Manuel Statik Analiz (LLM Okumali) — NanoCore RAT | Tehdit: YUKSEK

Dosya Kimligi

SHA2564eca71001daaabb1740b8f30978d43d778bfbc95f2bf336354094366f9487496
Dosya Adipk68.io.exe (C2 domain adi dosyada)
Platform.NET + ConfuserEx obfuske
Boyut207.872 byte
String Sayisi2.145

NanoCore Modulleri (Onaylandi)

NanoCore             -- ana modul
NanoCore Client      -- istemci binary adi
NanoCore Client.exe  -- calistirilan binary
NanoCore.ClientPlugin     -- plugin sistemi
NanoCore.ClientPluginHost -- plugin host
IClientAppHost       -- uygulama host arabirimi
IClientDataHost      -- veri host arabirimi
System.Net.Sockets   -- TCP ag katmani
SocketAsyncEventArgs -- async C2 baglantisi

ConfuserEx Izi

#=qoKFLFqm7bb3VWsU2QKXIQ4_6anGbTCWiZAfrNlgq8fc=
#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=
-- ConfuserEx obfuske edilmis .NET sembol isimleri

NanoCore Hakkinda

NanoCore, 2013 yilinda Taylor Huddleston tarafindan C# ile gelistirilmis, plugin-tabanli bir RAT'tir. Uretici 2017'de FBI tarafindan tutuklanmistir. Kaynak kodu sizdirildiktan sonra underground piyasada ucuza satilmaktadir. TCP socket ile C2 baglantisi kurar; keylogger, ekran yakalama, dosya yonetimi, uzaktan shell, webcam, kriptominer plugin modulleri bulunmaktadir.

IOC

SHA2564eca71001daaabb1740b8f30978d43d778bfbc95f2bf336354094366f9487496
Suspheli Domainpk68.io (dosya adinda)
ObfuskeConfuserEx

NanoCore — Malware Profile

NanoCore RAT .NET. HP scanner lures. FqStwIZtCP PDB path recurring. Plugin: GetConfig/SetConfig/conjugatePair.

Malware Type
RAT
Programming Language
.NET
C2 Protocol
TCP
Target Systems
Windows

Technical Details

.NET, plugin tabanli (DLL eklentiler), AES-128 sifreleme, port TCP dinamik, Mutex rastgele GUID, GetAsyncKeyState keylogger, Clipboard monitor, Remote Shell (cmd.exe), Hidden VNC, Password Recovery

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (1 indicators)

IOC — NanoCore
# SHA256 4eca71001daaabb1740b8f30978d43d778bfbc95f2bf336354094366f9487496
TypeValueNote
sha256 4eca71001daaabb1740b8f30978d43d778bfbc95f2bf336354094366f9487496

C2 Servers (4 recorded servers for this family)

Address Type Port Protocol Status Country
pk68.io domain 443 HTTPS active —
195.3.221.139 ip 4782 TCP inactive RO
UNKNOWN_HOST unknown 8918 TCP inactive —
37.140.192.146 ip 7707 TCP sinkholed UA

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
nanocoreratconfuserexnetplugintcppk68