Elektrine lite

← Feed

@james_inthe_box@infosec.exchange

Post #1851391

2026-04-30 20:43 UTC

#nanocore......#ransomware ..? https://app.any.run/tasks/0f06cf0b-8417-4e7d-83db-0fd384472772 No files actually encrypted though 🤔

Replies (3)

  • @FirehaK@infosec.exchange 2026-04-30 21:12

    @james_inthe_box Just with a quick glance (it's .NET, not obfuscated), I would have expected the encryption to work. It searches for any file in the Desktop, Documents, and Downloads directories, then loops through until 100 files have been processed. If anything does manage to be encrypted...they also use a hardcoded AES key and IV. Recovery should be trivial. ¯(ツ)/¯ key: NanoCoreKey12345 iv: NanoCoreIV67890 The binary also acts as a stealer and keylogger. Plenty of easy to read functionality. EDIT: This binary basically tries to do a little bit of everything.

    Open ##1851407

  • @0xfeedc0fe@infosec.exchange 2026-04-30 21:21

    @james_inthe_box also, curious choice of bitcoin address https://coincodex.com/article/28459/satoshi-nakamoto-wallet-address/

    Open ##1851410

  • @pmelson@infosec.exchange 2026-05-01 00:59

    @james_inthe_box Just using the name, or..?

    Open ##1851414