Advertisement
Neonprimetime

2018-06-19 #nanocore sample #malware

Jun 19th, 2018
1,310
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.54 KB | None | 0 0
  1. found by @asset_island_
  2. email subject: New Order
  3. attachment: Order.pdf
  4. https://www.hybrid-analysis.com/sample/c6ecbf5a26b935d11e4b9683fef05cea473cc6bec18ae707dfabc1d77bbb07c7?environmentId=120
  5. link in pdf to: dropbox.com
  6. dropbox file downloads: zip with EXE inside
  7. https://www.reverse.it/sample/4f493b991de64939caf9ff4cc4bf357c449026bf5b023a46a34f1452b1453c45
  8.  
  9. ----------
  10. keylogging to
  11. ----------
  12. C:\Users\xxxx\AppData\Roaming\9174B166-43EB-456B-8628-EF18D46933C5\Logs\xxxx\KB_11223367.dat
  13.  
  14.  
  15. ----------
  16. interesting in-memory strings
  17. ----------
  18. 0x3136a4 (144): file:///C:/Users/xxx/AppData/Local/Temp/ClientPlugin/ClientPlugin.EXE
  19. 0x328c94 (252): file:///C:/Users/xxx/AppData/Local/Temp/en-US/SurveillanceExClientPlugin.resources/SurveillanceExClientPlugin.resources.EXE
  20. 0x411f4d (21): NanoCore.ClientPlugin
  21. 0x411f8d (25): NanoCore.ClientPluginHost
  22. 0x1a838d8 (140): NanoCore Client, Version=1.2.2.0, Culture=neutral, PublicKeyToken=null
  23. 0x1ac2577 (11): NanoCore.My
  24. 0x1ac6b30 (42): PrimaryConnectionHost
  25. 0x1ac6b68 (38): wilfred123.ddns.net
  26. 0x1ac6b9c (40): BackupConnectionHost
  27. 0x1ac6bd4 (38): wilfred123.ddns.net
  28. 0x1acd938 (108): file:///C:/Users/xxx/AppData/Local/Temp/RegSvcs.exe
  29. 0x1acd9b4 (30): NanoCore Client
  30. 0x1b0dee4 (15): KeyboardLogging
  31. 0x1b0e444 (84): Plugin: SurveillanceEx Plugin, Cache: True
  32. 0x1b0e104 (192): C:\Users\xxx\AppData\Roaming\9174B166-43EB-456B-8628-EF18D46933C5\Logs\xxx\KB_11223367.dat
  33. 0x1b124b8 (80): Connecting to wilfred123.ddns.net:5794..
  34. 0x1b16444 (118): Resolved hostname 'wilfred123.ddns.net' to '105.112.98.108'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement