Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #nanocore #malware
- @neonprimetime security
- https://www.joesandbox.com/analysis/59815/0/html
- https://www.reverse.it/sample/47755676f0bfab8a782ea04dd3c5e22324e92dda42810c902e3a23327375a57b?environmentId=100
- excel md5 aa4876cc060652d9d54355188bbeafda
- exe md5 a237fa451c0fcd5f06057d3d4db5398c
- -------------
- interesting in memory strings
- -------------
- 0x2b1c80 (19): NanoCore Client.exe
- 0x2b1cb0 (19): nanocore client.exe
- 0x2baa28 (30): NanoCore Client
- 0x411cf5 (15): NanoCore Client
- 0x411d05 (19): NanoCore Client.exe
- 0x411f4d (21): NanoCore.ClientPlugin
- 0x411f8d (25): NanoCore.ClientPluginHost
- 0x1de3c34 (140): NanoCore Client, Version=1.2.2.0, Culture=neutral, PublicKeyToken=null
- 0x1de3cf0 (176): ClientLoaderForm, NanoCore Client, Version=1.2.2.0, Culture=neutral, PublicKeyToken=null
- 0x1de4344 (30): NanoCore Client
- 0x1df25c3 (11): NanoCore.My
- 0x1df261c (21): NanoCore.ClientPlugin
- 0x1df2659 (25): NanoCore.ClientPluginHost
- 0x1e21810 (44): shinanomachi.nagano.jp
- 0x1e25718 (34): minano.saitama.jp
- 0x1e72314 (30): NanoCore Client
- 0x1e72440 (30): NanoCore Client
- 0x1e7254c (42): NanoCore Client[4020]
- 0x1e73ff0 (42): nanocore client[4020]
- 0x1e76198 (42): nanocore client[4020]
- 0x1e766a4 (42): nanocore client[4020]
- 0x1e76e54 (42): nanocore client[4020]
- 0x1e77608 (42): nanocore client[4020]
- 0x1e77db4 (42): nanocore client[4020]
- 0x2e2aa6d (11): NanoCore.My
- 0x2e2aac6 (21): NanoCore.ClientPlugin
- 0x2e2ab03 (25): NanoCore.ClientPluginHost
- 0x2e3e23c (21): NanoCore.ClientPlugin
- 0x2e3e271 (25): NanoCore.ClientPluginHost
- 0x2e57220 (21): NanoCore.ClientPlugin
- 0x2e57255 (25): NanoCore.ClientPluginHost
- 0x1df6790 (26): 89.35.228.244
- 0x1e51968 (68): Connecting to 89.35.228.244:2233..
- 0x1e5208c (26): 89.35.228.244
- 0x1e533e4 (38): Host: 89.35.228.244
- 0x1e7abf4 (68): Connecting to 89.35.228.244:2233..
- 0x1e7f0f0 (26): 89.35.228.244
- 0x1f069cc (68): Connecting to 89.35.228.244:2233..
- 0x1f35100 (26): 89.35.228.244
- 89.35.228.244
- 0x2e2eaaa (21): SurveillanceEx Plugin
- 0x2e3dfd5 (26): SurveillanceExClientPlugin
- 0x2e3dff0 (30): SurveillanceExClientPlugin.dll
- 0x2e47110 (60): SurveillanceExClientPlugin.dll
- 0x2e471a0 (60): SurveillanceExClientPlugin.dll
- 0x2e56fb9 (26): SurveillanceExClientPlugin
- 0x2e56fd4 (30): SurveillanceExClientPlugin.dll
- 0x2e600f4 (60): SurveillanceExClientPlugin.dll
- 0x2e60184 (60): SurveillanceExClientPlugin.dll
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement