#nanocore — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #nanocore, aggregated by home.social.
-
-
#nanocore......#ransomware ..?
https://app.any.run/tasks/0f06cf0b-8417-4e7d-83db-0fd384472772
No files actually encrypted though 🤔
-
#nanocore......#ransomware ..?
https://app.any.run/tasks/0f06cf0b-8417-4e7d-83db-0fd384472772
No files actually encrypted though 🤔
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
Happy Monday everyone!
I ran across an article by Anurag describing the techniques they used to analyze a sample of the #NanoCore RAT. They share the tools that were used, screenshots of their findings, and interesting artifacts that were discovered. What I really appreciate about this article is that they shared both the static and dynamic analysis of the malware as well as the tools they used.
MITRE ATT&CK Behaviors:
Collection - TA0009:
Input Capture: Keylogging - T1056.001
Clipboard Data - T1115
- Stores the keylogs and clipboard data in C:\Users\User\AppData\Roaming\81E42A3A-6BA0-4784-B7EC-E653E9E1A8ED\logs\users\kbxxxxx.dat.
Persistence - TA0003:
Scheduled Task/Job: Scheduled Task - T1053.005
- The malware creates a schedule task for persistence.
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder - T1547.001
- The malware modifies the Windows Run Registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) and references an executable to run on logon.
You know the drill! Go support the author and check out the technical details that I did not include! Enjoy and Happy Hunting!
NanoCore RAT Malware Analysis
https://malwr-analysis.com/2025/02/10/nanocore-rat-malware-analysis/
Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday
-
Fortinet reports on a recent phishing campaign containing Scalable Vector Graphics (SVG) files. The malicious attachment downloads a ZIP file and begins the infection chain. ScrubCrypt, described as an "antivirus evasion tool", is used to load the final payload VenomRAT while maintaining a connection with the C2 server to install plugins like XWorm, NanoCore, RemcosRAT and a crypto wallet stealer. They provides detailed insights into how the threat actor distributes VenomRAT and other plugins. IOC listed. 🔗 https://www.fortinet.com/blog/threat-research/scrubcrypt-deploys-venomrat-with-arsenal-of-plugins
#ScrubCrypt #VenomRAT #RemcosRAT #XWorm #NanoCore #threatintel #IOC
-
@katnjiapus @suprjami @aks you can with #NanoCore!
-
📬 Malware-Gefahren im Jahr 2023: Qbot unangefochten auf Platz eins
#ITSicherheit #Malware #AgentTesla #CheckPointSoftware #DirectoryTraversal #log4j #NanoCore #Qakbot #RemoteCodeExecution #RemoteAccessTrojaner https://tarnkappe.info/artikel/it-sicherheit/malware/malware-gefahren-im-jahr-2023-qbot-unangefochten-auf-platz-eins-275138.html