typeanalysisfamilynanocoreconfidencehighcreated2026-07-25updated2026-07-25malware-familyratdotnetc2persistenceobfuscationconfuserex-obfuscation
SHA-256: 0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3

NanoCore: 0eedf3a8 — Fifth confirmed Feb 2015 sibling, Backdoor.exe lure

Executive Summary

A ConfuserEx-obfuscated .NET Framework 2.0 PE32 confirmed as a NanoCore RAT client v1.2.2.0 built from the leaked builder. Compilation timestamp 22 Feb 2015 00:49:37 UTC places it in the same batch as four prior siblings (fe81691f, 48c8e8a2, d065ebea, 4121d69c). The sample was distributed as Backdoor.exe — a blunt-filename lure suggesting either test/build artefacts or a buyer who did not bother renaming. All NanoCore-specific interfaces (IClientApp, IClientNetwork, ClientPluginHost) and builder config classes (BuilderSettings, ClientSettings, Variables) are present under the obfuscation layer.

What It Is

Field Value
SHA-256 0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3
File name Backdoor.exe ^[triage.json]
Size 207,872 bytes (203 KB)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Timestamp 0x54E927A1 → Sun Feb 22 00:49:37 2015 UTC ^[pefile.txt:34]
CLR v2.0.50727 (.NET Framework 2.0–3.5) ^[strings.txt:51]
Builder version 1.2.2.0 ^[strings.txt:1626]
Obfuscator ConfuserEx (mass #=q…== name mangling) ^[strings.txt:278–1773]
Signed No ^[rabin2-info.txt:27]
GUID $ee24ebfc-5674-4134-8aa8-c2651cc2f5d4 ^[strings.txt:1624]

Three sections (.text entropy 6.60, .reloc entropy 0.10, .rsrc entropy 7.998). ^[pefile.txt:92,112,132] The .rsrc section is a single RT_RCDATA entry (Size 0x15FA8, raw offset 0x22058) — almost certainly the encrypted plugin package or builder settings blob. ^[pefile.txt:237–239]

How It Works

Build / RE

  • Toolchain: C# / VB.NET compiled to .NET Framework 2.0 CIL, packed into a standard PE32 with mscoree.dll._CorExeMain as the only import. ^[pefile.txt:199]
  • Obfuscation: ConfuserEx with full namespace/type/method name encryption. Every user-defined symbol is replaced by a #=q…== Base64-like mangled string, producing ~1,500 noise entries in #Strings. ^[strings.txt:278–1773] This breaks dnSpy/ILSpy readability and inflates static analysis time.
  • Anti-analysis: No explicit VM/debug checks observed in static strings, but ConfuserEx itself includes anti-tamper delegates and constant encryption that will fault under debugger attach. The enter debug mode in .NET capa hit ^[capa.txt:92] is almost certainly a ConfuserEx false positive (it references Debugger.IsAttached in the anti-tamper stub).
  • Code quality: Standard builder output — no custom PDB paths, no developer artefacts. The literal filename Backdoor.exe suggests either a test build or a buyer who neglected builder renaming.

Deploy / ATT&CK

Static-only inference (CAPE skipped — no Windows guest). Capa and strings provide the following TTP mapping:

Tactic Technique Evidence
Defense Evasion T1112 Modify Registry set registry value (2 matches) ^[capa.txt:98]
Defense Evasion T1620 Reflective Code Loading load .NET assembly (2 matches) ^[capa.txt:104]
Discovery T1087 Account Discovery get session user name (2 matches) ^[capa.txt:101]
Discovery T1083 File and Directory Discovery Multiple file-system capa hits ^[capa.txt:74–84]
Discovery T1012 Query Registry query or enumerate registry key/value ^[capa.txt:94–97]
Discovery T1082 System Information Discovery get OS version in .NET, get hostname ^[capa.txt:88,89]
Discovery T1033 System Owner/User Discovery get session user name ^[capa.txt:101]
Command and Control T1095 Non-Application Layer Protocol create TCP socket, receive data, send data ^[capa.txt:62–66]
Command and Control T1071.004 DNS resolve DNS ^[capa.txt:64]
Collection — File/directory enumeration, read/write files ^[capa.txt:74–84]

Persistence — Inferred: NanoCore clients historically write themselves to %AppData% or %TEMP% and add a HKCU\Software\Microsoft\Windows\CurrentVersion\Run value. ^[entities/nanocore.md] Capa flags set registry value ^[capa.txt:98] consistent with this pattern, though the exact key is not visible in static strings.

C2 Protocol — Raw TCP sockets with builder-configured host/port list. The client supports dynamic host-cache updates via AddHostEntry and RebuildHostCache. ^[strings.txt:468,470] No hardcoded IP/domain visible in this sample; C2 is runtime-resolved from the encrypted builder config in .rsrc.

Plugin Architecture — The full NanoCore host/plugin interface surface is present: IClientApp, IClientNetwork, IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost, IClientUIHost, ClientPluginHost, ClientInvokeDelegate. ^[strings.txt:84–97] This confirms modular plugin loading from the encrypted resource package.

Process Behaviour — Capa flags create process in .NET (6 matches) and terminate process (4 matches) ^[capa.txt:91,93], consistent with child-process spawning for plugin isolation or self-relocation.

Decompiled Behavior

No decompilation performed. ConfuserEx name mangling (#=q…==) renders dnSpy/ILSpy output unreadable without manual symbol reconstruction. The entry point is the standard CLR _CorExeMain → managed Main. All business logic lives inside mangled types under the NanoCore namespace. Radare2/r2mcp loaded the binary (arch: cil) but no meaningful pseudo-C was extracted for ConfuserEx-protected CIL. Future work: run de4dot or ConfuserEx-Unpacker on the sample, then reload in dnSpy.

C2 Infrastructure

No hardcoded C2 strings recovered statically. NanoCore builder stores the host list in the encrypted .rsrc blob (size 0x15FA8 ≈ 90 KB). ^[pefile.txt:237–239] Decryption requires either:

  1. Runtime dump of the decrypted resource from a live .NET process, or
  2. Brute-forcing the ConfuserEx resource-protection key (non-trivial).

The DnsRecord class ^[strings.txt:343] suggests DNS resolution is used before TCP connect, matching the resolve DNS capa hit. ^[capa.txt:64]

Interesting Tidbits

  • Blunt lure: The builder output filename was left as Backdoor.exe — unusually honest for crimeware distribution. Most NanoCore siblings in this corpus were renamed to social-engineering lures (hotro.exe, etc.). ^[entities/nanocore.md]
  • GUID fingerprint: $ee24ebfc-5674-4134-8aa8-c2651cc2f5d4 is unique to this sample; useful for clustering builder sessions. ^[strings.txt:1624]
  • Builder version lock: All five Feb 2015 siblings carry 1.2.2.0, confirming a single leaked builder release was heavily reused in that window. ^[strings.txt:1626]
  • ConfuserEx entropy: .rsrc entropy 7.998 indicates the encrypted resource is high-entropy and likely compressed+encrypted, not just XORed. ^[pefile.txt:132]
  • No AMSI bypass: Unlike modern .NET crypters (e.g., unclassified-dotnet-crypter-loader cluster), this 2015 sample predates AMSI and contains no AmsiScanBuffer patches.

How To Mess With It (Homelab Replication)

Toolchain

  • Visual Studio 2013 or SharpDevelop targeting .NET Framework 2.0.
  • NanoCore Builder v1.2.2.0 (leaked circa 2014–2015).

Steps

  1. Obtain the leaked builder (publicly archived on malware-research repositories).
  2. Configure C2 host/port, persistence method (Registry Run), and plugin package.
  3. Build → output is a ~200 KB PE32 with 3 sections.
  4. Optionally pass through ConfuserEx (open-source, GitHub) with maximum protection level (resource encryption + constant encryption + control-flow flattening).
  5. Verify: strings -n 8 sample.exe | grep '#=q' should produce hundreds of mangled names. capa should hit create TCP socket, send data, receive data, query registry, create process, load .NET assembly.

What you learn: How a point-and-click RAT builder produces ready-to-deploy malware with minimal skill, and how ConfuserEx transforms an otherwise trivial .NET binary into a time-consuming reverse-engineering exercise.

Deployable Signatures

YARA Rule

rule nanocore_confuserex_client {
    meta:
        author = "PacketPursuit"
        description = "NanoCore RAT client with ConfuserEx obfuscation"
        family = "nanocore"
        confidence = "high"
    strings:
        $s1 = "NanoCore Client" ascii wide
        $s2 = "IClientApp" ascii wide
        $s3 = "IClientNetwork" ascii wide
        $s4 = "ClientPluginHost" ascii wide
        $s5 = "ClientInvokeDelegate" ascii wide
        $s6 = "SendToServer" ascii wide
        $s7 = "RebuildHostCache" ascii wide
        $s8 = "AddHostEntry" ascii wide
        $s9 = "PipeExists" ascii wide
        $s10 = "ClosePipe" ascii wide
        $s11 = "get_Connected" ascii wide
        $s12 = "get_BuilderSettings" ascii wide
        $s13 = "get_ClientSettings" ascii wide
        $s14 = "get_Variables" ascii wide
        $confuser = /#=q[A-Za-z0-9_$]{20,200}==/ wide ascii
    condition:
        uint16(0) == 0x5A4D and
        ($s1 or ($s2 and $s3 and $s4)) and
        3 of ($s5, $s6, $s7, $s8, $s9, $s10, $s11) and
        $s14 and
        #confuser > 50
}

Behavioral Hunt Query (Sigma-like pseudo-YAML)

title: NanoCore Client Process Spawn Pattern
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - 'Backdoor.exe'
    # Or more generically:
    Image|endswith: '.exe'
  network:
    Initiated: 'true'
    DestinationPort:
      - '>1024'   # raw TCP C2, builder-configured port
  condition: selection and network
falsepositives:
  - Rare legitimate .NET apps with coincidental naming
level: high

IOC List

Indicator Value Type
SHA-256 0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3 Hash
MD5 5fcb5aa1fdc9c289de1109170ee84049 Hash
Builder GUID $ee24ebfc-5674-4134-8aa8-c2651cc2f5d4 Config artefact
Builder version 1.2.2.0 Version
File name Backdoor.exe Filename
Mutex pattern Unknown (runtime-resolved from encrypted config) —
Registry persistence Unknown (likely HKCU\…\Run) —
C2 host/port Unknown (runtime-resolved from encrypted .rsrc) —

Behavioral Fingerprint Statement

This binary is a .NET Framework 2.0 PE32 with a minimal IAT (mscoree._CorExeMain only), a high-entropy .rsrc section (~8.0), and hundreds of #=q…== ConfuserEx-mangled symbol names in #Strings. At runtime it resolves DNS names, opens raw TCP sockets, loads additional .NET assemblies from memory, queries the registry, enumerates files, and spawns child processes — all behaviours consistent with a modular remote-access trojan.

Detection Signatures

  • MITRE ATT&CK: T1112, T1620, T1087, T1083, T1012, T1082, T1033, T1095, T1071.004
  • MBC: B0030.001 (Send Data), B0030.002 (Receive Data), C0011.001 (DNS Resolve), C0001.011 (TCP Socket), C0029.001 (MD5), C0042 (Mutex), C0017 (Create Process), C0055 (Suspend Thread), C0018 (Terminate Process)
  • MAEC: malware-category = launcher ^[capa.txt:26]

References

  • 7e1e7f29-69d6-4a6a-bde0-da0710b26fe0 (OpenCTI artifact ID) ^[metadata.json]
  • nanocore — entity page for the family cluster
  • confuserex-obfuscation — technique page for the obfuscator

Provenance

Analysis derived from static artefacts in raw/analyses/0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3/: file.txt, pefile.txt, strings.txt, capa.txt, rabin2-info.txt, triage.json, metadata.json. No dynamic execution was performed (CAPE skipped — no Windows guest). Capa version unknown (produced by triage pipeline). Floss was not successfully executed (CLI argument error in floss.txt).