TF-1821897
medium
📛 Threat Title
Nanocore RAT: Domain that is used for botnet Command&control (C&C) purerawk.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Nanocore RAT (aliases: Nancrat,NanoCore). Confidence: 50. First seen: 2026-06-03 14:42:25 UTC. Reporter: juroots. Tags: c2, NanoCore.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
158.174.211.33
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/158.174.211.33
IOC database
- Type
- ipv4
- Value
158.174.211.33- First seen
- Last seen
- Attached to this threat
- Appears in
- 13 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/158.174.211.33
domain
purerawk.com
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
purerawk.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Nanocore RAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Nanocore RAT (aliases: Nancrat,NanoCore). Confidence: 50. First seen: 2026-06-03 14:42:25 UTC. Reporter: juroots. Tags: c2, NanoCore.
Remediations (10)
-
web:attack.mitre.org
NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013.
-
web:cybersight-security.github.io
Nanocore is a remote access trojan ( RAT ) that allows cybercriminals to gain unauthorized access and control over infected computers remotely. It is known for its robust feature set, which includes keylogging, webcam and microphone hijacking, file transfer, and remote desktop functionality.
-
web:github.com
analysis and tools for hunting NanoCore C2 communications - Abjuri5t/Hunting- NanoCore
-
web:malpedia.caad.fkie.fraunhofer.de
Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.
-
web:medium.com
NanoCore RAT Hunting Guide Analysis and tools for hunting NanoCore command-and-control NanoCore is a prevalent RAT (Remote Access Trojan) which is used by threat actors to spy on victims and ...
-
web:redborder.com
NanoCore typically arrives via phishing attachments (e.g., Word documents or zipped executables). Once launched, it installs silently, establishes persistence and begins beaconing to its command-and-control (C2) server.
-
web:rewterz.com
Nanocore RAT Malware Analysis About this Report The goal of this report is to provide actionable intelligence against threat actors along with malware or other tools they use for reconnaissance, delivery, exploitation, and so forth in order to empower security operations (SecOps) teams to quickly detect and respond to this specific threat.
-
web:success.trendmicro.com
The stolen information is sent to the command and control (C&C) servers of the malware attacker. This RAT gathers the following data and sends it to its servers: Browser's user names and passwords File Transfer Protocol (FTP) clients or file manager software stored account information Email credentials of popular mail clients
-
web:www.astrill.com
NanoCore RAT is a powerful and widely used Remote Access Trojan that allows attackers to control a victim's system completely. First discovered in 2013, it has gained popularity among cybercriminals due to its low cost, ease of use, and range of malicious capabilities. From stealing login credentials to activating webcams and recording keystrokes, NanoCore poses a serious risk to individuals ...
-
web:www.checkpoint.com
Once installed on a device, NanoCore establishes a connection with its command and control server and begins collecting and exfiltrating sensitive information from the infected computer. For example, the malware will steal and send login credentials cached by the user's browser, email client, and similar software.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.