TF-1821814
high
📛 Threat Title
Nanocore RAT: Domain that is used for botnet Command&control (C&C) rtfo.sa.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Nanocore RAT (aliases: Nancrat,NanoCore). Confidence: 75. First seen: 2026-06-03 12:05:35 UTC. Reporter: abuse_ch. Tags: NanoCore.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
34.76.205.124
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/34.76.205.124
IOC database
- Type
- ipv4
- Value
34.76.205.124- First seen
- Last seen
- Attached to this threat
- Appears in
- 26 threats
- Description
- Resolved from domain xpch.sa.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/34.76.205.124
domain
rtfo.sa.com
UrlVoid 4 / 36
IOC database
- Type
- domain
- Value
rtfo.sa.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Nanocore RAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Nanocore RAT (aliases: Nancrat,NanoCore). Confidence: 75. First seen: 2026-06-03 12:05:35 UTC. Reporter: abuse_ch. Tags: NanoCore.
Remediations (10)
-
web:attack.mitre.org
NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013.
-
web:davidgodwinpratt.com
Hunt Hypothesis The detection identifies potential Nanocore RAT activity through known IOCs, indicating an adversary may be establishing persistence and command-and-control capabilities within the network. SOC teams should proactively hunt for this behavior to detect and mitigate advanced persistent threats leveraging Nanocore RAT in their Azure Sentinel environment.
-
web:malpedia.caad.fkie.fraunhofer.de
Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.
-
web:redborder.com
NanoCore typically arrives via phishing attachments (e.g., Word documents or zipped executables). Once launched, it installs silently, establishes persistence and begins beaconing to its command-and-control (C2) server.
-
web:success.trendmicro.com
The stolen information is sent to the command and control (C&C) servers of the malware attacker. This RAT gathers the following data and sends it to its servers: Browser's user names and passwords File Transfer Protocol (FTP) clients or file manager software stored account information Email credentials of popular mail clients
-
web:threatfox.abuse.ch
Nanocore RAT IOC: jnxetp.sa.com ( domain ) You are viewing the ThreatFox database entry for domain jnxetp.sa.com.
-
web:www.checkpoint.com
Once installed on a device, NanoCore establishes a connection with its command and control server and begins collecting and exfiltrating sensitive information from the infected computer. For example, the malware will steal and send login credentials cached by the user's browser, email client, and similar software.
-
web:www.huntress.com
NanoCore is a notorious remote access trojan ( RAT ) that gives attackers complete control over an infected system. It's a favorite in the cybercrime world for its low cost and modular design, allowing threat actors to steal data, spy on users, and deliver additional malware. Its primary targets are businesses and individuals, aiming to compromise sensitive information for financial gain. What ...
-
web:www.microsoft.com
NanoCore is a second-stage malware classified as a remote access trojan ( RAT ) that helps attackers to perform remote code execution (RCE) on a compromised device. Once installed, attackers can use it to perform various tasks, such as installing malicious files and establishing communication with a command-and-control (C2) server.
-
web:www.sharitsec.eu.org
NanoCore is a well-known Remote Access Trojan ( RAT ) used by threat actors for espionage, data theft, and system control. In this post, I will analyze a NanoCore RAT sample with the hash 18B476D37244CB0B435D7B06912E9193 and explore its behavior, obfuscation techniques, and deobfuscation process.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.