00000005.00000002.641608734.0000000006B90000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x2205:$x1: NanoCore.ClientPluginHost
- 0x223e:$x2: IClientNetworkHost
|
00000005.00000002.641608734.0000000006B90000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x2205:$x2: NanoCore.ClientPluginHost
- 0x2320:$s4: PipeCreated
- 0x221f:$s5: IClientLoggingHost
|
00000005.00000002.641608734.0000000006B90000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0x227f:$x2: NanoCore.ClientPlugin
- 0x2205:$x3: NanoCore.ClientPluginHost
- 0x2295:$i3: IClientNetwork
- 0x221f:$i6: IClientLoggingHost
- 0x223e:$i7: IClientNetworkHost
- 0x1f9f:$s1: ClientPlugin
- 0x2288:$s1: ClientPlugin
|
00000005.00000000.411957545.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000005.00000000.411957545.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000005.00000000.411957545.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000005.00000002.641634528.0000000006BB0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x59eb:$x1: NanoCore.ClientPluginHost
- 0x5b48:$x2: IClientNetworkHost
|
00000005.00000002.641634528.0000000006BB0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x59eb:$x2: NanoCore.ClientPluginHost
- 0x6941:$s3: PipeExists
- 0x5be1:$s4: PipeCreated
- 0x5a05:$s5: IClientLoggingHost
|
00000005.00000002.641634528.0000000006BB0000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0x5ad5:$x2: NanoCore.ClientPlugin
- 0x59eb:$x3: NanoCore.ClientPluginHost
- 0x5aeb:$i3: IClientNetwork
- 0x5a24:$i5: IClientDataHost
- 0x5a05:$i6: IClientLoggingHost
- 0x5b48:$i7: IClientNetworkHost
- 0x5a43:$i8: IClientUIHost
- 0x6955:$i9: IClientNameObjectCollection
- 0x54fc:$s1: ClientPlugin
- 0x5ade:$s1: ClientPlugin
- 0x6971:$s6: get_ClientSettings
|
00000005.00000002.640118033.0000000003DC1000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x55def:$a: NanoCore
- 0x55ed9:$a: NanoCore
- 0x56d50:$a: NanoCore
- 0x5fefa:$a: NanoCore
- 0x5ff5b:$a: NanoCore
- 0x5ff9e:$a: NanoCore
- 0x5ffde:$a: NanoCore
- 0x6021a:$a: NanoCore
- 0x602ba:$a: NanoCore
- 0x60a92:$a: NanoCore
- 0x61085:$a: NanoCore
- 0x611d6:$a: NanoCore
- 0x62030:$a: NanoCore
- 0x62297:$a: NanoCore
- 0x622ac:$a: NanoCore
- 0x622cb:$a: NanoCore
- 0x6b1ce:$a: NanoCore
- 0x6b1f7:$a: NanoCore
- 0x76f70:$a: NanoCore
- 0x76f99:$a: NanoCore
- 0x9be5c:$a: NanoCore
|
00000005.00000002.641805213.0000000006EA0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x1f1db:$x1: NanoCore.ClientPluginHost
- 0x1f1f5:$x2: IClientNetworkHost
|
00000005.00000002.641805213.0000000006EA0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x1f1db:$x2: NanoCore.ClientPluginHost
- 0x22518:$s4: PipeCreated
- 0x1f1c8:$s5: IClientLoggingHost
|
00000005.00000002.641805213.0000000006EA0000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0x1f1b2:$x2: NanoCore.ClientPlugin
- 0x1f1db:$x3: NanoCore.ClientPluginHost
- 0x1f1a3:$i3: IClientNetwork
- 0x1f1c8:$i6: IClientLoggingHost
- 0x1f1f5:$i7: IClientNetworkHost
- 0x1f208:$i8: IClientUIHost
- 0x1ef12:$s1: ClientPlugin
- 0x1f1bb:$s1: ClientPlugin
|
00000005.00000002.641707073.0000000006D20000.00000004.00000001.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5b99:$x1: NanoCore.ClientPluginHost
- 0x5bb3:$x2: IClientNetworkHost
|
00000005.00000002.641707073.0000000006D20000.00000004.00000001.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5b99:$x2: NanoCore.ClientPluginHost
- 0x6bce:$s4: PipeCreated
- 0x5b86:$s5: IClientLoggingHost
|
00000005.00000002.641707073.0000000006D20000.00000004.00000001.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0x5b70:$x2: NanoCore.ClientPlugin
- 0x5b99:$x3: NanoCore.ClientPluginHost
- 0x5b61:$i3: IClientNetwork
- 0x5b86:$i6: IClientLoggingHost
- 0x5bb3:$i7: IClientNetworkHost
- 0x59d4:$s1: ClientPlugin
- 0x5b79:$s1: ClientPlugin
- 0x5e84:$s2: EndPoint
- 0x5e8d:$s3: IPAddress
- 0x5e97:$s4: IPEndPoint
|
00000005.00000002.638035787.0000000003B21000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000005.00000002.641622424.0000000006BA0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x13a8:$x1: NanoCore.ClientPluginHost
|
00000005.00000002.641622424.0000000006BA0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x13a8:$x2: NanoCore.ClientPluginHost
- 0x1486:$s4: PipeCreated
- 0x13c2:$s5: IClientLoggingHost
|
00000005.00000002.641622424.0000000006BA0000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0x13f2:$x2: NanoCore.ClientPlugin
- 0x13a8:$x3: NanoCore.ClientPluginHost
- 0x1408:$i3: IClientNetwork
- 0x13c2:$i6: IClientLoggingHost
- 0x1185:$s1: ClientPlugin
- 0x13fb:$s1: ClientPlugin
|
00000005.00000000.411127213.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000005.00000000.411127213.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000005.00000000.411127213.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000005.00000002.630920607.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xff8d:$x1: NanoCore.ClientPluginHost
- 0xffca:$x2: IClientNetworkHost
- 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
|
00000005.00000002.630920607.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000005.00000002.630920607.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xfcf5:$a: NanoCore
- 0xfd05:$a: NanoCore
- 0xff39:$a: NanoCore
- 0xff4d:$a: NanoCore
- 0xff8d:$a: NanoCore
- 0xfd54:$b: ClientPlugin
- 0xff56:$b: ClientPlugin
- 0xff96:$b: ClientPlugin
- 0xfe7b:$c: ProjectData
- 0x10882:$d: DESCrypto
- 0x1824e:$e: KeepAlive
- 0x1623c:$g: LogClientMessage
- 0x12437:$i: get_Connected
- 0x10bb8:$j: #=q
- 0x10be8:$j: #=q
- 0x10c04:$j: #=q
- 0x10c34:$j: #=q
- 0x10c50:$j: #=q
- 0x10c6c:$j: #=q
- 0x10c9c:$j: #=q
- 0x10cb8:$j: #=q
|
00000005.00000002.641872775.0000000006EE0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0x5fee:$x1: NanoCore.ClientPluginHost
- 0x602b:$x2: IClientNetworkHost
|
00000005.00000002.641872775.0000000006EE0000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0x5fee:$x2: NanoCore.ClientPluginHost
- 0x9441:$s4: PipeCreated
- 0x6018:$s5: IClientLoggingHost
|
00000005.00000002.641872775.0000000006EE0000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0x5fc9:$x2: NanoCore.ClientPlugin
- 0x5fee:$x3: NanoCore.ClientPluginHost
- 0x5fba:$i3: IClientNetwork
- 0x5fdf:$i4: IClientAppHost
- 0x6008:$i5: IClientDataHost
- 0x6018:$i6: IClientLoggingHost
- 0x602b:$i7: IClientNetworkHost
- 0x603e:$i8: IClientUIHost
|