{"id":"a0ebe1250b23cb60d919aa4e7dbd7e40","title":"NanoCore-RAT — NanoCore-RAT · 木马/恶意软件 · PE32","md5":"a0ebe1250b23cb60d919aa4e7dbd7e40","sha256":"2055a6d22f882f79211a9209556b9d2e14498da87a112007e5fe0d3bf5cbd2fb","family":"NanoCore-RAT","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C#","file_format":"PE32","compiler":"VB.NET","published_at":"2026-08-05T16:00:00.000Z","summary":"该样本为 VB.NET 编写的 NanoCore RAT（远程访问木马），通过 System.Net.Sockets.TcpClient 建立 TCP C2 通道，使用 DES + MD5 加密通信。内置 NanoCore 插件架构（ClientPlugin/IClientApp/IClientNetwork），支持模块化功能扩展：键盘记录、屏幕捕获、密码窃取、文件管理、注册表持久化。通过 Mutex 确保单实例运行。NanoCore 是知名的商业 RAT 工具，广泛用于网络犯罪。","url":"https://zseceye.com/report/a0ebe1250b23cb60d919aa4e7dbd7e40","json_url":"https://zseceye.com/report/a0ebe1250b23cb60d919aa4e7dbd7e40.json","html_url":"https://zseceye.com/report/a0ebe1250b23cb60d919aa4e7dbd7e40","hash_urls":{"md5":"https://zseceye.com/hash/a0ebe1250b23cb60d919aa4e7dbd7e40","sha256":"https://zseceye.com/hash/2055a6d22f882f79211a9209556b9d2e14498da87a112007e5fe0d3bf5cbd2fb"},"search_urls":{"md5":"https://zseceye.com/?q=a0ebe1250b23cb60d919aa4e7dbd7e40","sha256":"https://zseceye.com/?q=2055a6d22f882f79211a9209556b9d2e14498da87a112007e5fe0d3bf5cbd2fb"},"sample_download_url":"https://zseceye.com/report/a0ebe1250b23cb60d919aa4e7dbd7e40/sample","sample_filename":"2055a6d22f882f79.zip","iocs":[],"ips":[]}