Bird_banner_small4
Trojan.MSIL.NanoCore.Q
TSL ID TSL20171116-06
Severity Moderate
Description

Trojan.MSIL.NanoCore.Q is a Trojan that targets the Windows platform. This malware collects and sends out the system information to a remote server. It can accept commands to download and execute files/miners, visit websites, kill processes, update/uninstall itself, and more. Furthermore, it adds a value to the Run key in the Registry to survive system reboots.

Affected Products
  • Microsoft Windows All Versions
File Hashes
MD5:
  • 5AA4A764994180FF881C1EEAD759BAEE
SHA1:
  • 80CD166AC3941B1DFAC97A6A617C875FF9CA6D33
Identifiers
McAfee
  • RDN/PUP-XDB-FZ
Sophos
  • MAL/MSIL-AX
Symantec
  • TROJAN.GEN.2
TrendMicro
ALYac
  • GEN:VARIANT.MSILPERSEUS.31402
Arcabit
  • TROJAN.MSILPERSEUS.D7AAA
Cybereason
  • MALICIOUS.1B8FB7
Cyren
  • W32/TROJAN.ZKHF-8037
ESET
  • MSIL/NANOCORE.Q
Fortinet
  • MSIL/MSIL.AX!TR
Ikarus
  • TROJAN.MSIL.NANOCORE
NANO-Antivirus
  • TROJAN.WIN32.NANOCORE.EUVOBH
Qihoo-360
  • WIN32/TROJAN.3DE
ViRobot
  • TROJAN.WIN32.Z.NANOCORE.24576
References http://www.virusradar.com/en/MSIL_NanoCore.Q/description
Related Threats TSL20171206-01 - Worm.MSIL.StxRansom.A
TSL20150420-03 - Backdoor.MSIL.Nanocore.B