00000004.00000000.408831258.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000004.00000000.408831258.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000004.00000000.408831258.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000004.00000000.409213843.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000004.00000000.409213843.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000004.00000000.409213843.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000004.00000002.631819376.0000000005E30000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
00000004.00000002.631819376.0000000005E30000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
00000004.00000002.631819376.0000000005E30000.00000004.08000000.00040000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000004.00000002.631819376.0000000005E30000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0xf778:$x2: NanoCore.ClientPlugin
- 0xf7ad:$x3: NanoCore.ClientPluginHost
- 0xf76c:$i2: IClientData
- 0xf78e:$i3: IClientNetwork
- 0xf79d:$i5: IClientDataHost
- 0xf7c7:$i6: IClientLoggingHost
- 0xf7da:$i7: IClientNetworkHost
- 0xf7ed:$i8: IClientUIHost
- 0xf7fb:$i9: IClientNameObjectCollection
- 0xf817:$i10: IClientReadOnlyNameObjectCollection
- 0xf56a:$s1: ClientPlugin
- 0xf781:$s1: ClientPlugin
- 0x147a2:$s6: get_ClientSettings
|
00000000.00000002.415299432.0000000002EE8000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
00000004.00000000.408232276.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000004.00000000.408232276.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000004.00000000.408232276.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000004.00000002.629684099.0000000003C51000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000000.00000002.414167821.0000000002D81000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
00000000.00000002.416862550.0000000003F52000.00000004.00000800.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x4f26d:$x1: NanoCore.ClientPluginHost
- 0x81c8d:$x1: NanoCore.ClientPluginHost
- 0xb44ad:$x1: NanoCore.ClientPluginHost
- 0x4f2aa:$x2: IClientNetworkHost
- 0x81cca:$x2: IClientNetworkHost
- 0xb44ea:$x2: IClientNetworkHost
- 0x52ddd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x857fd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0xb801d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000000.00000002.416862550.0000000003F52000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000000.00000002.416862550.0000000003F52000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x4efd5:$a: NanoCore
- 0x4efe5:$a: NanoCore
- 0x4f219:$a: NanoCore
- 0x4f22d:$a: NanoCore
- 0x4f26d:$a: NanoCore
- 0x819f5:$a: NanoCore
- 0x81a05:$a: NanoCore
- 0x81c39:$a: NanoCore
- 0x81c4d:$a: NanoCore
- 0x81c8d:$a: NanoCore
- 0xb4215:$a: NanoCore
- 0xb4225:$a: NanoCore
- 0xb4459:$a: NanoCore
- 0xb446d:$a: NanoCore
- 0xb44ad:$a: NanoCore
- 0x4f034:$b: ClientPlugin
- 0x4f236:$b: ClientPlugin
- 0x4f276:$b: ClientPlugin
- 0x81a54:$b: ClientPlugin
- 0x81c56:$b: ClientPlugin
- 0x81c96:$b: ClientPlugin
|
00000004.00000002.626920584.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000004.00000002.626920584.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000004.00000002.626920584.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000004.00000002.628123506.0000000002BF1000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000004.00000002.631747506.0000000005D90000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
00000004.00000002.631747506.0000000005D90000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
00000004.00000002.631747506.0000000005D90000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0xe38:$x2: NanoCore.ClientPlugin
- 0xe75:$x3: NanoCore.ClientPluginHost
- 0xe5a:$i1: IClientApp
- 0xe4e:$i2: IClientData
- 0xe29:$i3: IClientNetwork
- 0xec3:$i4: IClientAppHost
- 0xe65:$i5: IClientDataHost
- 0xeb0:$i6: IClientLoggingHost
- 0xe8f:$i7: IClientNetworkHost
- 0xea2:$i8: IClientUIHost
- 0xed2:$i9: IClientNameObjectCollection
- 0xef7:$i10: IClientReadOnlyNameObjectCollection
- 0xe41:$s1: ClientPlugin
- 0x177c:$s1: ClientPlugin
- 0x1789:$s1: ClientPlugin
- 0x11f9:$s6: get_ClientSettings
- 0x1249:$s7: get_Connected
|
00000004.00000000.409721909.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000004.00000000.409721909.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000004.00000000.409721909.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
Process Memory Space: SecuriteInfo.com.Trojan.PackedNET.331.28355.exe PID: 5012 | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x77335:$x1: NanoCore.ClientPluginHost
- 0x77372:$x2: IClientNetworkHost
- 0x7ae5a:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x85ed8:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x91e90:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x9d278:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
Process Memory Space: SecuriteInfo.com.Trojan.PackedNET.331.28355.exe PID: 5012 | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
Process Memory Space: SecuriteInfo.com.Trojan.PackedNET.331.28355.exe PID: 5012 | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: SecuriteInfo.com.Trojan.PackedNET.331.28355.exe PID: 5012 | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x77002:$a: NanoCore
- 0x77012:$a: NanoCore
- 0x770d1:$a: NanoCore
- 0x770e0:$a: NanoCore
- 0x772e1:$a: NanoCore
- 0x772f5:$a: NanoCore
- 0x77335:$a: NanoCore
- 0x82542:$a: NanoCore
- 0x82554:$a: NanoCore
- 0x82590:$a: NanoCore
- 0x8e4fa:$a: NanoCore
- 0x8e50c:$a: NanoCore
- 0x8e548:$a: NanoCore
- 0x998e2:$a: NanoCore
- 0x998f4:$a: NanoCore
- 0x99930:$a: NanoCore
- 0x77061:$b: ClientPlugin
- 0x7712a:$b: ClientPlugin
- 0x772fe:$b: ClientPlugin
- 0x7733e:$b: ClientPlugin
- 0x8255d:$b: ClientPlugin
|
Process Memory Space: RegSvcs.exe PID: 4736 | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x79b3:$x1: NanoCore.ClientPluginHost
- 0x314e5:$x1: NanoCore.ClientPluginHost
- 0x66375:$x1: NanoCore.ClientPluginHost
- 0x78138:$x1: NanoCore.ClientPluginHost
- 0xa5810:$x1: NanoCore.ClientPluginHost
- 0x79f0:$x2: IClientNetworkHost
- 0x31512:$x2: IClientNetworkHost
- 0x663a2:$x2: IClientNetworkHost
- 0x78152:$x2: IClientNetworkHost
- 0xa582a:$x2: IClientNetworkHost
- 0xb4e1:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
- 0x16567:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
Process Memory Space: RegSvcs.exe PID: 4736 | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: RegSvcs.exe PID: 4736 | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x7680:$a: NanoCore
- 0x7690:$a: NanoCore
- 0x774f:$a: NanoCore
- 0x775e:$a: NanoCore
- 0x795f:$a: NanoCore
- 0x7973:$a: NanoCore
- 0x79b3:$a: NanoCore
- 0x12bd1:$a: NanoCore
- 0x12be3:$a: NanoCore
- 0x12c1f:$a: NanoCore
- 0x3149b:$a: NanoCore
- 0x314b0:$a: NanoCore
- 0x314e5:$a: NanoCore
- 0x36667:$a: NanoCore
- 0x3667a:$a: NanoCore
- 0x366ac:$a: NanoCore
- 0x6632b:$a: NanoCore
- 0x66340:$a: NanoCore
- 0x66375:$a: NanoCore
- 0x67e4f:$a: NanoCore
- 0x67e62:$a: NanoCore
|
Click to see the 31 entries |