public mosaic llc support@publicmosaic.com
malware family

NanoCore

16 addresses convicted as NanoCore remote-access trojan controllers — 0 still listed, 16 archived. Observed from 2026-08-26.

TLP:CLEAR
addresses 16 0 still listed
observations 19 address and port pairs
networks 3 distinct ASNs
first seen 2026-08-26 oldest observation

Detection packs

Rules for the 0 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.

About

A commodity remote-access trojan sold on criminal forums since 2013 and leaked repeatedly since. It is cheap, widely available, and typically deployed by operators with no custom tooling of their own — so a NanoCore controller says more about the operator's budget than about their sophistication.

Ports

:22011:23761:70501:73481:80921:81401:85561:90041

Addresses

Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.