00000000.00000002.448596274.0000000003291000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
0000000D.00000000.444387239.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0000000D.00000000.444387239.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000D.00000000.444387239.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000000.00000002.449384414.0000000003534000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
0000000D.00000000.437739210.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0000000D.00000000.437739210.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000D.00000000.437739210.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
0000000D.00000000.431483918.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0000000D.00000000.431483918.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000D.00000000.431483918.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
0000000D.00000000.433933861.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0000000D.00000000.433933861.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000D.00000000.433933861.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
0000000D.00000002.630998796.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
0000000D.00000002.630998796.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000D.00000002.630998796.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
0000000D.00000002.634263840.0000000004059000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000D.00000002.634263840.0000000004059000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x2ec5:$a: NanoCore
- 0x2f1e:$a: NanoCore
- 0x2f5b:$a: NanoCore
- 0x2fd4:$a: NanoCore
- 0x1667f:$a: NanoCore
- 0x16694:$a: NanoCore
- 0x166c9:$a: NanoCore
- 0x2f123:$a: NanoCore
- 0x2f138:$a: NanoCore
- 0x2f16d:$a: NanoCore
- 0x2f27:$b: ClientPlugin
- 0x2f64:$b: ClientPlugin
- 0x3862:$b: ClientPlugin
- 0x386f:$b: ClientPlugin
- 0x1643b:$b: ClientPlugin
- 0x16456:$b: ClientPlugin
- 0x16486:$b: ClientPlugin
- 0x1669d:$b: ClientPlugin
- 0x166d2:$b: ClientPlugin
- 0x2eedf:$b: ClientPlugin
- 0x2eefa:$b: ClientPlugin
|
0000000D.00000002.635612339.0000000006280000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
0000000D.00000002.635612339.0000000006280000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
0000000D.00000002.635612339.0000000006280000.00000004.08000000.00040000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000D.00000002.635612339.0000000006280000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0xf778:$x2: NanoCore.ClientPlugin
- 0xf7ad:$x3: NanoCore.ClientPluginHost
- 0xf76c:$i2: IClientData
- 0xf78e:$i3: IClientNetwork
- 0xf79d:$i5: IClientDataHost
- 0xf7c7:$i6: IClientLoggingHost
- 0xf7da:$i7: IClientNetworkHost
- 0xf7ed:$i8: IClientUIHost
- 0xf7fb:$i9: IClientNameObjectCollection
- 0xf817:$i10: IClientReadOnlyNameObjectCollection
- 0xf56a:$s1: ClientPlugin
- 0xf781:$s1: ClientPlugin
- 0x147a2:$s6: get_ClientSettings
|
0000000D.00000002.635329054.0000000005950000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
0000000D.00000002.635329054.0000000005950000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
0000000D.00000002.635329054.0000000005950000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0xe38:$x2: NanoCore.ClientPlugin
- 0xe75:$x3: NanoCore.ClientPluginHost
- 0xe5a:$i1: IClientApp
- 0xe4e:$i2: IClientData
- 0xe29:$i3: IClientNetwork
- 0xec3:$i4: IClientAppHost
- 0xe65:$i5: IClientDataHost
- 0xeb0:$i6: IClientLoggingHost
- 0xe8f:$i7: IClientNetworkHost
- 0xea2:$i8: IClientUIHost
- 0xed2:$i9: IClientNameObjectCollection
- 0xef7:$i10: IClientReadOnlyNameObjectCollection
- 0xe41:$s1: ClientPlugin
- 0x177c:$s1: ClientPlugin
- 0x1789:$s1: ClientPlugin
- 0x11f9:$s6: get_ClientSettings
- 0x1249:$s7: get_Connected
|
00000000.00000002.450332002.0000000004461000.00000004.00000800.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4eabd:$x1: NanoCore.ClientPluginHost
- 0x814dd:$x1: NanoCore.ClientPluginHost
- 0xb3cfd:$x1: NanoCore.ClientPluginHost
- 0x4eafa:$x2: IClientNetworkHost
- 0x8151a:$x2: IClientNetworkHost
- 0xb3d3a:$x2: IClientNetworkHost
- 0x5262d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x8504d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0xb786d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000000.00000002.450332002.0000000004461000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000000.00000002.450332002.0000000004461000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4e825:$a: NanoCore
- 0x4e835:$a: NanoCore
- 0x4ea69:$a: NanoCore
- 0x4ea7d:$a: NanoCore
- 0x4eabd:$a: NanoCore
- 0x81245:$a: NanoCore
- 0x81255:$a: NanoCore
- 0x81489:$a: NanoCore
- 0x8149d:$a: NanoCore
- 0x814dd:$a: NanoCore
- 0xb3a65:$a: NanoCore
- 0xb3a75:$a: NanoCore
- 0xb3ca9:$a: NanoCore
- 0xb3cbd:$a: NanoCore
- 0xb3cfd:$a: NanoCore
- 0x4e884:$b: ClientPlugin
- 0x4ea86:$b: ClientPlugin
- 0x4eac6:$b: ClientPlugin
- 0x812a4:$b: ClientPlugin
- 0x814a6:$b: ClientPlugin
- 0x814e6:$b: ClientPlugin
|
Process Memory Space: qs5yhVj1bE.exe PID: 6204 | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x18dbfd:$x1: NanoCore.ClientPluginHost
- 0x18dc3a:$x2: IClientNetworkHost
- 0x191722:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x19c7a0:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x1a886d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x1b3c6a:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
Process Memory Space: qs5yhVj1bE.exe PID: 6204 | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
Process Memory Space: qs5yhVj1bE.exe PID: 6204 | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: qs5yhVj1bE.exe PID: 6204 | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x18d8ca:$a: NanoCore
- 0x18d8da:$a: NanoCore
- 0x18d999:$a: NanoCore
- 0x18d9a8:$a: NanoCore
- 0x18dba9:$a: NanoCore
- 0x18dbbd:$a: NanoCore
- 0x18dbfd:$a: NanoCore
- 0x198e0a:$a: NanoCore
- 0x198e1c:$a: NanoCore
- 0x198e58:$a: NanoCore
- 0x1a4ed7:$a: NanoCore
- 0x1a4ee9:$a: NanoCore
- 0x1a4f25:$a: NanoCore
- 0x1b02d4:$a: NanoCore
- 0x1b02e6:$a: NanoCore
- 0x1b0322:$a: NanoCore
- 0x18d929:$b: ClientPlugin
- 0x18d9f2:$b: ClientPlugin
- 0x18dbc6:$b: ClientPlugin
- 0x18dc06:$b: ClientPlugin
- 0x198e25:$b: ClientPlugin
|
Process Memory Space: qs5yhVj1bE.exe PID: 6464 | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x10572:$x1: NanoCore.ClientPluginHost
- 0xa233f:$x1: NanoCore.ClientPluginHost
- 0xaf5aa:$x1: NanoCore.ClientPluginHost
- 0xb9a8d:$x1: NanoCore.ClientPluginHost
- 0x105af:$x2: IClientNetworkHost
- 0xa2359:$x2: IClientNetworkHost
- 0xaf5d7:$x2: IClientNetworkHost
- 0xb9aa7:$x2: IClientNetworkHost
- 0x140a0:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x1f126:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
Process Memory Space: qs5yhVj1bE.exe PID: 6464 | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: qs5yhVj1bE.exe PID: 6464 | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x1023f:$a: NanoCore
- 0x1024f:$a: NanoCore
- 0x1030e:$a: NanoCore
- 0x1031d:$a: NanoCore
- 0x1051e:$a: NanoCore
- 0x10532:$a: NanoCore
- 0x10572:$a: NanoCore
- 0x1b790:$a: NanoCore
- 0x1b7a2:$a: NanoCore
- 0x1b7de:$a: NanoCore
- 0x8f956:$a: NanoCore
- 0x8f9b1:$a: NanoCore
- 0x8fa25:$a: NanoCore
- 0xa22a9:$a: NanoCore
- 0xa2302:$a: NanoCore
- 0xa233f:$a: NanoCore
- 0xa23b8:$a: NanoCore
- 0xa2c5b:$a: NanoCore
- 0xa2cae:$a: NanoCore
- 0xa2ce7:$a: NanoCore
- 0xa2d5a:$a: NanoCore
|
Click to see the 31 entries |