Adversaries may communicate using a custom command and control protocol instead of using existing [[Technique/T1071|Standard Application Layer Protocol]] to encapsulate commands.
Learn more
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
:1:8:A:F:U:[:`:
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:5:>:E:N:]:r:
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:60002/snapshotjpeg
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:8;N;e;l;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:?clear@QStandardItemModel@@QAEXXZ
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Dataflow
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Default ports
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:F?setColorAt@QGradient@@QAEXNABVQColor@@@Z
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:ME2 mode
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Pie statistics
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:QoS mode
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Voice mode
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;&;,;2;8;>;D;J;P;V;\;b;h;n;t;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;(;-;3;8;=;C;M;U;];e;m;u;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;0;4;8;@;X;h;l;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;8;H;L;\;`;p;t;x;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; <a<j<z<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; [!] USER/PASS commands failed. Dunno what to do.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; border: 1px solid white;
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
; Roundtrip time =
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; Status =
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;!;(;=;U;^;j;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;!;9;B;M;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;";*;3;;;B;H;Z;_;h;n;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;(;K;Z;b;w;~;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;);1;7;D;Q;Z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;+;:;D;M;V;`;i;r;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;1;<;\;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;;;D;L;S;k;t;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#<)<;<A<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;$;);7;=;Z;q;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;$;0;7;=;E;K;R;^;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;$;4;D;p;x;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;$;G;Q;X;h;q;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;%;.;5;>;M;b;p;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;&;.;7;Y;b;k;p;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;&;4;V;c;l;u;~;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;&<?<K<W<`<i<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;';3;E;Y;l;q;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;';5;O;X;_;h;w;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;';=;J;Z;h;m;v;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;';?;H;T;[;e;l;v;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;(<D<H<h<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;);1;A;W;f;o;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;*;:;K;^;h;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;*;A;N;^;c;l;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;+;2;8;N;U;[;t;{;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;2;;;T;^;g;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;3;;;A;H;T;`;k;p;y;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;:;O;`;j;u;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;;;S;^;c;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;</span> T: <font color=GoldenRod>
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;<4<=<F<O<X<a<j<{<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;?;U;i;u;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;A;H;M;U;d;x;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;C;Z;l;u;~;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;E;N;W;`;i;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
< <$<(<0<H<L<d<t<x<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
< <-<=<B<K<[<d<r<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
< <0<4<8<L<P<`<d<h<l<t<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
<!=*=7===G=U=\=e=
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN" "http://www.w3.org/TR/REC-html40/strict.dtd"><html><head><meta name="qrichtext" content="1" /><style type="text/css">p, li { white-space: pre-wrap; }</style></head><body style=" font-family:'Small Fonts'
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN" "http://www.w3.org/TR/REC-html40/strict.dtd"><html><head><meta name="qrichtext" content="1" /><style type="text/css">p, li { white-space: pre-wrap; }</style></head><body style=" font-family:'Small Fonts'; font-size:7pt; font-weight:400; font-style:normal;"><p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; font-family:'Verdana'; font-size:6pt;"><br /></p></body></html>
Copyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUse
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
Could not load HCNetSDK.dll! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikCleanup()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikInit()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikLogin()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CreateDirectoryA
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CreateMutexW
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Curl error.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CURL error: (
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_cleanup
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_getinfo
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_init
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_perform
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_setopt
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_global_cleanup
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_global_init
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_slist_append
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curllib.dll
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
currentDirectoryLine
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
customer
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
customer login
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CWDIllegalInDLLSearch
Unicode based on Runtime Data
(nesca_3.exe
)
CyanLabel
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
d3w.org database (NDB) collects all found sites for structuring and further analysis.
nCopyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUse
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nd-color: rgb(56, 56, 56);border:none;
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nd-color: rgba(2, 2, 2, 0);
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
NESCA 3 :: Revealing the Unseen Horizon
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
nesca_3.exe
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nesca_3/Z:/nesca.ico
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nesca_3Class
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NET_DVR_Cleanup
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NET_DVR_Init
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NET_DVR_Login_V30
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NetSuveillance
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
netwave ip camera
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Netwave IP Camera
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
network camera
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Network Camera BB-SC384
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Network Camera VB-??
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Network Camera VB-M40
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
New message
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
newMessageLabel
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
No closing tag detected.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No definition found!
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No login list found
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No password list found
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No password/login list found
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No ports specified!
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Non-Existed
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Not logged in
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NS-Track
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
NSTrackStatusLabel
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
VS_VERSION_INFO
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
Wait, killing threads...
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WaitForSingleObject
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
was built with FontStructhttp://www.fontshop.comhttp://fontstruct.fontshop.com/fontstructions/show/351143Creative Commons Attribution Non-commercial No Derivativeshttp://creativecommons.org/licenses/by-nc-nd/3.0/Five big quacking zephyrs jolt my wax bedAQwJdF1n
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Web Authorization
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WEB Authorization
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WEB SERVICE
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
webcamxp
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WEBCAMXP
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
webcamXP
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
WFLogin list loaded (
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WFPassword list loaded (
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WhiteLabel
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
WideCharToMultiByte
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
widgetJOB
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
{Copyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUser
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
:1:8:A:F:U:[:`:
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:5:>:E:N:]:r:
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:?clear@QStandardItemModel@@QAEXXZ
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Default ports
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:F?setColorAt@QGradient@@QAEXNABVQColor@@@Z
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; [!] USER/PASS commands failed. Dunno what to do.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN" "http://www.w3.org/TR/REC-html40/strict.dtd"><html><head><meta name="qrichtext" content="1" /><style type="text/css">p, li { white-space: pre-wrap; }</style></head><body style=" font-family:'Small Fonts'
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN" "http://www.w3.org/TR/REC-html40/strict.dtd"><html><head><meta name="qrichtext" content="1" /><style type="text/css">p, li { white-space: pre-wrap; }</style></head><body style=" font-family:'Small Fonts'; font-size:7pt; font-weight:400; font-style:normal;"><p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; font-family:'Verdana'; font-size:6pt;"><br /></p></body></html>
Copyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUse
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
Could not load HCNetSDK.dll! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikCleanup()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikInit()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikLogin()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CreateMutexW
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Curl error.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CURL error: (
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_getinfo
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
d3w.org database (NDB) collects all found sites for structuring and further analysis.
nCopyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUse
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nd-color: rgb(56, 56, 56);border:none;
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nd-color: rgba(2, 2, 2, 0);
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nesca_3.exe
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nesca_3/Z:/nesca.ico
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
VS_VERSION_INFO
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
was built with FontStructhttp://www.fontshop.comhttp://fontstruct.fontshop.com/fontstructions/show/351143Creative Commons Attribution Non-commercial No Derivativeshttp://creativecommons.org/licenses/by-nc-nd/3.0/Five big quacking zephyrs jolt my wax bedAQwJdF1n
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WEB SERVICE
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
widgetJOB
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
{Copyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUser
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
:1:8:A:F:U:[:`:
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:5:>:E:N:]:r:
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:60002/snapshotjpeg
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:8;N;e;l;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:?clear@QStandardItemModel@@QAEXXZ
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Dataflow
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Default ports
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:F?setColorAt@QGradient@@QAEXNABVQColor@@@Z
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:ME2 mode
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Pie statistics
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:QoS mode
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
:Voice mode
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;&;,;2;8;>;D;J;P;V;\;b;h;n;t;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;(;-;3;8;=;C;M;U;];e;m;u;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;0;4;8;@;X;h;l;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; ;8;H;L;\;`;p;t;x;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; <a<j<z<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; [!] USER/PASS commands failed. Dunno what to do.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; border: 1px solid white;
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
; Roundtrip time =
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
; Status =
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;!;(;=;U;^;j;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;!;9;B;M;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;";*;3;;;B;H;Z;_;h;n;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;(;K;Z;b;w;~;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;);1;7;D;Q;Z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;+;:;D;M;V;`;i;r;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;1;<;\;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#;;;D;L;S;k;t;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;#<)<;<A<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;$;);7;=;Z;q;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;$;0;7;=;E;K;R;^;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;$;4;D;p;x;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;$;G;Q;X;h;q;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;%;.;5;>;M;b;p;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;&;.;7;Y;b;k;p;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;&;4;V;c;l;u;~;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;&<?<K<W<`<i<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;';3;E;Y;l;q;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;';5;O;X;_;h;w;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;';=;J;Z;h;m;v;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;';?;H;T;[;e;l;v;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;(<D<H<h<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;);1;A;W;f;o;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;*;:;K;^;h;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;*;A;N;^;c;l;|;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;+;2;8;N;U;[;t;{;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;2;;;T;^;g;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;3;;;A;H;T;`;k;p;y;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;:;O;`;j;u;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;;;S;^;c;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;</span> T: <font color=GoldenRod>
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;<4<=<F<O<X<a<j<{<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;?;U;i;u;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;A;H;M;U;d;x;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;C;Z;l;u;~;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
;E;N;W;`;i;z;
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
< <$<(<0<H<L<d<t<x<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
< <-<=<B<K<[<d<r<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
< <0<4<8<L<P<`<d<h<l<t<
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
<!=*=7===G=U=\=e=
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN" "http://www.w3.org/TR/REC-html40/strict.dtd"><html><head><meta name="qrichtext" content="1" /><style type="text/css">p, li { white-space: pre-wrap; }</style></head><body style=" font-family:'Small Fonts'
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN" "http://www.w3.org/TR/REC-html40/strict.dtd"><html><head><meta name="qrichtext" content="1" /><style type="text/css">p, li { white-space: pre-wrap; }</style></head><body style=" font-family:'Small Fonts'; font-size:7pt; font-weight:400; font-style:normal;"><p style="-qt-paragraph-type:empty; margin-top:0px; margin-bottom:0px; margin-left:0px; margin-right:0px; -qt-block-indent:0; text-indent:0px; font-family:'Verdana'; font-size:6pt;"><br /></p></body></html>
Copyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUse
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
Could not load HCNetSDK.dll! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikCleanup()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikInit()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Could not locate hikLogin()! Hikvision support disabled.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CreateDirectoryA
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CreateMutexW
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Curl error.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CURL error: (
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_cleanup
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_getinfo
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_init
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_perform
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_easy_setopt
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_global_cleanup
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_global_init
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curl_slist_append
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
curllib.dll
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
currentDirectoryLine
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
customer
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
customer login
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
CyanLabel
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
d3w.org database (NDB) collects all found sites for structuring and further analysis.
nCopyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUse
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nd-color: rgb(56, 56, 56);border:none;
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nd-color: rgba(2, 2, 2, 0);
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
NESCA 3 :: Revealing the Unseen Horizon
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
nesca_3.exe
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nesca_3/Z:/nesca.ico
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
nesca_3Class
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NET_DVR_Cleanup
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NET_DVR_Init
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NET_DVR_Login_V30
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NetSuveillance
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
netwave ip camera
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Netwave IP Camera
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
network camera
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Network Camera BB-SC384
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Network Camera VB-??
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Network Camera VB-M40
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
New message
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
newMessageLabel
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
No closing tag detected.
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No definition found!
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No login list found
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No password list found
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No password/login list found
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
No ports specified!
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Non-Existed
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Not logged in
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
NS-Track
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
NSTrackStatusLabel
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
VS_VERSION_INFO
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
Wait, killing threads...
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WaitForSingleObject
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
was built with FontStructhttp://www.fontshop.comhttp://fontstruct.fontshop.com/fontstructions/show/351143Creative Commons Attribution Non-commercial No Derivativeshttp://creativecommons.org/licenses/by-nc-nd/3.0/Five big quacking zephyrs jolt my wax bedAQwJdF1n
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
Web Authorization
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WEB Authorization
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WEB SERVICE
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
webcamxp
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WEBCAMXP
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
webcamXP
Ansi based on Hybrid Analysis
(nesca_3.exe.bin)
WFLogin list loaded (
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WFPassword list loaded (
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
WhiteLabel
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
WideCharToMultiByte
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
widgetJOB
Unicode based on Memory/File Scan
(nesca_3.exe.bin)
{Copyright SomeUser 2010Small FontRegularFontStruct Small FontSmall Font RegularVersion 1.0Small-FontFontStruct is a trademark of FSI FontShop International GmbHhttp://fontstruct.fontshop.comSomeUser
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
~F?setData@QStandardItem@@UAEXABVQVariant@@H@Z
Ansi based on Memory/File Scan
(nesca_3.exe.bin)
8_0_________e_e___
Ansi based on Image Processing
(screen_2.png)
?_____0________
Ansi based on Image Processing
(screen_2.png)
?_____0_____q0______
Ansi based on Image Processing
(screen_2.png)
?___________00_____
Ansi based on Image Processing
(screen_2.png)
_08_______
Ansi based on Image Processing
(screen_2.png)
_0_?0____00L0__
Ansi based on Image Processing
(screen_2.png)
_0_______0
Ansi based on Image Processing
(screen_2.png)
_0_________0
Ansi based on Image Processing
(screen_2.png)
_0__e_v___
Ansi based on Image Processing
(screen_2.png)
__08_____u__________0___
Ansi based on Image Processing
(screen_2.png)
____?____________Jv__
Ansi based on Image Processing
(screen_2.png)
________0_____
Ansi based on Image Processing
(screen_2.png)
___________0___
Ansi based on Image Processing
(screen_2.png)
____________0
Ansi based on Image Processing
(screen_2.png)
_____________
Ansi based on Image Processing
(screen_2.png)
__yB__|D_
Ansi based on Image Processing
(screen_2.png)
_li_7___'7_7;_7__7__7'_____
Ansi based on Image Processing
(screen_2.png)
c0nf_gu_at_0n
Ansi based on Image Processing
(screen_2.png)
Calculat0r
Ansi based on Image Processing
(screen_2.png)
j'IGm_n9Sta_ed
Ansi based on Image Processing
(screen_2.png)
Magn_f_er
Ansi based on Image Processing
(screen_2.png)
P_____og0_v?_0____a__c
Ansi based on Image Processing
(screen_2.png)
Res0u_cem0n_t0_
Ansi based on Image Processing
(screen_2.png)
S0l_ta_re
Ansi based on Image Processing
(screen_2.png)
sn____n9T001
Ansi based on Image Processing
(screen_2.png)
\Sessions\1\Windows\ApiPort
Unicode based on Runtime Data
(nesca_3.exe
)
CWDIllegalInDLLSearch
Unicode based on Runtime Data
(nesca_3.exe
)
MachinePreferredUILanguages
Unicode based on Runtime Data
(nesca_3.exe
)
PreferExternalManifest
Unicode based on Runtime Data
(nesca_3.exe
)
PreferredUILanguages
Unicode based on Runtime Data
(nesca_3.exe
)
TransparentEnabled
Unicode based on Runtime Data
(nesca_3.exe
)
_?_?_?M_L_
Ansi based on Image Processing
(screen_0.png)
__?mJ____q_?,,?,??m??_?_v__,,,_,,
Ansi based on Image Processing
(screen_0.png)
m____qJ_,,
Ansi based on Image Processing
(screen_0.png)
PSPUBWS-PC
Ansi based on PCAP Processing
(network.pcap)
Extracted Files
No significant files were extracted.
Notifications
Runtime
Not all IP/URL string resources were checked online
Hybrid Analysis requires that users undergo the Hybrid Analysis Vetting Process prior to obtaining an API key or downloading malware samples. Please note that you must abide by the Hybrid Analysis Terms and Conditions and only use these samples for research purposes. You are not permitted to share your user credentials or API key with anyone else. Please notify Hybrid Analysis immediately if you believe that your API key or user credentials have been compromised.