00000008.00000002.519250618.0000000003D81000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000008.00000002.515876792.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000008.00000002.515876792.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000008.00000002.515876792.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000000.00000002.293486073.0000000002DEB000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
00000008.00000000.288319319.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000008.00000000.288319319.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000008.00000000.288319319.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000008.00000000.289425663.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000008.00000000.289425663.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000008.00000000.289425663.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000000.00000002.292920833.0000000002C31000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
00000008.00000002.520324734.0000000005540000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
00000008.00000002.520324734.0000000005540000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
00000008.00000002.520324734.0000000005540000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0xe38:$x2: NanoCore.ClientPlugin
- 0xe75:$x3: NanoCore.ClientPluginHost
- 0xe5a:$i1: IClientApp
- 0xe4e:$i2: IClientData
- 0xe29:$i3: IClientNetwork
- 0xec3:$i4: IClientAppHost
- 0xe65:$i5: IClientDataHost
- 0xeb0:$i6: IClientLoggingHost
- 0xe8f:$i7: IClientNetworkHost
- 0xea2:$i8: IClientUIHost
- 0xed2:$i9: IClientNameObjectCollection
- 0xef7:$i10: IClientReadOnlyNameObjectCollection
- 0xe41:$s1: ClientPlugin
- 0x177c:$s1: ClientPlugin
- 0x1789:$s1: ClientPlugin
- 0x11f9:$s6: get_ClientSettings
- 0x1249:$s7: get_Connected
|
00000008.00000000.286410609.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000008.00000000.286410609.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000008.00000000.286410609.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000008.00000000.288866971.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000008.00000000.288866971.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000008.00000000.288866971.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000008.00000002.520506917.00000000057F0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
00000008.00000002.520506917.00000000057F0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
00000008.00000002.520506917.00000000057F0000.00000004.08000000.00040000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000008.00000002.520506917.00000000057F0000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0xf778:$x2: NanoCore.ClientPlugin
- 0xf7ad:$x3: NanoCore.ClientPluginHost
- 0xf76c:$i2: IClientData
- 0xf78e:$i3: IClientNetwork
- 0xf79d:$i5: IClientDataHost
- 0xf7c7:$i6: IClientLoggingHost
- 0xf7da:$i7: IClientNetworkHost
- 0xf7ed:$i8: IClientUIHost
- 0xf7fb:$i9: IClientNameObjectCollection
- 0xf817:$i10: IClientReadOnlyNameObjectCollection
- 0xf56a:$s1: ClientPlugin
- 0xf781:$s1: ClientPlugin
- 0x147a2:$s6: get_ClientSettings
|
00000000.00000002.294855459.0000000003DDF000.00000004.00000800.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4e72d:$x1: NanoCore.ClientPluginHost
- 0x8114d:$x1: NanoCore.ClientPluginHost
- 0xb396d:$x1: NanoCore.ClientPluginHost
- 0x4e76a:$x2: IClientNetworkHost
- 0x8118a:$x2: IClientNetworkHost
- 0xb39aa:$x2: IClientNetworkHost
- 0x5229d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x84cbd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0xb74dd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000000.00000002.294855459.0000000003DDF000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000000.00000002.294855459.0000000003DDF000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4e495:$a: NanoCore
- 0x4e4a5:$a: NanoCore
- 0x4e6d9:$a: NanoCore
- 0x4e6ed:$a: NanoCore
- 0x4e72d:$a: NanoCore
- 0x80eb5:$a: NanoCore
- 0x80ec5:$a: NanoCore
- 0x810f9:$a: NanoCore
- 0x8110d:$a: NanoCore
- 0x8114d:$a: NanoCore
- 0xb36d5:$a: NanoCore
- 0xb36e5:$a: NanoCore
- 0xb3919:$a: NanoCore
- 0xb392d:$a: NanoCore
- 0xb396d:$a: NanoCore
- 0x4e4f4:$b: ClientPlugin
- 0x4e6f6:$b: ClientPlugin
- 0x4e736:$b: ClientPlugin
- 0x80f14:$b: ClientPlugin
- 0x81116:$b: ClientPlugin
- 0x81156:$b: ClientPlugin
|
00000008.00000002.518021079.0000000002D21000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: e1f388b8a086e034b1fbd94ca7341008.exe PID: 6952 | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x76417:$x1: NanoCore.ClientPluginHost
- 0x76454:$x2: IClientNetworkHost
- 0x79f3c:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x84fba:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x90ffb:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x9c345:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
Process Memory Space: e1f388b8a086e034b1fbd94ca7341008.exe PID: 6952 | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
Process Memory Space: e1f388b8a086e034b1fbd94ca7341008.exe PID: 6952 | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: e1f388b8a086e034b1fbd94ca7341008.exe PID: 6952 | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x760e4:$a: NanoCore
- 0x760f4:$a: NanoCore
- 0x761b3:$a: NanoCore
- 0x761c2:$a: NanoCore
- 0x763c3:$a: NanoCore
- 0x763d7:$a: NanoCore
- 0x76417:$a: NanoCore
- 0x81624:$a: NanoCore
- 0x81636:$a: NanoCore
- 0x81672:$a: NanoCore
- 0x8d665:$a: NanoCore
- 0x8d677:$a: NanoCore
- 0x8d6b3:$a: NanoCore
- 0x989af:$a: NanoCore
- 0x989c1:$a: NanoCore
- 0x989fd:$a: NanoCore
- 0x76143:$b: ClientPlugin
- 0x7620c:$b: ClientPlugin
- 0x763e0:$b: ClientPlugin
- 0x76420:$b: ClientPlugin
- 0x8163f:$b: ClientPlugin
|
Process Memory Space: e1f388b8a086e034b1fbd94ca7341008.exe PID: 3312 | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1121d:$x1: NanoCore.ClientPluginHost
- 0x38ca7:$x1: NanoCore.ClientPluginHost
- 0xa0681:$x1: NanoCore.ClientPluginHost
- 0x1124a:$x2: IClientNetworkHost
- 0x38ce4:$x2: IClientNetworkHost
- 0xa069b:$x2: IClientNetworkHost
- 0x3c7d5:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x4785b:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
Process Memory Space: e1f388b8a086e034b1fbd94ca7341008.exe PID: 3312 | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: e1f388b8a086e034b1fbd94ca7341008.exe PID: 3312 | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x111d3:$a: NanoCore
- 0x111e8:$a: NanoCore
- 0x1121d:$a: NanoCore
- 0x12d27:$a: NanoCore
- 0x12d3a:$a: NanoCore
- 0x12d6c:$a: NanoCore
- 0x38974:$a: NanoCore
- 0x38984:$a: NanoCore
- 0x38a43:$a: NanoCore
- 0x38a52:$a: NanoCore
- 0x38c53:$a: NanoCore
- 0x38c67:$a: NanoCore
- 0x38ca7:$a: NanoCore
- 0x43ec5:$a: NanoCore
- 0x43ed7:$a: NanoCore
- 0x43f13:$a: NanoCore
- 0x67dbb:$a: NanoCore
- 0x96047:$a: NanoCore
- 0x960a2:$a: NanoCore
- 0x96115:$a: NanoCore
- 0xa05eb:$a: NanoCore
|
Click to see the 31 entries |