MB-97b2a7b78f98521a1436c44adb0f717b84364f67f4444b22d544caa2eba8811b
high
📛 Threat Title
NanoCore: 23d82b604133932ba4391ae7fb344dd0.exe
Description
File type: exe. Size: 207360 bytes. Tags: exe, NanoCore, RAT. Reporter: abuse_ch. First seen: 2026-08-04 21:40:05.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 638 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
97b2a7b78f98521a1436c44adb0f717b84364f67f4444b22d544caa2eba8811b
IOC database
- Type
- hash_sha256
- Value
97b2a7b78f98521a1436c44adb0f717b84364f67f4444b22d544caa2eba8811b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- NanoCore
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
9b75143b3e4e331a0de2796dc06ac888c55b0dca
IOC database
- Type
- hash_sha1
- Value
9b75143b3e4e331a0de2796dc06ac888c55b0dca- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
23d82b604133932ba4391ae7fb344dd0
IOC database
- Type
- hash_md5
- Value
23d82b604133932ba4391ae7fb344dd0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 207360 bytes. Tags: exe, NanoCore, RAT. Reporter: abuse_ch. First seen: 2026-08-04 21:40:05.
Remediations (10)
-
web:0xmrmagnezi.github.io
Summary NanoCore is a remote access Trojan (RAT) linked to Iranian threat actor APT33. It features multiple stages, anti-analysis techniques, and obfuscation. During analysis, I extracted its configuration, which revealed C2 domains, mutexes, bypass UAC, and other key details. The malware ensures persistence across reboots by impersonating legitimate processes and manipulating the registry ...
-
web:bazaar.abuse.ch
NanoCore malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as NanoCore . Database Entry
-
web:bazaar.abuse.ch
Information on NanoCore malware sample (SHA256 21f3851df5c3487b850c88275818072eb000857423f72608b0708b53bb3bbf64) MalwareBazaar Database You are currently viewing the ...
-
web:cybersight-security.github.io
Nanocore typically spreads through phishing emails, malicious downloads, or exploit kits. Once installed on a victim's computer, Nanocore establishes communication with a command-and-control (C2) server operated by the attacker, enabling remote control and data exfiltration.
-
web:github.com
Nanocore download for those who want to do malware analysis on it and study it's behavior as well as play around with its features. - PaleoMenace/ NanoCore
-
web:malwr-analysis.com
NanoCore is a well-known Remote Access Trojan (RAT) used by threat actors for espionage, data theft, and system control. In this post, I will analyze a NanoCore RAT sample with the hash 18B476D37244CB0B435D7B06912E9193 and explore its behavior, obfuscation techniques, and deobfuscation process.
-
web:success.trendmicro.com
This advisory provides Trend Micro coverage for NanoCore malware that combines backdoor and info stealing capabilities.
-
web:support.gridinsoft.com
NanoCore is a remote access trojan (RAT) used by criminals to spy on victims, steal data, and control Windows PCs from afar. It can log keystrokes, grab screenshots, record from the webcam or mic, and drop more malware.
-
web:www.huntress.com
NanoCore Removal Instructions If you suspect a NanoCore infection, disconnect the infected device from the network immediately to prevent further data exfiltration or lateral movement. Manual removal is complex and not recommended for non-experts, as the malware embeds itself deep within the system.
-
web:www.microsoft.com
Summary NanoCore is a second-stage malware classified as a remote access trojan (RAT) that helps attackers to perform remote code execution (RCE) on a compromised device. Once installed, attackers can use it to perform various tasks, such as installing malicious files and establishing communication with a command-and-control (C2) server.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.