typeanalysisfamilynanocoreconfidencehighcreated2026-08-02updated2026-08-02dotnetmalware-familyratc2obfuscationpersistence
SHA-256: 12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac

nanocore: 12deaec6 — Eighth confirmed Feb 2015 batch sibling (new88.exe)

Executive Summary

A 203 KB PE32 .NET assembly (new88.exe) that is a byte-identical build twin of the NanoCore RAT client v1.2.2.0 batch first observed in February 2015. Same timestamp, same ConfuserEx obfuscation layer, same VB.NET My Application Framework provenance, same high-entropy .rsrc payload. The only deltas from sibling fe81691f are the SHA-256, the MyTemplate GUID, and the filename. Static-only analysis — no Windows CAPE guest available. ^[file.txt] ^[strings.txt]

What It Is

Property Value Provenance
SHA-256 12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac metadata.json
File name new88.exe metadata.json
Size 207,872 bytes (203 KB) metadata.json
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections file.txt
Timestamp Sun Feb 22 00:49:37 2015 UTC pefile.txt:34
Linker .NET Framework v2.0.50727 (CLR 2.0) strings.txt:51
Language Visual Basic .NET (My.Application framework) strings.txt:1613-1618
RAT version NanoCore Client 1.2.2.0 strings.txt:1626
Obfuscator ConfuserEx (massive #=q… mangling, ~1,000+ tokens) strings.txt:278+
Signed No pefile.txt:153-154
MyTemplate GUID 2601925a-2b07-4fb7-aeb0-80126437ed67 strings.txt:1624

This sample is a confirmed twin of fe81691f (the first sibling in this cluster). Shared cluster analysis lives at nanocore; per-sample deltas are documented below. ^[/intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html]

How It Works

Loader / Startup

  1. Standard .NET EXE with a single import (mscoree.dll!_CorExeMain). ^[pefile.txt:199]
  2. CLR bootstrap reaches the VB.NET My.Application entry point, spawning an invisible ClientLoaderForm (set_Visible, set_ShowInTaskbar, set_WindowState). ^[strings.txt:1610-1612]
  3. The IClientApp interface is instantiated, wiring network, registry, and plugin layers. ^[strings.txt:86-97]

Obfuscation

  • Name mangling: ConfuserEx has replaced every class, method, field, and property with #=q…== identifiers. ~1,000+ mangled tokens in the binary. Blocks naive string clustering and decompiler readability. ^[strings.txt:278]
  • Resource encryption: .rsrc is 90 KB with entropy 7.998. Contains an embedded ZIP archive (PK header observed within the section) — the ConfuserEx-encrypted plugin/config package. ^[pefile.txt:132]
  • No native packing: ConfuserEx operates entirely at the .NET layer; no UPX or custom native stub. ^[binwalk.txt]

Persistence & Installation (inferred — same as cluster)

  • Self-copying via get_StartupPath / set_CurrentDirectory into %AppData% or %TEMP%. ^[capa.txt:72-73]
  • Registry Run-key persistence via RegistryKey, RegOpenKeyEx, RegQueryValueEx. ^[capa.txt:15,95-99]
  • File-system staging: create directory, copy file, delete file, write file. ^[capa.txt:73-84]

Network / C2 (inferred — same as cluster)

  • No hardcoded IP, domain, or URL survived string extraction. Builder config is encrypted inside .rsrc. ^[strings.txt:1400-1402]
  • Raw TCP sockets: System.Net.Sockets.Socket, ConnectAsync, SendToServer, get_Connected. ^[strings.txt:172-181]
  • Mutable host cache: DnsRecord, AddHostEntry, RebuildHostCache, GetHostEntry. ^[strings.txt:468-471]
  • Keepalive framing: KeepAlive present in strings. ^[strings.txt:1116]

Plugin Architecture (same as cluster)

  • ClientPlugin, NanoCore.ClientPlugin, NanoCore.ClientPluginHost namespaces. ^[strings.txt:61,91-94]
  • Task dispatch: CommandType, BaseCommand, FileCommand, PluginCommand. ^[strings.txt:344-348]
  • Pipe-based IPC: CreatePipe, PipeExists, PipeCreated, PipeClosed, ClosePipe, SendToServer. ^[strings.txt:459-465,1112-1113]

Decompiled Behavior

Radare2 CIL analysis identifies 858 functions — identical function count to sibling fe81691f. Entry point lands in:

  • method.ClientLoaderForm.Main — WinForms bootstrap.
  • method.Client..ctor — Client singleton constructor wiring IClientApp to network layer.
  • method.LogClientException / method.LogClientMessage — centralized logging forwarded to C2.

Control flow is dominated by ConfuserEx flattening and delegate trampolines. Manual decompilation is impractical without a de4dot/NoFuser pipeline. ^[rabin2-info.txt]

C2 Infrastructure

  • Static C2: None extracted. Builder-encrypted ClientSettings / BuilderSettings blob lives inside the .rsrc ZIP and is decrypted at runtime. ^[strings.txt:1400-1402]
  • Protocol: Raw TCP sockets with keepalive framing (not HTTP/HTTPS). ^[capa.txt:62-66]
  • DNS / Host cache: Mutable; supports server-driven redirection via AddHostEntry / RebuildHostCache. ^[strings.txt:468-471]

Interesting Tidbits

  1. Eighth confirmed sibling in the Feb 22 2015 00:49:37 UTC batch. The cluster now comprises: fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8, cb2aa275, e48f1c56, and this sample (12deaec6).
  2. Unique GUID: MyTemplate GUID 2601925a-2b07-4fb7-aeb0-80126437ed67 differs from fe81691f's b4de0bbe-4fc1-4999-bc15-86136959e331, confirming per-sample builder generation even within the same batch second. ^[strings.txt:1624]
  3. Filename: new88.exe is a blunt, non-social-engineering name — no purchase-order or invoice masquerade. This contrasts with sibling d065ebea (hotro.exe, Vietnamese-themed) but aligns with fe81691f (okfun.exe) and e48f1c56 (Backdoor.exe).
  4. No YARA family hit: Only PE_File_Generic triggered, same as the rest of the cluster. Open-source NanoCore YARA rules need updating for ConfuserEx-obfuscated VB.NET variants. ^[yara.txt]
  5. floss failed: The pipeline's floss invocation used invalid --no argument syntax; no decoded strings were produced. This is a tooling artefact, not an anti-analysis measure. ^[floss.txt]

How To Mess With It (Homelab Replication)

See the cluster's primary analysis at fe81691f for the full replication recipe. The short form:

  1. Build a VB.NET WinForms app in Visual Studio with System.Net.Sockets.TcpClient and a hidden startup form.
  2. Store C2 config in Properties.Resources as an encrypted JSON blob.
  3. Pass the assembly through ConfuserEx v1.6.0 with name obfuscation, constant encryption, control-flow flattening, and resource encryption.
  4. Verify with capa — should hit communication/socket/tcp, data-manipulation/hashing/md5, host-interaction/file-system/create, and host-interaction/registry/create.
  5. What you learn: ConfuserEx is free, mature, and trivial to apply. A de4dot replacement pipeline is mandatory for .NET malware analysis.

Deployable Signatures

YARA — NanoCore ConfuserEx VB.NET Variant (updated for cluster)

rule nanocore_confuserex_vbnet
{
    meta:
        description = "NanoCore RAT client obfuscated with ConfuserEx, VB.NET build"
        author      = "triage-auto"
        date        = "2026-08-02"
        sha256      = "12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac"
    strings:
        $nano1 = "NanoCore Client" ascii wide
        $nano2 = "NanoCore.ClientPlugin" ascii wide
        $nano3 = "IClientApp" ascii wide
        $nano4 = "IClientNetwork" ascii wide
        $nano5 = "ClientLoaderForm" ascii wide
        $nano6 = "SendToServer" ascii wide
        $nano7 = "AddHostEntry" ascii wide
        $nano8 = "PluginUninstalling" ascii wide
        $conf1 = /#=q[A-Za-z0-9_$]{20,}==/
        $conf2 = /#=q[A-Za-z0-9_$]{20,}=.*=/
        $vb1   = "MyTemplate" ascii wide
        $vb2   = "My.MyProject.Forms" ascii wide
        $ver   = "1.2.2.0" ascii wide
    condition:
        uint16(0) == 0x5A4D
        and pe.number_of_sections == 3
        and any of ($nano*)
        and any of ($conf*)
        and any of ($vb*)
        and filesize < 500KB
}

Sigma — NanoCore Process Launch Hunt

title: NanoCore RAT Client Loader Execution
description: Detects NanoCore VB.NET client process based on module/interface strings and pipe creation.
logsource:
    category: process_creation
    product: windows
detection:
    selection_strings:
        CommandLine|contains|all:
            - 'NanoCore'
            - 'ClientLoaderForm'
    selection_pipes:
        CommandLine|contains:
            - 'PipeCreated'
            - 'PipeExists'
            - 'CreatePipe'
    selection_vb:
        ImageLoaded|contains:
            - 'Microsoft.VisualBasic'
            - 'MyTemplate'
    selection_mscoree:
        CommandLine|endswith:
            - '.exe'
    condition: 1 of selection_strings or (selection_pipes and selection_vb)
falsepositives:
    - Unknown
level: high
tags:
    - attack.execution
    - attack.t1059
    - attack.command_and_control
    - attack.t1071

IOC List

Category Indicator Context
Hash 12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac SHA-256
Hash 7caae6051783ef34f266fd844e15db01 MD5
Hash 5738032e33055dd6e6ebbf6b3787c7fbcc08b893 SHA-1
Filename new88.exe Original name
Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run Persistence inferred
File %TEMP%\*.tmp, %APPDATA%\* Staging inferred
Pipe \.\pipe\* IPC bridge (CreatePipe, PipeExists)
Network Raw TCP outbound (no static IP) C2 host resolved via DNS / builder config
Mutex Unknown — not extracted statically Likely runtime-generated

Behavioral Fingerprint

This binary is a .NET PE32 GUI assembly with a single mscoree.dll import. At startup it instantiates a hidden VB.NET WinForms client loader, initializes TCP socket objects, and maintains an internal C2 host cache. It creates file-system directories and copies itself, interacts with the registry for persistence, and uses anonymous/named pipes for internal plugin IPC. Network traffic is raw TCP with keepalive framing; no obfuscated HTTPS. The heavy ConfuserEx obfuscation (~1,000 mangled #=q… identifiers) blocks naive string extraction and decompilation. Builder version 1.2.2.0, compiled Feb 22 2015.

Detection Signatures (capa → ATT&CK)

capa static analysis mapped capabilities to ATT&CK: ^[capa.txt]

capa Capability ATT&CK Technique
modify registry T1112
reflective code loading T1620
account discovery T1087
file and directory discovery T1083
query registry T1012
system information discovery T1082
system owner/user discovery T1033
C2 communication (send/receive) T1071
DNS resolution T1071.004
create TCP socket T1071
MD5 hashing — (crypto utility)
generate random numbers — (utility)
copy file / create directory / delete file T1070
create process T1106
create mutex — (single instance)
enumerate registry T1012
get session integrity level T1033
suspend thread T1055

Dynamic execution would likely surface additional TTPs such as T1547.001 (Registry Run Keys), T1059.001 (PowerShell), and T1021 (Remote Services) depending on builder configuration.

References

  • SHA-256: 12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac
  • Wiki entity: nanocore
  • Wiki technique: confuserex-obfuscation
  • Primary cluster sibling: fe81691f — /intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html
  • OpenCTI labels: nanocore, rat, malware-bazaar ^[metadata.json]
  • Sample source: abuse.ch / MalwareBazaar (via OpenCTI urlhaus-recent-payloads connector)

Provenance

  • Report built from static artefacts generated by the triage pipeline on 2026-05-26.
  • Tools: file, strings, floss (failed — invalid args), capa v5 (static, dotnet), binwalk, radare2 (CIL analysis, 858 functions), pefile, exiftool, ssdeep, tlsh.
  • No CAPE dynamic analysis: Windows guest unavailable. All runtime/C2 claims are inferred from static imports, capa capability map, and known NanoCore builder behavior documented across the cluster.