s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-e38617f054245a6771e7e475fdd557f9bb85bbcadbb2a7604d67f03f97b8ebc3 high

📛 Threat Title

NanoCore: 234aeb22a6abfbdcc159fc37f1395ab5.exe

Category: NanoCore Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 207360 bytes. Tags: exe, NanoCore, RAT. Reporter: abuse_ch. First seen: 2026-08-04 20:25:06.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
638 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 e38617f054245a6771e7e475fdd557f9bb85bbcadbb2a7604d67f03f97b8ebc3

IOC database

Type
hash_sha256
Value
e38617f054245a6771e7e475fdd557f9bb85bbcadbb2a7604d67f03f97b8ebc3
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
NanoCore

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 952199df3e0fcc21143b2f04bbfb52b07875cce1

IOC database

Type
hash_sha1
Value
952199df3e0fcc21143b2f04bbfb52b07875cce1
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 234aeb22a6abfbdcc159fc37f1395ab5

IOC database

Type
hash_md5
Value
234aeb22a6abfbdcc159fc37f1395ab5
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 207360 bytes. Tags: exe, NanoCore, RAT. Reporter: abuse_ch. First seen: 2026-08-04 20:25:06.

Remediations (10)

  • web:bazaar.abuse.ch

    NanoCore malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as NanoCore . Database Entry

  • web:cybersight-security.github.io

    Nanocore typically spreads through phishing emails, malicious downloads, or exploit kits. Once installed on a victim's computer, Nanocore establishes communication with a command-and-control (C2) server operated by the attacker, enabling remote control and data exfiltration.

  • web:github.com

    Nanocore download for those who want to do malware analysis on it and study it's behavior as well as play around with its features. - PaleoMenace/ NanoCore

  • web:malwr-analysis.com

    NanoCore is a well-known Remote Access Trojan (RAT) used by threat actors for espionage, data theft, and system control. In this post, I will analyze a NanoCore RAT sample with the hash 18B476D37244CB0B435D7B06912E9193 and explore its behavior, obfuscation techniques, and deobfuscation process.

  • web:malwr-analysis.com

    NanoCore is a well-known Remote Access Trojan (RAT) used by threat actors for espionage, data theft, and system control. In this post, I will analyze a NanoCore RAT sample with the hash 18B476D37244CB0B435D7B06912E9193 and explore its behavior, obfuscation techniques, and deobfuscation process.

  • web:success.trendmicro.com

    This advisory provides Trend Micro coverage for NanoCore malware that combines backdoor and info stealing capabilities.

  • web:support.gridinsoft.com

    NanoCore is a remote access trojan (RAT) used by criminals to spy on victims, steal data, and control Windows PCs from afar. It can log keystrokes, grab screenshots, record from the webcam or mic, and drop more malware.

  • web:www.huntress.com

    NanoCore Removal Instructions If you suspect a NanoCore infection, disconnect the infected device from the network immediately to prevent further data exfiltration or lateral movement. Manual removal is complex and not recommended for non-experts, as the malware embeds itself deep within the system.

  • web:www.microsoft.com

    Summary NanoCore is a second-stage malware classified as a remote access trojan (RAT) that helps attackers to perform remote code execution (RCE) on a compromised device. Once installed, attackers can use it to perform various tasks, such as installing malicious files and establishing communication with a command-and-control (C2) server.

  • web:www.pcrisk.com

    What is NanoCore ? NanoCore is high-risk trojan, a remote access tool (RAT). In most cases, this malware is proliferated using spam email campaigns. Criminals send thousands of deceptive emails that contain malicious attachments. Once opened, these files immediately infect computers with viruses such as NanoCore . The presence of this malware can cause serious issues, since the malware ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.