TF-1819064
high
📛 Threat Title
Nanocore RAT: Domain that is used for botnet Command&control (C&C) rijschool-geduld.nl
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Nanocore RAT (aliases: Nancrat,NanoCore). Confidence: 75. First seen: 2026-05-27 11:35:40 UTC. Reporter: abuse_ch. Tags: NanoCore.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
rijschool-geduld.nl
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
rijschool-geduld.nl- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Nanocore RAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Nanocore RAT (aliases: Nancrat,NanoCore). Confidence: 75. First seen: 2026-05-27 11:35:40 UTC. Reporter: abuse_ch. Tags: NanoCore.
Remediations (10)
-
web:any.run
NanoCore is a Remote Access Trojan or RAT . This malware is highly customizable with plugins that allow attackers to tailor its functionality to their needs. Follow live malware statistics of this trojan and get new reports, samples, IOCs, etc.
-
web:attack.mitre.org
NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013.
-
web:cybersight-security.github.io
Nanocore is a remote access trojan ( RAT ) that allows cybercriminals to gain unauthorized access and control over infected computers remotely. It is known for its robust feature set, which includes keylogging, webcam and microphone hijacking, file transfer, and remote desktop functionality.
-
web:malpedia.caad.fkie.fraunhofer.de
Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.
-
web:malwr-analysis.com
NanoCore is a well-known Remote Access Trojan ( RAT ) used by threat actors for espionage, data theft, and system control. In this post, I will analyze a NanoCore RAT sample with the hash 18B476D37244CB0B435D7B06912E9193 and explore its behavior, obfuscation techniques, and deobfuscation process.
-
web:medium.com
At start-up, a NanoCore payload will query the domain name of its assigned C2 (Command-and-Control) server and then attempt to use the answered IP address for all of its communications ².
-
web:redborder.com
NanoCore typically arrives via phishing attachments (e.g., Word documents or zipped executables). Once launched, it installs silently, establishes persistence and begins beaconing to its command-and-control (C2) server.
-
web:rewterz.com
Nanocore RAT Malware Analysis About this Report The goal of this report is to provide actionable intelligence against threat actors along with malware or other tools they use for reconnaissance, delivery, exploitation, and so forth in order to empower security operations (SecOps) teams to quickly detect and respond to this specific threat.
-
web:success.trendmicro.com
The stolen information is sent to the command and control (C&C) servers of the malware attacker. This RAT gathers the following data and sends it to its servers:
-
web:www.checkpoint.com
What is NanoCore Malware? NanoCore is an example of a RAT , which is a type of malware designed to provide an attacker with access to and control over an infected machine. Like most RATs , NanoCore provides a wide range of capabilities, including: Screen capture Remote access Keylogging Password stealing Screen locking Data exfiltration Run backdoor commands Webcam session theft Cryptocurrency ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.