← Back to SOC feed Coverage →

ThreatFox: Nanocore RAT IOCs

ioc-hunt HIGH ThreatFox
DeviceFileEvents
backdooriocthreatfoxwin-nanocore
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-06-29T23:00:00Z · Confidence: high

Hunt Hypothesis

This hunt targets adversary behavior involving the deployment of the Nanocore Remote Access Trojan by matching network and endpoint telemetry against a curated set of twelve specific Indicators of Compromise (IOCs). The SOC team should proactively execute this hunt within Azure Sentinel to identify early-stage lateral movement or command-and-control communications that may have evaded standard signature-based detections.

IOC Summary

Malware Family: Nanocore RAT Total IOCs: 12 IOC Types: sha1_hash, sha256_hash, md5_hash

TypeValueThreat TypeFirst SeenConfidence
md5_hash04f340ede96f607f310a9ca67370a5e5payload2026-06-2995%
md5_hashd11ea15f2c690f46bfc282f300f692c1payload2026-06-2995%
sha256_hash1d805377c6dc2c4321897789d82add4d2e83e947c5fe2a182061484db840d7bbpayload2026-06-2995%
sha1_hashe7feba95e7553a8d070623a279def1fabebe1ca8payload2026-06-2995%
sha1_hashb6c0e1b9da3c8f21bffbe878f58f3513848f3748payload2026-06-2995%
md5_hash5fea3f930de097794a95ced9dbae500cpayload2026-06-2995%
sha256_hashcfa1674a075c651c7bf0278f5fffc2ed2d268f4317eb41faf1d1eb03c14bdb04payload2026-06-2995%
sha1_hash999dbc13a581e26dd6e2931db152b01087d13c92payload2026-06-2995%
sha1_hash1a46239db708d9eb82152b45392433be8f182b22payload2026-06-2995%
md5_hash1615ac4b69265a70f17a0eb37df82065payload2026-06-2995%
sha256_hashaf154a4bb20730e0d8f7e88179b1797d8e67b23302ee2a0fa152dbd23a39a9ddpayload2026-06-2995%
sha256_hash604a502f34aa28773356a131d2ce537866cdd973e464a7144b0d626fd65f5937payload2026-06-2995%

KQL: Hash Hunt

// Hunt for files matching known malicious hashes
// Source: ThreatFox - Nanocore RAT
let malicious_hashes = dynamic(["04f340ede96f607f310a9ca67370a5e5", "d11ea15f2c690f46bfc282f300f692c1", "1d805377c6dc2c4321897789d82add4d2e83e947c5fe2a182061484db840d7bb", "e7feba95e7553a8d070623a279def1fabebe1ca8", "b6c0e1b9da3c8f21bffbe878f58f3513848f3748", "5fea3f930de097794a95ced9dbae500c", "cfa1674a075c651c7bf0278f5fffc2ed2d268f4317eb41faf1d1eb03c14bdb04", "999dbc13a581e26dd6e2931db152b01087d13c92", "1a46239db708d9eb82152b45392433be8f182b22", "1615ac4b69265a70f17a0eb37df82065", "af154a4bb20730e0d8f7e88179b1797d8e67b23302ee2a0fa152dbd23a39a9dd", "604a502f34aa28773356a131d2ce537866cdd973e464a7144b0d626fd65f5937"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
DeviceFileEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are specific false positive scenarios for the ThreatFox: Nanocore RAT IOCs detection rule, tailored for an enterprise environment:

Original source: https://threatfox.abuse.ch/browse/malware/win.nanocore/