0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3NanoCore: 0eedf3a8 — Fifth confirmed Feb 2015 sibling, Backdoor.exe lure
Executive Summary
A ConfuserEx-obfuscated .NET Framework 2.0 PE32 confirmed as a NanoCore RAT client v1.2.2.0 built from the leaked builder. Compilation timestamp 22 Feb 2015 00:49:37 UTC places it in the same batch as four prior siblings (fe81691f, 48c8e8a2, d065ebea, 4121d69c). The sample was distributed as Backdoor.exe — a blunt-filename lure suggesting either test/build artefacts or a buyer who did not bother renaming. All NanoCore-specific interfaces (IClientApp, IClientNetwork, ClientPluginHost) and builder config classes (BuilderSettings, ClientSettings, Variables) are present under the obfuscation layer.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3 |
| File name | Backdoor.exe ^[triage.json] |
| Size | 207,872 bytes (203 KB) |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Timestamp | 0x54E927A1 → Sun Feb 22 00:49:37 2015 UTC ^[pefile.txt:34] |
| CLR | v2.0.50727 (.NET Framework 2.0–3.5) ^[strings.txt:51] |
| Builder version | 1.2.2.0 ^[strings.txt:1626] |
| Obfuscator | ConfuserEx (mass #=q…== name mangling) ^[strings.txt:278–1773] |
| Signed | No ^[rabin2-info.txt:27] |
| GUID | $ee24ebfc-5674-4134-8aa8-c2651cc2f5d4 ^[strings.txt:1624] |
Three sections (.text entropy 6.60, .reloc entropy 0.10, .rsrc entropy 7.998). ^[pefile.txt:92,112,132] The .rsrc section is a single RT_RCDATA entry (Size 0x15FA8, raw offset 0x22058) — almost certainly the encrypted plugin package or builder settings blob. ^[pefile.txt:237–239]
How It Works
Build / RE
- Toolchain: C# / VB.NET compiled to .NET Framework 2.0 CIL, packed into a standard PE32 with
mscoree.dll._CorExeMainas the only import. ^[pefile.txt:199] - Obfuscation: ConfuserEx with full namespace/type/method name encryption. Every user-defined symbol is replaced by a
#=q…==Base64-like mangled string, producing ~1,500 noise entries in#Strings. ^[strings.txt:278–1773] This breaks dnSpy/ILSpy readability and inflates static analysis time. - Anti-analysis: No explicit VM/debug checks observed in static strings, but ConfuserEx itself includes anti-tamper delegates and constant encryption that will fault under debugger attach. The
enter debug mode in .NETcapa hit ^[capa.txt:92] is almost certainly a ConfuserEx false positive (it referencesDebugger.IsAttachedin the anti-tamper stub). - Code quality: Standard builder output — no custom PDB paths, no developer artefacts. The literal filename
Backdoor.exesuggests either a test build or a buyer who neglected builder renaming.
Deploy / ATT&CK
Static-only inference (CAPE skipped — no Windows guest). Capa and strings provide the following TTP mapping:
| Tactic | Technique | Evidence |
|---|---|---|
| Defense Evasion | T1112 Modify Registry | set registry value (2 matches) ^[capa.txt:98] |
| Defense Evasion | T1620 Reflective Code Loading | load .NET assembly (2 matches) ^[capa.txt:104] |
| Discovery | T1087 Account Discovery | get session user name (2 matches) ^[capa.txt:101] |
| Discovery | T1083 File and Directory Discovery | Multiple file-system capa hits ^[capa.txt:74–84] |
| Discovery | T1012 Query Registry | query or enumerate registry key/value ^[capa.txt:94–97] |
| Discovery | T1082 System Information Discovery | get OS version in .NET, get hostname ^[capa.txt:88,89] |
| Discovery | T1033 System Owner/User Discovery | get session user name ^[capa.txt:101] |
| Command and Control | T1095 Non-Application Layer Protocol | create TCP socket, receive data, send data ^[capa.txt:62–66] |
| Command and Control | T1071.004 DNS | resolve DNS ^[capa.txt:64] |
| Collection | — | File/directory enumeration, read/write files ^[capa.txt:74–84] |
Persistence — Inferred: NanoCore clients historically write themselves to %AppData% or %TEMP% and add a HKCU\Software\Microsoft\Windows\CurrentVersion\Run value. ^[entities/nanocore.md] Capa flags set registry value ^[capa.txt:98] consistent with this pattern, though the exact key is not visible in static strings.
C2 Protocol — Raw TCP sockets with builder-configured host/port list. The client supports dynamic host-cache updates via AddHostEntry and RebuildHostCache. ^[strings.txt:468,470] No hardcoded IP/domain visible in this sample; C2 is runtime-resolved from the encrypted builder config in .rsrc.
Plugin Architecture — The full NanoCore host/plugin interface surface is present: IClientApp, IClientNetwork, IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost, IClientUIHost, ClientPluginHost, ClientInvokeDelegate. ^[strings.txt:84–97] This confirms modular plugin loading from the encrypted resource package.
Process Behaviour — Capa flags create process in .NET (6 matches) and terminate process (4 matches) ^[capa.txt:91,93], consistent with child-process spawning for plugin isolation or self-relocation.
Decompiled Behavior
No decompilation performed. ConfuserEx name mangling (#=q…==) renders dnSpy/ILSpy output unreadable without manual symbol reconstruction. The entry point is the standard CLR _CorExeMain → managed Main. All business logic lives inside mangled types under the NanoCore namespace. Radare2/r2mcp loaded the binary (arch: cil) but no meaningful pseudo-C was extracted for ConfuserEx-protected CIL. Future work: run de4dot or ConfuserEx-Unpacker on the sample, then reload in dnSpy.
C2 Infrastructure
No hardcoded C2 strings recovered statically. NanoCore builder stores the host list in the encrypted .rsrc blob (size 0x15FA8 ≈ 90 KB). ^[pefile.txt:237–239] Decryption requires either:
- Runtime dump of the decrypted resource from a live .NET process, or
- Brute-forcing the ConfuserEx resource-protection key (non-trivial).
The DnsRecord class ^[strings.txt:343] suggests DNS resolution is used before TCP connect, matching the resolve DNS capa hit. ^[capa.txt:64]
Interesting Tidbits
- Blunt lure: The builder output filename was left as
Backdoor.exe— unusually honest for crimeware distribution. Most NanoCore siblings in this corpus were renamed to social-engineering lures (hotro.exe, etc.). ^[entities/nanocore.md] - GUID fingerprint:
$ee24ebfc-5674-4134-8aa8-c2651cc2f5d4is unique to this sample; useful for clustering builder sessions. ^[strings.txt:1624] - Builder version lock: All five Feb 2015 siblings carry
1.2.2.0, confirming a single leaked builder release was heavily reused in that window. ^[strings.txt:1626] - ConfuserEx entropy:
.rsrcentropy 7.998 indicates the encrypted resource is high-entropy and likely compressed+encrypted, not just XORed. ^[pefile.txt:132] - No AMSI bypass: Unlike modern .NET crypters (e.g.,
unclassified-dotnet-crypter-loadercluster), this 2015 sample predates AMSI and contains noAmsiScanBufferpatches.
How To Mess With It (Homelab Replication)
Toolchain
- Visual Studio 2013 or SharpDevelop targeting .NET Framework 2.0.
- NanoCore Builder v1.2.2.0 (leaked circa 2014–2015).
Steps
- Obtain the leaked builder (publicly archived on malware-research repositories).
- Configure C2 host/port, persistence method (Registry Run), and plugin package.
- Build → output is a ~200 KB PE32 with 3 sections.
- Optionally pass through ConfuserEx (open-source, GitHub) with maximum protection level (resource encryption + constant encryption + control-flow flattening).
- Verify:
strings -n 8 sample.exe | grep '#=q'should produce hundreds of mangled names.capashould hitcreate TCP socket,send data,receive data,query registry,create process,load .NET assembly.
What you learn: How a point-and-click RAT builder produces ready-to-deploy malware with minimal skill, and how ConfuserEx transforms an otherwise trivial .NET binary into a time-consuming reverse-engineering exercise.
Deployable Signatures
YARA Rule
rule nanocore_confuserex_client {
meta:
author = "PacketPursuit"
description = "NanoCore RAT client with ConfuserEx obfuscation"
family = "nanocore"
confidence = "high"
strings:
$s1 = "NanoCore Client" ascii wide
$s2 = "IClientApp" ascii wide
$s3 = "IClientNetwork" ascii wide
$s4 = "ClientPluginHost" ascii wide
$s5 = "ClientInvokeDelegate" ascii wide
$s6 = "SendToServer" ascii wide
$s7 = "RebuildHostCache" ascii wide
$s8 = "AddHostEntry" ascii wide
$s9 = "PipeExists" ascii wide
$s10 = "ClosePipe" ascii wide
$s11 = "get_Connected" ascii wide
$s12 = "get_BuilderSettings" ascii wide
$s13 = "get_ClientSettings" ascii wide
$s14 = "get_Variables" ascii wide
$confuser = /#=q[A-Za-z0-9_$]{20,200}==/ wide ascii
condition:
uint16(0) == 0x5A4D and
($s1 or ($s2 and $s3 and $s4)) and
3 of ($s5, $s6, $s7, $s8, $s9, $s10, $s11) and
$s14 and
#confuser > 50
}
Behavioral Hunt Query (Sigma-like pseudo-YAML)
title: NanoCore Client Process Spawn Pattern
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'Backdoor.exe'
# Or more generically:
Image|endswith: '.exe'
network:
Initiated: 'true'
DestinationPort:
- '>1024' # raw TCP C2, builder-configured port
condition: selection and network
falsepositives:
- Rare legitimate .NET apps with coincidental naming
level: high
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3 |
Hash |
| MD5 | 5fcb5aa1fdc9c289de1109170ee84049 |
Hash |
| Builder GUID | $ee24ebfc-5674-4134-8aa8-c2651cc2f5d4 |
Config artefact |
| Builder version | 1.2.2.0 |
Version |
| File name | Backdoor.exe |
Filename |
| Mutex pattern | Unknown (runtime-resolved from encrypted config) | — |
| Registry persistence | Unknown (likely HKCU\…\Run) |
— |
| C2 host/port | Unknown (runtime-resolved from encrypted .rsrc) |
— |
Behavioral Fingerprint Statement
This binary is a .NET Framework 2.0 PE32 with a minimal IAT (mscoree._CorExeMain only), a high-entropy .rsrc section (~8.0), and hundreds of #=q…== ConfuserEx-mangled symbol names in #Strings. At runtime it resolves DNS names, opens raw TCP sockets, loads additional .NET assemblies from memory, queries the registry, enumerates files, and spawns child processes — all behaviours consistent with a modular remote-access trojan.
Detection Signatures
- MITRE ATT&CK: T1112, T1620, T1087, T1083, T1012, T1082, T1033, T1095, T1071.004
- MBC: B0030.001 (Send Data), B0030.002 (Receive Data), C0011.001 (DNS Resolve), C0001.011 (TCP Socket), C0029.001 (MD5), C0042 (Mutex), C0017 (Create Process), C0055 (Suspend Thread), C0018 (Terminate Process)
- MAEC: malware-category = launcher ^[capa.txt:26]
References
7e1e7f29-69d6-4a6a-bde0-da0710b26fe0(OpenCTI artifact ID) ^[metadata.json]- nanocore — entity page for the family cluster
- confuserex-obfuscation — technique page for the obfuscator
Provenance
Analysis derived from static artefacts in raw/analyses/0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3/: file.txt, pefile.txt, strings.txt, capa.txt, rabin2-info.txt, triage.json, metadata.json. No dynamic execution was performed (CAPE skipped — no Windows guest). Capa version unknown (produced by triage pipeline). Floss was not successfully executed (CLI argument error in floss.txt).