0000000F.00000002.527779375.00000000033BB000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000000.00000002.466623981.000000000427E000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000000.00000002.466623981.000000000427E000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x2aa65:$a: NanoCore
- 0x2ac25:$a: NanoCore
- 0x2d674:$a: NanoCore
- 0x2d69a:$a: NanoCore
- 0x2d9cb:$a: NanoCore
- 0x350aa:$a: NanoCore
- 0x2d67d:$b: ClientPlugin
- 0x2d6a3:$b: ClientPlugin
- 0x2d9d4:$b: ClientPlugin
- 0x3456b:$c: ProjectData
- 0x2fd3a:$d: DESCrypto
- 0x304b5:$e: KeepAlive
- 0x2f5e7:$g: LogClientMessage
- 0x2dc43:$i: get_Connected
- 0x2acf4:$j: #=q
- 0x2ad38:$j: #=q
- 0x2ad54:$j: #=q
- 0x2ad96:$j: #=q
- 0x2adb2:$j: #=q
- 0x2adce:$j: #=q
- 0x2ae26:$j: #=q
|
00000000.00000002.466623981.000000000427E000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0x2d69a:$a1: NanoCore.ClientPluginHost
- 0x2d9cb:$a2: NanoCore.ClientPlugin
- 0x2d6c7:$b1: get_BuilderSettings
- 0x35047:$b2: ClientLoaderForm.resources
- 0x2b5d5:$b3: PluginCommand
- 0x2ddba:$b4: IClientAppHost
- 0x319bc:$b5: GetBlockHash
- 0x2dccf:$b6: AddHostEntry
- 0x2f5d4:$b7: LogClientException
- 0x2dc90:$b8: PipeExists
- 0x2dda7:$b9: IClientLoggingHost
|
0000000F.00000002.527200680.0000000003371000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000000.00000002.453841918.0000000003031000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000000.00000003.255565605.0000000004056000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
0000000F.00000002.527732524.00000000033B2000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
0000000E.00000000.450018784.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000E.00000000.450018784.0000000000402000.00000040.00000400.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x2a46d:$a: NanoCore
- 0x2a62d:$a: NanoCore
- 0x2d07c:$a: NanoCore
- 0x2d0a2:$a: NanoCore
- 0x2d3d3:$a: NanoCore
- 0x34ab2:$a: NanoCore
- 0x2d085:$b: ClientPlugin
- 0x2d0ab:$b: ClientPlugin
- 0x2d3dc:$b: ClientPlugin
- 0x33f73:$c: ProjectData
- 0x2f742:$d: DESCrypto
- 0x2febd:$e: KeepAlive
- 0x2efef:$g: LogClientMessage
- 0x2d64b:$i: get_Connected
- 0x2a6fc:$j: #=q
- 0x2a740:$j: #=q
- 0x2a75c:$j: #=q
- 0x2a79e:$j: #=q
- 0x2a7ba:$j: #=q
- 0x2a7d6:$j: #=q
- 0x2a82e:$j: #=q
|
0000000E.00000000.450018784.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0x2d0a2:$a1: NanoCore.ClientPluginHost
- 0x2d3d3:$a2: NanoCore.ClientPlugin
- 0x2d0cf:$b1: get_BuilderSettings
- 0x34a4f:$b2: ClientLoaderForm.resources
- 0x2afdd:$b3: PluginCommand
- 0x2d7c2:$b4: IClientAppHost
- 0x313c4:$b5: GetBlockHash
- 0x2d6d7:$b6: AddHostEntry
- 0x2efdc:$b7: LogClientException
- 0x2d698:$b8: PipeExists
- 0x2d7af:$b9: IClientLoggingHost
|
00000000.00000002.467477543.0000000005570000.00000004.08000000.00040000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000000.00000002.464712592.00000000040FB000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000000.00000002.464712592.00000000040FB000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x86b15:$a: NanoCore
- 0x86cd5:$a: NanoCore
- 0x89724:$a: NanoCore
- 0x8974a:$a: NanoCore
- 0x89a7b:$a: NanoCore
- 0x9115a:$a: NanoCore
- 0x8972d:$b: ClientPlugin
- 0x89753:$b: ClientPlugin
- 0x89a84:$b: ClientPlugin
- 0x9061b:$c: ProjectData
- 0x8bdea:$d: DESCrypto
- 0x8c565:$e: KeepAlive
- 0x8b697:$g: LogClientMessage
- 0x89cf3:$i: get_Connected
- 0x86da4:$j: #=q
- 0x86de8:$j: #=q
- 0x86e04:$j: #=q
- 0x86e46:$j: #=q
- 0x86e62:$j: #=q
- 0x86e7e:$j: #=q
- 0x86ed6:$j: #=q
|
00000000.00000002.464712592.00000000040FB000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0x8974a:$a1: NanoCore.ClientPluginHost
- 0x89a7b:$a2: NanoCore.ClientPlugin
- 0x89777:$b1: get_BuilderSettings
- 0x910f7:$b2: ClientLoaderForm.resources
- 0x87685:$b3: PluginCommand
- 0x89e6a:$b4: IClientAppHost
- 0x8da6c:$b5: GetBlockHash
- 0x89d7f:$b6: AddHostEntry
- 0x8b684:$b7: LogClientException
- 0x89d40:$b8: PipeExists
- 0x89e57:$b9: IClientLoggingHost
|
0000000E.00000002.538529652.0000000005E00000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xf7ad:$x1: NanoCore.ClientPluginHost
- 0xf7da:$x2: IClientNetworkHost
|
0000000E.00000002.538529652.0000000005E00000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xf7ad:$x2: NanoCore.ClientPluginHost
- 0x10888:$s4: PipeCreated
- 0xf7c7:$s5: IClientLoggingHost
|
0000000E.00000002.538529652.0000000005E00000.00000004.08000000.00040000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000E.00000002.538529652.0000000005E00000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0xf778:$x2: NanoCore.ClientPlugin
- 0xf7ad:$x3: NanoCore.ClientPluginHost
- 0xf76c:$i2: IClientData
- 0xf78e:$i3: IClientNetwork
- 0xf79d:$i5: IClientDataHost
- 0xf7c7:$i6: IClientLoggingHost
- 0xf7da:$i7: IClientNetworkHost
- 0xf7ed:$i8: IClientUIHost
- 0xf7fb:$i9: IClientNameObjectCollection
- 0xf817:$i10: IClientReadOnlyNameObjectCollection
- 0xf56a:$s1: ClientPlugin
- 0xf781:$s1: ClientPlugin
- 0x147a2:$s6: get_ClientSettings
|
0000000E.00000002.538529652.0000000005E00000.00000004.08000000.00040000.00000000.sdmp | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0xf7ad:$a1: NanoCore.ClientPluginHost
- 0xf778:$a2: NanoCore.ClientPlugin
- 0x146f3:$b1: get_BuilderSettings
- 0x14662:$b7: LogClientException
- 0xf7c7:$b9: IClientLoggingHost
|
0000000F.00000002.533387647.00000000035B4000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
0000000E.00000002.527475187.0000000002D29000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0x5a46d:$a1: NanoCore.ClientPluginHost
- 0x5a430:$a2: NanoCore.ClientPlugin
- 0x5a804:$b1: get_BuilderSettings
- 0x5a4bb:$b4: IClientAppHost
- 0x5a875:$b6: AddHostEntry
- 0x5a8e4:$b7: LogClientException
- 0x5a859:$b8: PipeExists
- 0x5a4a8:$b9: IClientLoggingHost
|
0000000E.00000002.533662558.0000000003D29000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
0000000E.00000002.533662558.0000000003D29000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x22ee5:$a: NanoCore
- 0x22f3e:$a: NanoCore
- 0x22f7b:$a: NanoCore
- 0x22ff4:$a: NanoCore
- 0x3669f:$a: NanoCore
- 0x366b4:$a: NanoCore
- 0x366e9:$a: NanoCore
- 0x4f153:$a: NanoCore
- 0x4f168:$a: NanoCore
- 0x4f19d:$a: NanoCore
- 0x22f47:$b: ClientPlugin
- 0x22f84:$b: ClientPlugin
- 0x23882:$b: ClientPlugin
- 0x2388f:$b: ClientPlugin
- 0x3645b:$b: ClientPlugin
- 0x36476:$b: ClientPlugin
- 0x364a6:$b: ClientPlugin
- 0x366bd:$b: ClientPlugin
- 0x366f2:$b: ClientPlugin
- 0x4ef0f:$b: ClientPlugin
- 0x4ef2a:$b: ClientPlugin
|
0000000E.00000002.533662558.0000000003D29000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0x22f7b:$a1: NanoCore.ClientPluginHost
- 0x366e9:$a1: NanoCore.ClientPluginHost
- 0x4f19d:$a1: NanoCore.ClientPluginHost
- 0x22f3e:$a2: NanoCore.ClientPlugin
- 0x366b4:$a2: NanoCore.ClientPlugin
- 0x4f168:$a2: NanoCore.ClientPlugin
- 0x23312:$b1: get_BuilderSettings
- 0x3b62f:$b1: get_BuilderSettings
- 0x540e3:$b1: get_BuilderSettings
- 0x22fc9:$b4: IClientAppHost
- 0x23383:$b6: AddHostEntry
- 0x233f2:$b7: LogClientException
- 0x3b59e:$b7: LogClientException
- 0x54052:$b7: LogClientException
- 0x23367:$b8: PipeExists
- 0x22fb6:$b9: IClientLoggingHost
- 0x36703:$b9: IClientLoggingHost
- 0x4f1b7:$b9: IClientLoggingHost
|
00000010.00000002.528679468.000000000347F000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000000.00000002.466145560.00000000041DD000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
00000000.00000002.466145560.00000000041DD000.00000004.00000800.00020000.00000000.sdmp | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x2b845:$a: NanoCore
- 0x2ba05:$a: NanoCore
- 0x2e454:$a: NanoCore
- 0x2e47a:$a: NanoCore
- 0x2e7ab:$a: NanoCore
- 0x35e8a:$a: NanoCore
- 0x2e45d:$b: ClientPlugin
- 0x2e483:$b: ClientPlugin
- 0x2e7b4:$b: ClientPlugin
- 0x3534b:$c: ProjectData
- 0x30b1a:$d: DESCrypto
- 0x31295:$e: KeepAlive
- 0x303c7:$g: LogClientMessage
- 0x2ea23:$i: get_Connected
- 0x2bad4:$j: #=q
- 0x2bb18:$j: #=q
- 0x2bb34:$j: #=q
- 0x2bb76:$j: #=q
- 0x2bb92:$j: #=q
- 0x2bbae:$j: #=q
- 0x2bc06:$j: #=q
|
00000000.00000002.466145560.00000000041DD000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0x2e47a:$a1: NanoCore.ClientPluginHost
- 0x2e7ab:$a2: NanoCore.ClientPlugin
- 0x2e4a7:$b1: get_BuilderSettings
- 0x35e27:$b2: ClientLoaderForm.resources
- 0x2c3b5:$b3: PluginCommand
- 0x2eb9a:$b4: IClientAppHost
- 0x3279c:$b5: GetBlockHash
- 0x2eaaf:$b6: AddHostEntry
- 0x303b4:$b7: LogClientException
- 0x2ea70:$b8: PipeExists
- 0x2eb87:$b9: IClientLoggingHost
|
00000010.00000002.527935405.000000000343B000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000000.00000002.457661334.00000000032A8000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
0000000E.00000002.538073119.0000000005660000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth | - 0xe75:$x1: NanoCore.ClientPluginHost
- 0xe8f:$x2: IClientNetworkHost
|
0000000E.00000002.538073119.0000000005660000.00000004.08000000.00040000.00000000.sdmp | Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth | - 0xe75:$x2: NanoCore.ClientPluginHost
- 0x1261:$s3: PipeExists
- 0x1136:$s4: PipeCreated
- 0xeb0:$s5: IClientLoggingHost
|
0000000E.00000002.538073119.0000000005660000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_NanoCore | Detects NanoCore | ditekSHen | - 0xe38:$x2: NanoCore.ClientPlugin
- 0xe75:$x3: NanoCore.ClientPluginHost
- 0xe5a:$i1: IClientApp
- 0xe4e:$i2: IClientData
- 0xe29:$i3: IClientNetwork
- 0xec3:$i4: IClientAppHost
- 0xe65:$i5: IClientDataHost
- 0xeb0:$i6: IClientLoggingHost
- 0xe8f:$i7: IClientNetworkHost
- 0xea2:$i8: IClientUIHost
- 0xed2:$i9: IClientNameObjectCollection
- 0xef7:$i10: IClientReadOnlyNameObjectCollection
- 0xe41:$s1: ClientPlugin
- 0x177c:$s1: ClientPlugin
- 0x1789:$s1: ClientPlugin
- 0x11f9:$s6: get_ClientSettings
- 0x1249:$s7: get_Connected
|
0000000E.00000002.538073119.0000000005660000.00000004.08000000.00040000.00000000.sdmp | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0xe75:$a1: NanoCore.ClientPluginHost
- 0xe38:$a2: NanoCore.ClientPlugin
- 0x120c:$b1: get_BuilderSettings
- 0xec3:$b4: IClientAppHost
- 0x127d:$b6: AddHostEntry
- 0x12ec:$b7: LogClientException
- 0x1261:$b8: PipeExists
- 0xeb0:$b9: IClientLoggingHost
|
00000000.00000003.257014991.00000000042E1000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
Process Memory Space: new order.exe PID: 5796 | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: new order.exe PID: 5796 | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
Process Memory Space: new order.exe PID: 5796 | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0x1dc42:$a: NanoCore
- 0x1ddfd:$a: NanoCore
- 0x20828:$a: NanoCore
- 0x2084e:$a: NanoCore
- 0x20b7f:$a: NanoCore
- 0x281b7:$a: NanoCore
- 0x28360:$a: NanoCore
- 0x2ab8f:$a: NanoCore
- 0x2abb2:$a: NanoCore
- 0x2aec0:$a: NanoCore
- 0x31e54:$a: NanoCore
- 0x31eca:$a: NanoCore
- 0x47318:$a: NanoCore
- 0x474d3:$a: NanoCore
- 0x49efe:$a: NanoCore
- 0x49f24:$a: NanoCore
- 0x4a255:$a: NanoCore
- 0x5188d:$a: NanoCore
- 0x51a36:$a: NanoCore
- 0x54265:$a: NanoCore
- 0x54288:$a: NanoCore
|
Process Memory Space: new order.exe PID: 5796 | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0x2084e:$a1: NanoCore.ClientPluginHost
- 0x49f24:$a1: NanoCore.ClientPluginHost
- 0xe2bd6:$a1: NanoCore.ClientPluginHost
- 0x20b7f:$a2: NanoCore.ClientPlugin
- 0x4a255:$a2: NanoCore.ClientPlugin
- 0xe2f07:$a2: NanoCore.ClientPlugin
- 0x2087b:$b1: get_BuilderSettings
- 0x49f51:$b1: get_BuilderSettings
- 0xe2c03:$b1: get_BuilderSettings
- 0x28175:$b2: ClientLoaderForm.resources
- 0x5184b:$b2: ClientLoaderForm.resources
- 0xea4fd:$b2: ClientLoaderForm.resources
- 0x1e7a3:$b3: PluginCommand
- 0x47e79:$b3: PluginCommand
- 0xe0b2b:$b3: PluginCommand
- 0x20f6e:$b4: IClientAppHost
- 0x4a644:$b4: IClientAppHost
- 0xe32f6:$b4: IClientAppHost
- 0x24b57:$b5: GetBlockHash
- 0x4e22d:$b5: GetBlockHash
- 0xe6edf:$b5: GetBlockHash
|
Process Memory Space: InstallUtil.exe PID: 2344 | JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 2344 | NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> | - 0xe0b:$a: NanoCore
- 0xe67:$a: NanoCore
- 0xeda:$a: NanoCore
- 0x15b12:$a: NanoCore
- 0x15ccd:$a: NanoCore
- 0x186f8:$a: NanoCore
- 0x1871e:$a: NanoCore
- 0x18a4f:$a: NanoCore
- 0x20087:$a: NanoCore
- 0x20230:$a: NanoCore
- 0x22a5f:$a: NanoCore
- 0x22a82:$a: NanoCore
- 0x22d90:$a: NanoCore
- 0x29d24:$a: NanoCore
- 0x29d9a:$a: NanoCore
- 0x34153:$a: NanoCore
- 0x34168:$a: NanoCore
- 0x3419d:$a: NanoCore
- 0x3931f:$a: NanoCore
- 0x39332:$a: NanoCore
- 0x39364:$a: NanoCore
|
Process Memory Space: InstallUtil.exe PID: 2344 | Windows_Trojan_Nanocore_d8c4e3c5 | unknown | unknown | - 0x1871e:$a1: NanoCore.ClientPluginHost
- 0x3419d:$a1: NanoCore.ClientPluginHost
- 0x47da1:$a1: NanoCore.ClientPluginHost
- 0x90a64:$a1: NanoCore.ClientPluginHost
- 0x18a4f:$a2: NanoCore.ClientPlugin
- 0x34168:$a2: NanoCore.ClientPlugin
- 0x47d64:$a2: NanoCore.ClientPlugin
- 0x90a27:$a2: NanoCore.ClientPlugin
- 0x1874b:$b1: get_BuilderSettings
- 0x38f6f:$b1: get_BuilderSettings
- 0x4811b:$b1: get_BuilderSettings
- 0x90dde:$b1: get_BuilderSettings
- 0x20045:$b2: ClientLoaderForm.resources
- 0x16673:$b3: PluginCommand
- 0x18e3e:$b4: IClientAppHost
- 0x47def:$b4: IClientAppHost
- 0x90ab2:$b4: IClientAppHost
- 0x1ca27:$b5: GetBlockHash
- 0x18d53:$b6: AddHostEntry
- 0x4818c:$b6: AddHostEntry
- 0x90e4f:$b6: AddHostEntry
|
Process Memory Space: Luqkasd.exe PID: 1016 | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
Process Memory Space: Luqkasd.exe PID: 628 | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
Click to see the 40 entries |