x41ee:$x2: NanoCore.ClientPluginHost
- 0x7641:$s4: PipeCreated
- 0x4218:$s5: IClientLoggingHost
|
9.2.sys30.exe.379169a.26.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x16e3:$x1: NanoCore.ClientPluginHost
- 0xb537:$x1: NanoCore.ClientPluginHost
- 0x1345f:$x1: NanoCore.ClientPluginHost
- 0x19432:$x1: NanoCore.ClientPluginHost
- 0x22ea0:$x1: NanoCore.ClientPluginHost
- 0x2d2cd:$x1: NanoCore.ClientPluginHost
- 0x382ac:$x1: NanoCore.ClientPluginHost
- 0x44050:$x1: NanoCore.ClientPluginHost
- 0x68f56:$x1: NanoCore.ClientPluginHost
- 0x78398:$x1: NanoCore.ClientPluginHost
- 0x9f9a1:$x1: NanoCore.ClientPluginHost
- 0x171c:$x2: IClientNetworkHost
- 0xb570:$x2: IClientNetworkHost
- 0x13498:$x2: IClientNetworkHost
- 0x22ffd:$x2: IClientNetworkHost
- 0x2d306:$x2: IClientNetworkHost
- 0x382c6:$x2: IClientNetworkHost
- 0x4406a:$x2: IClientNetworkHost
- 0x68f70:$x2: IClientNetworkHost
- 0x783d5:$x2: IClientNetworkHost
- 0x9f9bb:$x2: IClientNetworkHost
|
9.2.sys30.exe.379169a.26.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x142b:$a: NanoCore
- 0x1484:$a: NanoCore
- 0x14b7:$a: NanoCore
- 0x16e3:$a: NanoCore
- 0x175f:$a: NanoCore
- 0x1d78:$a: NanoCore
- 0x1ec1:$a: NanoCore
- 0x2395:$a: NanoCore
- 0x267c:$a: NanoCore
- 0x2693:$a: NanoCore
- 0xb537:$a: NanoCore
- 0xb5b3:$a: NanoCore
- 0xde96:$a: NanoCore
- 0x1345f:$a: NanoCore
- 0x134d9:$a: NanoCore
- 0x18076:$a: NanoCore
- 0x19432:$a: NanoCore
- 0x1947c:$a: NanoCore
- 0x1a0d6:$a: NanoCore
- 0x22ea0:$a: NanoCore
- 0x22f8a:$a: NanoCore
|
9.2.sys30.exe.389bc09.29.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xb184:$x1: NanoCore.ClientPluginHost
- 0x18dbe:$x1: NanoCore.ClientPluginHost
- 0x28fda:$x1: NanoCore.ClientPluginHost
- 0x36143:$x1: NanoCore.ClientPluginHost
- 0x3c691:$x1: NanoCore.ClientPluginHost
- 0x42662:$x1: NanoCore.ClientPluginHost
- 0x4c0ce:$x1: NanoCore.ClientPluginHost
- 0x564f9:$x1: NanoCore.ClientPluginHost
- 0x614d6:$x1: NanoCore.ClientPluginHost
- 0xb1b1:$x2: IClientNetworkHost
- 0x18de8:$x2: IClientNetworkHost
- 0x29007:$x2: IClientNetworkHost
- 0x3617c:$x2: IClientNetworkHost
- 0x3c6ca:$x2: IClientNetworkHost
- 0x4c22b:$x2: IClientNetworkHost
- 0x56532:$x2: IClientNetworkHost
- 0x614f0:$x2: IClientNetworkHost
|
9.2.sys30.exe.389bc09.29.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xb184:$x2: NanoCore.ClientPluginHost
- 0x18dbe:$x2: NanoCore.ClientPluginHost
- 0x28fda:$x2: NanoCore.ClientPluginHost
- 0x36143:$x2: NanoCore.ClientPluginHost
- 0x3c691:$x2: NanoCore.ClientPluginHost
- 0x42662:$x2: NanoCore.ClientPluginHost
- 0x4c0ce:$x2: NanoCore.ClientPluginHost
- 0x564f9:$x2: NanoCore.ClientPluginHost
- 0x614d6:$x2: NanoCore.ClientPluginHost
- 0x29fa9:$s2: FileCommand
- 0x4d024:$s3: PipeExists
- 0xc25f:$s4: PipeCreated
- 0x1ac6e:$s4: PipeCreated
- 0x2e9ab:$s4: PipeCreated
- 0x36260:$s4: PipeCreated
- 0x3c7ac:$s4: PipeCreated
- 0x42740:$s4: PipeCreated
- 0x4c2c4:$s4: PipeCreated
- 0x56644:$s4: PipeCreated
- 0x6250b:$s4: PipeCreated
- 0xb19e:$s5: IClientLoggingHost
|
9.2.sys30.exe.389bc09.29.raw.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
9.2.sys30.exe.389bc09.29.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xb13a:$a: NanoCore
- 0xb14f:$a: NanoCore
- 0xb184:$a: NanoCore
- 0x18d99:$a: NanoCore
- 0x18dbe:$a: NanoCore
- 0x18e17:$a: NanoCore
- 0x28fb4:$a: NanoCore
- 0x28fda:$a: NanoCore
- 0x29036:$a: NanoCore
- 0x35e8b:$a: NanoCore
- 0x35ee4:$a: NanoCore
- 0x35f17:$a: NanoCore
- 0x36143:$a: NanoCore
- 0x361bf:$a: NanoCore
- 0x367d8:$a: NanoCore
- 0x36921:$a: NanoCore
- 0x36df5:$a: NanoCore
- 0x370dc:$a: NanoCore
- 0x370f3:$a: NanoCore
- 0x3c691:$a: NanoCore
- 0x3c70b:$a: NanoCore
|
9.2.sys30.exe.3770e39.27.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x14dd9:$x1: NanoCore.ClientPluginHost
- 0x21f44:$x1: NanoCore.ClientPluginHost
- 0x2bd98:$x1: NanoCore.ClientPluginHost
- 0x33cc0:$x1: NanoCore.ClientPluginHost
- 0x39c93:$x1: NanoCore.ClientPluginHost
- 0x43701:$x1: NanoCore.ClientPluginHost
- 0x4db2e:$x1: NanoCore.ClientPluginHost
- 0x58b0d:$x1: NanoCore.ClientPluginHost
- 0x648b1:$x1: NanoCore.ClientPluginHost
- 0x897b7:$x1: NanoCore.ClientPluginHost
- 0x98bf9:$x1: NanoCore.ClientPluginHost
- 0xc0202:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
- 0x14e06:$x2: IClientNetworkHost
- 0x21f7d:$x2: IClientNetworkHost
- 0x2bdd1:$x2: IClientNetworkHost
- 0x33cf9:$x2: IClientNetworkHost
- 0x4385e:$x2: IClientNetworkHost
- 0x4db67:$x2: IClientNetworkHost
- 0x58b27:$x2: IClientNetworkHost
|
9.2.sys30.exe.3770e39.27.raw.unpack | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4b96:$a: NanoCore
- 0x4bbb:$a: NanoCore
- 0x4c14:$a: NanoCore
- 0x14db3:$a: NanoCore
- 0x14dd9:$a: NanoCore
- 0x14e35:$a: NanoCore
- 0x21c8c:$a: NanoCore
- 0x21ce5:$a: NanoCore
- 0x21d18:$a: NanoCore
- 0x21f44:$a: NanoCore
- 0x21fc0:$a: NanoCore
- 0x225d9:$a: NanoCore
- 0x22722:$a: NanoCore
- 0x22bf6:$a: NanoCore
- 0x22edd:$a: NanoCore
- 0x22ef4:$a: NanoCore
- 0x2bd98:$a: NanoCore
- 0x2be14:$a: NanoCore
- 0x2e6f7:$a: NanoCore
- 0x33cc0:$a: NanoCore
- 0x33d3a:$a: NanoCore
|
9.2.sys30.exe.3964057.31.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1deb:$x1: NanoCore.ClientPluginHost
- 0x1e24:$x2: IClientNetworkHost
|
9.2.sys30.exe.3964057.31.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1deb:$x2: NanoCore.ClientPluginHost
- 0x1f36:$s4: PipeCreated
- 0x1e05:$s5: IClientLoggingHost
|
9.2.sys30.exe.630000.5.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4bbb:$x1: NanoCore.ClientPluginHost
- 0x4be5:$x2: IClientNetworkHost
|
9.2.sys30.exe.630000.5.raw.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x4bbb:$x2: NanoCore.ClientPluginHost
- 0x6a6b:$s4: PipeCreated
|
9.2.sys30.exe.37385c8.23.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xd9ad:$x1: NanoCore.ClientPluginHost
- 0xd9da:$x2: IClientNetworkHost
|
9.2.sys30.exe.37385c8.23.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xd9ad:$x2: NanoCore.ClientPluginHost
- 0xea88:$s4: PipeCreated
- 0xd9c7:$s5: IClientLoggingHost
|
9.2.sys30.exe.37385c8.23.unpack | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
9.2.sys30.exe.bc0000.12.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1deb:$x1: NanoCore.ClientPluginHost
- 0x1e24:$x2: IClientNetworkHost
|
9.2.sys30.exe.bc0000.12.unpack | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1deb:$x2: NanoCore.ClientPluginHost
- 0x1f36:$s4: PipeCreated
- 0x1e05:$s5: IClientLoggingHost
|
9.2.sys30.exe.740000.8.raw.unpack | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b0b:$x1: NanoCore.ClientPluginHost
- 0x5b44:$x2: IClientNetworkHost
|
Click to see the 102 entries |