This hunt targets adversary behavior involving the deployment of the Nanocore Remote Access Trojan by matching network and endpoint telemetry against a curated set of twelve specific Indicators of Compromise (IOCs). The SOC team should proactively execute this hunt within Azure Sentinel to identify early-stage lateral movement or command-and-control communications that may have evaded standard signature-based detections.
Malware Family: Nanocore RAT Total IOCs: 12 IOC Types: sha1_hash, sha256_hash, md5_hash
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| md5_hash | 04f340ede96f607f310a9ca67370a5e5 | payload | 2026-06-29 | 95% |
| md5_hash | d11ea15f2c690f46bfc282f300f692c1 | payload | 2026-06-29 | 95% |
| sha256_hash | 1d805377c6dc2c4321897789d82add4d2e83e947c5fe2a182061484db840d7bb | payload | 2026-06-29 | 95% |
| sha1_hash | e7feba95e7553a8d070623a279def1fabebe1ca8 | payload | 2026-06-29 | 95% |
| sha1_hash | b6c0e1b9da3c8f21bffbe878f58f3513848f3748 | payload | 2026-06-29 | 95% |
| md5_hash | 5fea3f930de097794a95ced9dbae500c | payload | 2026-06-29 | 95% |
| sha256_hash | cfa1674a075c651c7bf0278f5fffc2ed2d268f4317eb41faf1d1eb03c14bdb04 | payload | 2026-06-29 | 95% |
| sha1_hash | 999dbc13a581e26dd6e2931db152b01087d13c92 | payload | 2026-06-29 | 95% |
| sha1_hash | 1a46239db708d9eb82152b45392433be8f182b22 | payload | 2026-06-29 | 95% |
| md5_hash | 1615ac4b69265a70f17a0eb37df82065 | payload | 2026-06-29 | 95% |
| sha256_hash | af154a4bb20730e0d8f7e88179b1797d8e67b23302ee2a0fa152dbd23a39a9dd | payload | 2026-06-29 | 95% |
| sha256_hash | 604a502f34aa28773356a131d2ce537866cdd973e464a7144b0d626fd65f5937 | payload | 2026-06-29 | 95% |
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Nanocore RAT
let malicious_hashes = dynamic(["04f340ede96f607f310a9ca67370a5e5", "d11ea15f2c690f46bfc282f300f692c1", "1d805377c6dc2c4321897789d82add4d2e83e947c5fe2a182061484db840d7bb", "e7feba95e7553a8d070623a279def1fabebe1ca8", "b6c0e1b9da3c8f21bffbe878f58f3513848f3748", "5fea3f930de097794a95ced9dbae500c", "cfa1674a075c651c7bf0278f5fffc2ed2d268f4317eb41faf1d1eb03c14bdb04", "999dbc13a581e26dd6e2931db152b01087d13c92", "1a46239db708d9eb82152b45392433be8f182b22", "1615ac4b69265a70f17a0eb37df82065", "af154a4bb20730e0d8f7e88179b1797d8e67b23302ee2a0fa152dbd23a39a9dd", "604a502f34aa28773356a131d2ce537866cdd973e464a7144b0d626fd65f5937"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
DeviceFileEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: Nanocore RAT IOCs detection rule, tailored for an enterprise environment:
Endpoint Detection & Response (EDR) Agent Updates
svc-edr-updater) and destination IPs belonging to the primary EDR vendor’s known update servers, verified against the current IOCs list.Third-Party Patch Management Execution
ccmexec.exe (SCCM) or IvantiAgentService.exe, and the destination port matches standard HTTPS traffic (443) to known vendor update domains, provided the user context is a non-interactive system account.Enterprise Backup and Data Replication Tasks