112d957b56a0ccec1e06defc317c8b7b169b6e74514d1a6f7bee8c2b32b080aenanocore: 112d957b — VB.NET ConfuserEx client, Dutch domain masquerade (12th Feb 2015 sibling)
Executive Summary
A 203 KB PE32 .NET assembly (gwwsite.nl.exe) carrying the NanoCore RAT client (v1.2.2.0) inside a heavy ConfuserEx obfuscation layer. This is the twelfth confirmed sibling of the Feb 22 2015 00:49:37 UTC batch cluster, joining eleven prior samples already catalogued in nanocore. The sample masquerades as a Dutch domain (gwwsite.nl) — a website-domain social-engineering lure rather than a game or software utility. Unique MyTemplate GUID ead3cb61-5c13-4ced-8ae6-88a547e425c9. No hardcoded C2 recovered statically; builder-generated config is encrypted inside the .rsrc RCData payload. Static-only analysis — Windows CAPE guest unavailable. ^[file.txt] ^[strings.txt:55] ^[strings.txt:1626]
What It Is
| Property | Value | Provenance |
|---|---|---|
| SHA-256 | 112d957b56a0ccec1e06defc317c8b7b169b6e74514d1a6f7bee8c2b32b080ae |
metadata.json |
| File name | gwwsite.nl.exe |
triage.json |
| Size | 207,872 bytes (203 KB) | metadata.json |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | file.txt |
| Timestamp | Sun Feb 22 00:49:37 2015 UTC | pefile.txt:34 |
| Linker | .NET Framework v2.0.50727 (CLR 2.0) | strings.txt:43 |
| Language | Visual Basic .NET (My.Application framework) | strings.txt:1585, strings.txt:1613 |
| RAT version | NanoCore Client 1.2.2.0 | strings.txt:1626 |
| Obfuscator | ConfuserEx (massive #=q…== mangling, 465 symbols) |
r2:sym.list |
| Signed | No (stripped, unsigned) | pefile.txt:153-155 |
| MyTemplate GUID | ead3cb61-5c13-4ced-8ae6-88a547e425c9 |
strings.txt:1624 |
The binary is the compiled client payload for NanoCore, a commodity .NET-based remote-access trojan. The original source was likely assembled by the NanoCore builder and then passed through ConfuserEx to strip names, encrypt resources, and impede static recovery. ^[strings.txt:55] ^[strings.txt:56]
How It Works
Loader / Startup
- The PE is a standard .NET EXE with a single import (
mscoree.dll!_CorExeMain) ^[pefile.txt:199]. - On CLR bootstrap, execution reaches
ClientLoaderForm.Mainat0x0040c480(the entry point identified in radare2) ^[r2:method.ClientLoaderForm.Main]. - The VB.NET
My.Applicationtemplate auto-generates a hidden Windows Forms wrapper;ClientLoaderFormis created as invisible (set_Visible,set_ShowInTaskbar,set_WindowState). - The
IClientAppinterface (NanoCore plugin contract) is instantiated, which triggers the network layer, registry operations, and plugin loading.
Obfuscation
- Name mangling: ConfuserEx has rewritten every class, method, field, and property into
#=q…==identifiers. Radare2 lists 465 symbols, nearly all mangled. ^[r2:sym.list] - Resource encryption:
.rsrc(90,464 bytes, entropy ~8.00) contains a singleRT_RCDATAentry (ID0xA→0x1→ LANG_NEUTRAL) at raw offset0x22058, size0x15F60. ^[pefile.txt:237-238] The payload is encrypted (no cleartext headers, no ZIP magic in first 1 KB) and terminates with theXPADDINGPADDINGXtrailer common to ConfuserEx-encrypted resources. ^[custom:hexdump of /tmp/nanocore_rcdata.bin] - No native packing: Not UPX, not custom native packer. ConfuserEx operates entirely inside the .NET layer. ^[binwalk.txt]
- Decryption surface: Strings reference
RijndaelManaged,set_Key,set_IV,CreateDecryptor,TransformFinalBlock, andSystem.IO.Compression.DeflateStream— the RCData is decrypted via Rijndael (AES) then decompressed at runtime. ^[strings.txt:232] ^[strings.txt:1474-1477] ^[strings.txt:152]
Persistence & Installation (inferred)
The binary references standard NanoCore installation behaviors already documented in the cluster (see nanocore):
get_StartupPathandset_CurrentDirectoryfor self-copying into%AppData%or%TEMP%.- Registry manipulation via
RegistryKeyfor Run-key persistence. ^[capa.txt:15-16] ^[capa.txt:98-99] - File-system operations: create directory, copy file, delete file, write file. ^[capa.txt:73-84]
Network / C2 (inferred)
No hardcoded IP, domain, or URL survived string extraction. Network behavior is inferred from:
System.Net.Sockets.Socket,ConnectAsync,SendToServer,get_Connected,get_Port— NanoCore speaks over raw TCP sockets, not HTTP. ^[strings.txt:170-181] ^[strings.txt:1114]DnsRecord,AddHostEntry,RebuildHostCache,GetHostEntry— C2 host list is maintained internally and can be updated by the server. ^[strings.txt:468] ^[strings.txt:470]KeepAlivepresent in strings, suggesting persistent TCP keepalive framing. ^[strings.txt:1116]- Builder pattern: NanoCore's builder generates a custom
ClientSettings/BuilderSettingsblob stored inside the resource stream. This sample likely carries its settings in the encrypted RCData within.rsrc; static extraction without decryption yields nothing. ^[strings.txt:1401-1402] ^[strings.txt:411-412]
Plugin Architecture
NanoCore is plugin-driven. Static evidence includes:
NanoCore.ClientPlugin,NanoCore.ClientPluginHostnamespaces. ^[strings.txt:87] ^[strings.txt:91]FileCommand,PluginCommand— task dispatch enum. ^[strings.txt:346] ^[strings.txt:344]IClientApp,IClientData,IClientNetwork,IClientUIHost, etc. — interface contracts for modular components. ^[strings.txt:86-97]- Pipe-based IPC:
PipeCreated,PipeExists,ClosePipe— the client ↔ plugin bridge uses named/anonymous pipes. ^[strings.txt:1113] ^[strings.txt:1111]
Decompiled Behavior
Radare2 (CIL engine) identifies 858 functions, with the entry point landing in:
method.ClientLoaderForm.Main(address0x40c480) — WinForms bootstrap. ^[r2:method.ClientLoaderForm.Main]- Control flow is dominated by ConfuserEx
ControlFlowobfuscation: flattened blocks, exception-based branching, and delegate trampolines. Manual decompilation is impractical without tools like NoFusicator or de4dot replacement pipelines.
C2 Infrastructure
- Static C2: None extracted. The builder-generated
ClientSettings/BuilderSettingsobject is encrypted inside the.rsrcRCData and decrypted at runtime. ^[strings.txt:1401-1402] - Protocol: Raw TCP sockets (not HTTPS/HTTP per standard NanoCore behavior). Keepalive framing inferred from
KeepAlive,Socket,SendToServer,ReceiveAsync. ^[strings.txt:1116] - DNS:
DnsRecord,GetHostEntry,AddHostEntry,RebuildHostCacheshow the client maintains a mutable host cache — typical for DGA fallback or server-driven redirection. ^[strings.txt:468] ^[strings.txt:470]
Interesting Tidbits
- Dutch domain masquerade: The filename
gwwsite.nl.exeimpersonates a.nl(Netherlands) domain — a website-domain social-engineering lure, distinct from the game-utility lures seen in siblingsf017a517(EMU.exe) and37509ef2(Nemo.exe). - Unique GUID:
ead3cb61-5c13-4ced-8ae6-88a547e425c9is theMyTemplateauto-generated GUID for this build. Every sibling in the Feb 2015 batch carries a unique GUID, confirming batch-builder behaviour. ^[strings.txt:1624] - Same builder, same payload size: The encrypted RCData is 90,464 bytes (
0x15F60), virtually identical to siblingb6008cf6(90,408 bytes) andf017a517(89,960 bytes). The builder likely pads or encrypts a fixed-size plugin/config bundle. ^[pefile.txt:238] - Rijndael + Deflate: Unlike earlier siblings where only AES references were found, this sample explicitly references
RijndaelManagedandDeflateStreamin the same string set — the decryption pipeline is Rijndael-decrypt then Deflate-decompress. ^[strings.txt:232] ^[strings.txt:152] - No YARA family hit: Only
PE_File_Generictriggered; standard open-source NanoCore YARA rules miss ConfuserEx-obfuscated variants. ^[yara.txt] - FLOSS failure: The
floss.txtartifact contains only a CLI argument-error message because the triage pipeline passed malformed flags — no decoded strings were recovered. The heavy ConfuserEx obfuscation would likely defeat FLOSS anyway. ^[floss.txt]
How To Mess With It (Homelab Replication)
Goal: Reproduce a NanoCore-like .NET RAT with ConfuserEx obfuscation and see how static tools respond.
- Toolchain: Visual Studio Community + VB.NET/.NET Framework 4.8 Console / WinForms app.
- Build a stub: Create a Windows Forms app with a hidden startup form,
System.Net.Sockets.TcpClient, and aTcpListenerloop. - Add builder pattern: Store C2 host/port in
Properties.Resourcesas an encrypted JSON blob (e.g., AES-CBC with a hardcoded key). - Obfuscate with ConfuserEx: Download the open-source ConfuserEx v1.6.0, apply:
- Name obfuscation (rename everything to
#=q…==) - Constant obfuscation (encrypt strings at compile time)
- Control flow flattening
- Resource encryption (zip + encrypt payload)
- Name obfuscation (rename everything to
- Verification: Run
capa <your_sample.exe>andstrings | grep -i nano— should hitcommunication/socket/tcp,data-manipulation/hashing/md5, andhost-interaction/file-system/createjust like this sample. - What you learn: ConfuserEx is mature, free, and trivial to apply. Every
.NETmalware analyst needs a de4dot/NoFuser pipeline ready.
Deployable Signatures
YARA — NanoCore ConfuserEx Variant (batch-aware)
rule nanocore_confuserex_vbnet_batch_2015
{
meta:
description = "NanoCore RAT client obfuscated with ConfuserEx, VB.NET build, Feb 2015 batch"
author = "triage-auto"
date = "2026-08-09"
sha256 = "112d957b56a0ccec1e06defc317c8b7b169b6e74514d1a6f7bee8c2b32b080ae"
strings:
$nano1 = "NanoCore Client" ascii wide
$nano2 = "NanoCore.ClientPlugin" ascii wide
$nano3 = "IClientApp" ascii wide
$nano4 = "IClientNetwork" ascii wide
$nano5 = "ClientLoaderForm" ascii wide
$nano6 = "SendToServer" ascii wide
$nano7 = "AddHostEntry" ascii wide
$nano8 = "RebuildHostCache" ascii wide
$nano9 = "PluginCommand" ascii wide
$conf1 = /#=q[A-Za-z0-9_$]{20,}==/ // ConfuserEx mangled name
$conf2 = /#=q[A-Za-z0-9_$]{20,}=.*=/ // ConfuserEx extended form
$vb1 = "MyTemplate" ascii wide
$vb2 = "My.MyProject.Forms" ascii wide
$ver = "1.2.2.0" ascii wide
condition:
uint16(0) == 0x5A4D
and pe.number_of_sections == 3
and any of ($nano*)
and any of ($conf*)
and any of ($vb*)
and filesize < 500KB
}
Note: Syntactically tested by eye; deploy to your YARA sandbox before production.
Sigma — NanoCore Process Launch Hunt
title: NanoCore RAT Client Loader Execution
id: 8f3a2b1c-4d5e-6f7a-8b9c-0d1e2f3a4b5c
description: Detects NanoCore VB.NET client process based on module/interface strings and pipe creation.
logsource:
category: process_creation
product: windows
detection:
selection_strings:
CommandLine|contains|all:
- 'NanoCore'
- 'ClientLoaderForm'
selection_pipes:
- PipeName|contains:
- 'NanoCore'
selection_mutex:
- CommandLine|contains:
- 'IClientApp'
- 'IClientNetwork'
condition: 1 of selection_*
falsepositives:
- Unlikely — these strings are specific to the NanoCore RAT family.
level: critical
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 112d957b56a0ccec1e06defc317c8b7b169b6e74514d1a6f7bee8c2b32b080ae |
Hash |
| SHA-1 | 84a408c0eb3be359866255074448c1c67aa806ee |
Hash |
| MD5 | d5055092da14cf9985f755dbec97ec01 |
Hash |
| ssdeep | 6144:uLV6Bta6dtJmakIM57BGmPDZ1ZgJB6QUWv:uLV6BtpmkWBGmPDZ1gB65Wv |
Fuzzy hash |
| File name | gwwsite.nl.exe |
Filename |
| Builder version | 1.2.2.0 |
Version |
| MyTemplate GUID | ead3cb61-5c13-4ced-8ae6-88a547e425c9 |
GUID |
| Timestamp | Sun Feb 22 00:49:37 2015 UTC |
PE timestamp |
| Resource entropy | ~8.00 bits/byte (.rsrc) |
Section entropy |
Behavioral Fingerprint
This binary is a PE32 .NET GUI executable with exactly three sections (.text, .reloc, .rsrc) and a minimal import table containing only mscoree.dll!_CorExeMain. At process start, the CLR loads the assembly, JIT-compiles the obfuscated IL, and enters ClientLoaderForm.Main. The loader decrypts a 90 KB RCData resource using RijndaelManaged (AES-family) and DeflateStream decompression, then reflectively loads the resulting plugin/config assemblies. Network behaviour uses raw TCP sockets (not HTTP) with a mutable host cache updated via server commands. Persistence is achieved through registry Run keys and file-system self-copying. Pipe-based IPC mediates communication between the main client and dynamically loaded plugins.
Detection Signatures
capa → ATT&CK Mapping
| capa Capability | ATT&CK Technique |
|---|---|
| set registry value | T1112 |
| load .NET assembly | T1620 |
| query or enumerate registry key/value | T1012 |
| get session user name | T1033 |
| get OS version | T1082 |
| create process | T1106 |
| create or open mutex | T1106 |
| file and directory discovery | T1083 |
| system information discovery | T1082 |
| account discovery | T1087 |
| receive data / send data | T1071 |
| resolve DNS | T1071 |
| create TCP socket | T1071 |
| hash data with MD5 | T1021 |
| manipulate unmanaged memory | T1055 |
| enter debug mode | T1622 |
| terminate process | T1489 |
| suspend thread | T1055 |
Dynamic analysis was skipped (no Windows guest available); the ATT&CK mapping is derived from static capa hits and is therefore conservative.
References
- nanocore — cluster entity page with shared analysis of the Feb 2015 batch.
- confuserex-obfuscation — technique page documenting ConfuserEx fingerprints and reproduction.
- MalwareBazaar / abuse.ch entry for SHA-256
112d957b.... - OpenCTI artifact
23536bde-e4c1-4187-a0da-d9b6334814ac.
Provenance
file.txt— file(1) outputpefile.txt— pefile.py PE structure dumpstrings.txt—strings -n 6outputfloss.txt— flare-floss CLI error (no decoded strings recovered)capa.txt— Mandiant capa static capability detectionyara.txt— YARA scan resultsbinwalk.txt— binwalk signature scanrabin2-info.txt— radare2 binary header summaryexiftool.json— EXIF/PE metadatametadata.json/triage.json— corpus metadata- Radare2 analysis:
a3on<sample 112d957b56a0.bin>, 858 functions, 465 symbols - RCData extraction:
dd if=/tmp/112d957b...bin of=/tmp/nanocore_rcdata.bin bs=1 skip=139352 count=90464 - Tools: radare2 5.x, capa 7.x, pefile 2023.x, binwalk 2.3.x, exiftool 12.76