user@threatcheck.sh ~ threat-analysis
bash
$ analyze-threat Backdoor:MSIL/Nanocore!atmn
Backdoor:MSIL/Nanocore!atmn - Windows Defender threat signature analysis

Backdoor:MSIL/Nanocore!atmn - Windows Defender Threat Analysis

$ cat analysis.txt
=== THREAT ANALYSIS REPORT ===
Threat Name: Backdoor:MSIL/Nanocore!atmn
Classification:
Type:Backdoor
Platform:MSIL
Family:Nanocore
Detection Type:Concrete
Known malware family with identified signatures
Suffix:!atmn
Confidence:Very High
False-Positive Risk:Low

Concrete signature match: Backdoor - Provides unauthorized remote access for .NET (Microsoft Intermediate Language) platform, family Nanocore

Summary:

This threat is a concrete detection of the Nanocore Remote Access Trojan (RAT), a backdoor that provides attackers with complete remote control over the compromised system. As a .NET-based RAT, it uses a plugin architecture to steal data, execute commands, and manage files. Evidence suggests it may be delivered via a self-extracting archive.

Severity:
Critical
VDM Static Detection:
Relevant strings associated with this threat:
 - ReZer0.Properties (PEHSTR)
 - System.CodeDom.Compiler (PEHSTR)
 - set_UseShellExecute (PEHSTR)
 - ReZer0V2.exe (PEHSTR)
 - set_UseShellExecute (PEHSTR_EXT)
 - NanoCore Client.exe (PEHSTR_EXT)
 - ClientLoaderForm.resources (PEHSTR_EXT)
 - NanoCore.ClientPlugin (PEHSTR_EXT)
 - 6A84./7BK8 (PEHSTR)
 - winrarsfxmappingfile.tmp (PEHSTR_EXT)
 - .docx (PEHSTR_EXT)
 - Extracting files to C:\ folder (PEHSTR_EXT)
 - Path=%temp%\ (PEHSTR_EXT)
 - NanoCore.ClientPluginHost (PEHSTR_EXT)
 - BaseCommand (PEHSTR_EXT)
 - FileCommand (PEHSTR_EXT)
 - PluginCommand (PEHSTR_EXT)
 - .pif (PEHSTR_EXT)
 - NanoCore.ClientPlugin (PEHSTR)
 - NanoCore.ClientPluginHost (PEHSTR)
 - C:\Users\Administrator\Desktop\Client\Temp\ (PEHSTR_EXT)
 - \CSPARMPricingCalOps\obj\Debug\ (PEHSTR_EXT)
 - 0.4.7.2 (PEHSTR_EXT)
 - .vbs (PEHSTR_EXT)
 - NanoCore (PEHSTR_EXT)
 - CinemaManagement.Properties.Resources.resources (PEHSTR_EXT)
 - MyClientPlugin.dll (PEHSTR_EXT)
 - \Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb (PEHSTR_EXT)
 - ConfuserEx v1.0.0-38-g7889971 (PEHSTR_EXT)
 - ComputeHash (PEHSTR_EXT)
 - get_Computer (PEHSTR_EXT)
 - get_ExecutablePath (PEHSTR_EXT)
 - */*G*/*e*/*t*/*M*/*e*/*t*/*h*/*o*/*d (PEHSTR_EXT)
 - GetExecutingAssembly (PEHSTR_EXT)
 - /tac.fmop.a//:sptth (PEHSTR_EXT)
 - powershell.exe (PEHSTR_EXT)
 - CompressionMode (PEHSTR_EXT)
 - OleDbCommand (PEHSTR_EXT)
 - p0.jO (PEHSTR_EXT)
 - b6ca9a8445.res (PEHSTR_EXT)
 - 17fac4fc2e19.Resources.resources (PEHSTR_EXT)
 - e6D0.Resources.resources (PEHSTR_EXT)
 - 849ccca2dbaa.Resources.resources (PEHSTR_EXT)
 - 6240b06f90.res (PEHSTR_EXT)
 - Advanced_Html_Editor.Resources.resources (PEHSTR_EXT)
 - CheatMenu.Properties.Resources.resources (PEHSTR_EXT)
 - Select * from Win32_ComputerSystem (PEHSTR_EXT)
 - SCHTASKS.exe /RUN /TN " (PEHSTR_EXT)
 - --Qdj$;a:9pDsb@ =} k|u9g\&. (PEHSTR_EXT)
 - qtjiZSSiWlGAf3SavB.FJr54K84g6drqE3j0u (PEHSTR_EXT)
 - zUKC.exe (PEHSTR_EXT)
 - VolvoS60.PDOControls.resources (PEHSTR_EXT)
 - SpringPendulum.SpringPendulum.resources (PEHSTR_EXT)
 - HelloWPFApp.Properties.Resources.resources (PEHSTR_EXT)
 - HelloWPFApp.Properties (PEHSTR_EXT)
 - AlgorithmSimulator.Properties.Resources.resources (PEHSTR_EXT)
 - QuanLyBangDiaCD.Properties (PEHSTR_EXT)
 - fsdgsrxd.Resources.resources (PEHSTR_EXT)
 - Cmuvk.Properties.Resources (PEHSTR_EXT)
 - Questions.Properties.Resources.resources (PEHSTR_EXT)
 - MPR.dll (PEHSTR)
 - sZIp.exe (PEHSTR_EXT)
 - MeshPods.exe (PEHSTR)
 - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT)
 - rundll32 (PEHSTR_EXT)
 - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT)
 - !#HSTR:ExecutionGuardrails (PEHSTR_EXT)
 - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
Known malware which is associated with this threat:
Filename: ED8C27E5ACB067148937E6DA6E763D32.exe
77da09a95342309e29b441182c91d79ff511f5d35bcfda7aaf5a212b763f589c
06/09/2026
Filename: 14e53f177fc328f845b1847b5cab0703.exe
632483ffc92cf6cf7aa1900f312ec8a89af06bc3ce8edab8147013cee68510dc
03/09/2026
Filename: C856731038D020706AAAA7DA2A8E46A5.exe
96812d2a00a6ced73e1eae84ed4791ec6b7b687e89fa097183b843042dd9d70b
02/09/2026
Filename: 33970F0D2D3BA1F4D505DEC41EB157E6.exe
d70fc0b690b491762a0f861cd129786e9e54c4a79dff6f7bd0b3a14c90b6ec24
01/09/2026
Filename: DF436F62AF38B7A5BCD8A3368A9F110A.exe
1c250ac3db43c8379591c0a1e8e428b972c1adda38eec2fb46376fb905e0a5e1
30/08/2026
Remediation Steps:
Immediately isolate the affected machine from the network to prevent lateral movement. Perform a full antivirus scan to remove all detected components. Due to the nature of this backdoor, consider the machine fully compromised; reset all user credentials associated with the device and re-image the system from a known-good source to ensure complete threat removal.
=== END REPORT ===
$ reanalyze-threat
This analysis was last updated on 22/11/2025. Do you want to analyze it again?
$ ls available-commands/
user@threatcheck.sh:~$ ▊