12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287acnanocore: 12deaec6 — Eighth confirmed Feb 2015 batch sibling (new88.exe)
Executive Summary
A 203 KB PE32 .NET assembly (new88.exe) that is a byte-identical build twin of the NanoCore RAT client v1.2.2.0 batch first observed in February 2015. Same timestamp, same ConfuserEx obfuscation layer, same VB.NET My Application Framework provenance, same high-entropy .rsrc payload. The only deltas from sibling fe81691f are the SHA-256, the MyTemplate GUID, and the filename. Static-only analysis — no Windows CAPE guest available. ^[file.txt] ^[strings.txt]
What It Is
| Property | Value | Provenance |
|---|---|---|
| SHA-256 | 12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac |
metadata.json |
| File name | new88.exe |
metadata.json |
| Size | 207,872 bytes (203 KB) | metadata.json |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | file.txt |
| Timestamp | Sun Feb 22 00:49:37 2015 UTC | pefile.txt:34 |
| Linker | .NET Framework v2.0.50727 (CLR 2.0) | strings.txt:51 |
| Language | Visual Basic .NET (My.Application framework) | strings.txt:1613-1618 |
| RAT version | NanoCore Client 1.2.2.0 | strings.txt:1626 |
| Obfuscator | ConfuserEx (massive #=q… mangling, ~1,000+ tokens) |
strings.txt:278+ |
| Signed | No | pefile.txt:153-154 |
| MyTemplate GUID | 2601925a-2b07-4fb7-aeb0-80126437ed67 |
strings.txt:1624 |
This sample is a confirmed twin of fe81691f (the first sibling in this cluster). Shared cluster analysis lives at nanocore; per-sample deltas are documented below. ^[/intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html]
How It Works
Loader / Startup
- Standard .NET EXE with a single import (
mscoree.dll!_CorExeMain). ^[pefile.txt:199] - CLR bootstrap reaches the VB.NET
My.Applicationentry point, spawning an invisibleClientLoaderForm(set_Visible,set_ShowInTaskbar,set_WindowState). ^[strings.txt:1610-1612] - The
IClientAppinterface is instantiated, wiring network, registry, and plugin layers. ^[strings.txt:86-97]
Obfuscation
- Name mangling: ConfuserEx has replaced every class, method, field, and property with
#=q…==identifiers. ~1,000+ mangled tokens in the binary. Blocks naive string clustering and decompiler readability. ^[strings.txt:278] - Resource encryption:
.rsrcis 90 KB with entropy 7.998. Contains an embedded ZIP archive (PK header observed within the section) — the ConfuserEx-encrypted plugin/config package. ^[pefile.txt:132] - No native packing: ConfuserEx operates entirely at the .NET layer; no UPX or custom native stub. ^[binwalk.txt]
Persistence & Installation (inferred — same as cluster)
- Self-copying via
get_StartupPath/set_CurrentDirectoryinto%AppData%or%TEMP%. ^[capa.txt:72-73] - Registry Run-key persistence via
RegistryKey,RegOpenKeyEx,RegQueryValueEx. ^[capa.txt:15,95-99] - File-system staging: create directory, copy file, delete file, write file. ^[capa.txt:73-84]
Network / C2 (inferred — same as cluster)
- No hardcoded IP, domain, or URL survived string extraction. Builder config is encrypted inside
.rsrc. ^[strings.txt:1400-1402] - Raw TCP sockets:
System.Net.Sockets.Socket,ConnectAsync,SendToServer,get_Connected. ^[strings.txt:172-181] - Mutable host cache:
DnsRecord,AddHostEntry,RebuildHostCache,GetHostEntry. ^[strings.txt:468-471] - Keepalive framing:
KeepAlivepresent in strings. ^[strings.txt:1116]
Plugin Architecture (same as cluster)
ClientPlugin,NanoCore.ClientPlugin,NanoCore.ClientPluginHostnamespaces. ^[strings.txt:61,91-94]- Task dispatch:
CommandType,BaseCommand,FileCommand,PluginCommand. ^[strings.txt:344-348] - Pipe-based IPC:
CreatePipe,PipeExists,PipeCreated,PipeClosed,ClosePipe,SendToServer. ^[strings.txt:459-465,1112-1113]
Decompiled Behavior
Radare2 CIL analysis identifies 858 functions — identical function count to sibling fe81691f. Entry point lands in:
method.ClientLoaderForm.Main— WinForms bootstrap.method.Client..ctor—Clientsingleton constructor wiringIClientAppto network layer.method.LogClientException/method.LogClientMessage— centralized logging forwarded to C2.
Control flow is dominated by ConfuserEx flattening and delegate trampolines. Manual decompilation is impractical without a de4dot/NoFuser pipeline. ^[rabin2-info.txt]
C2 Infrastructure
- Static C2: None extracted. Builder-encrypted
ClientSettings/BuilderSettingsblob lives inside the.rsrcZIP and is decrypted at runtime. ^[strings.txt:1400-1402] - Protocol: Raw TCP sockets with keepalive framing (not HTTP/HTTPS). ^[capa.txt:62-66]
- DNS / Host cache: Mutable; supports server-driven redirection via
AddHostEntry/RebuildHostCache. ^[strings.txt:468-471]
Interesting Tidbits
- Eighth confirmed sibling in the Feb 22 2015 00:49:37 UTC batch. The cluster now comprises:
fe81691f,48c8e8a2,d065ebea,4121d69c,0eedf3a8,cb2aa275,e48f1c56, and this sample (12deaec6). - Unique GUID:
MyTemplateGUID2601925a-2b07-4fb7-aeb0-80126437ed67differs fromfe81691f'sb4de0bbe-4fc1-4999-bc15-86136959e331, confirming per-sample builder generation even within the same batch second. ^[strings.txt:1624] - Filename:
new88.exeis a blunt, non-social-engineering name — no purchase-order or invoice masquerade. This contrasts with siblingd065ebea(hotro.exe, Vietnamese-themed) but aligns withfe81691f(okfun.exe) ande48f1c56(Backdoor.exe). - No YARA family hit: Only
PE_File_Generictriggered, same as the rest of the cluster. Open-source NanoCore YARA rules need updating for ConfuserEx-obfuscated VB.NET variants. ^[yara.txt] - floss failed: The pipeline's
flossinvocation used invalid--noargument syntax; no decoded strings were produced. This is a tooling artefact, not an anti-analysis measure. ^[floss.txt]
How To Mess With It (Homelab Replication)
See the cluster's primary analysis at fe81691f for the full replication recipe. The short form:
- Build a VB.NET WinForms app in Visual Studio with
System.Net.Sockets.TcpClientand a hidden startup form. - Store C2 config in
Properties.Resourcesas an encrypted JSON blob. - Pass the assembly through ConfuserEx v1.6.0 with name obfuscation, constant encryption, control-flow flattening, and resource encryption.
- Verify with
capa— should hitcommunication/socket/tcp,data-manipulation/hashing/md5,host-interaction/file-system/create, andhost-interaction/registry/create. - What you learn: ConfuserEx is free, mature, and trivial to apply. A de4dot replacement pipeline is mandatory for .NET malware analysis.
Deployable Signatures
YARA — NanoCore ConfuserEx VB.NET Variant (updated for cluster)
rule nanocore_confuserex_vbnet
{
meta:
description = "NanoCore RAT client obfuscated with ConfuserEx, VB.NET build"
author = "triage-auto"
date = "2026-08-02"
sha256 = "12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac"
strings:
$nano1 = "NanoCore Client" ascii wide
$nano2 = "NanoCore.ClientPlugin" ascii wide
$nano3 = "IClientApp" ascii wide
$nano4 = "IClientNetwork" ascii wide
$nano5 = "ClientLoaderForm" ascii wide
$nano6 = "SendToServer" ascii wide
$nano7 = "AddHostEntry" ascii wide
$nano8 = "PluginUninstalling" ascii wide
$conf1 = /#=q[A-Za-z0-9_$]{20,}==/
$conf2 = /#=q[A-Za-z0-9_$]{20,}=.*=/
$vb1 = "MyTemplate" ascii wide
$vb2 = "My.MyProject.Forms" ascii wide
$ver = "1.2.2.0" ascii wide
condition:
uint16(0) == 0x5A4D
and pe.number_of_sections == 3
and any of ($nano*)
and any of ($conf*)
and any of ($vb*)
and filesize < 500KB
}
Sigma — NanoCore Process Launch Hunt
title: NanoCore RAT Client Loader Execution
description: Detects NanoCore VB.NET client process based on module/interface strings and pipe creation.
logsource:
category: process_creation
product: windows
detection:
selection_strings:
CommandLine|contains|all:
- 'NanoCore'
- 'ClientLoaderForm'
selection_pipes:
CommandLine|contains:
- 'PipeCreated'
- 'PipeExists'
- 'CreatePipe'
selection_vb:
ImageLoaded|contains:
- 'Microsoft.VisualBasic'
- 'MyTemplate'
selection_mscoree:
CommandLine|endswith:
- '.exe'
condition: 1 of selection_strings or (selection_pipes and selection_vb)
falsepositives:
- Unknown
level: high
tags:
- attack.execution
- attack.t1059
- attack.command_and_control
- attack.t1071
IOC List
| Category | Indicator | Context |
|---|---|---|
| Hash | 12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac |
SHA-256 |
| Hash | 7caae6051783ef34f266fd844e15db01 |
MD5 |
| Hash | 5738032e33055dd6e6ebbf6b3787c7fbcc08b893 |
SHA-1 |
| Filename | new88.exe |
Original name |
| Registry | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
Persistence inferred |
| File | %TEMP%\*.tmp, %APPDATA%\* |
Staging inferred |
| Pipe | \.\pipe\* |
IPC bridge (CreatePipe, PipeExists) |
| Network | Raw TCP outbound (no static IP) | C2 host resolved via DNS / builder config |
| Mutex | Unknown — not extracted statically | Likely runtime-generated |
Behavioral Fingerprint
This binary is a .NET PE32 GUI assembly with a single mscoree.dll import. At startup it instantiates a hidden VB.NET WinForms client loader, initializes TCP socket objects, and maintains an internal C2 host cache. It creates file-system directories and copies itself, interacts with the registry for persistence, and uses anonymous/named pipes for internal plugin IPC. Network traffic is raw TCP with keepalive framing; no obfuscated HTTPS. The heavy ConfuserEx obfuscation (~1,000 mangled #=q… identifiers) blocks naive string extraction and decompilation. Builder version 1.2.2.0, compiled Feb 22 2015.
Detection Signatures (capa → ATT&CK)
capa static analysis mapped capabilities to ATT&CK: ^[capa.txt]
| capa Capability | ATT&CK Technique |
|---|---|
| modify registry | T1112 |
| reflective code loading | T1620 |
| account discovery | T1087 |
| file and directory discovery | T1083 |
| query registry | T1012 |
| system information discovery | T1082 |
| system owner/user discovery | T1033 |
| C2 communication (send/receive) | T1071 |
| DNS resolution | T1071.004 |
| create TCP socket | T1071 |
| MD5 hashing | — (crypto utility) |
| generate random numbers | — (utility) |
| copy file / create directory / delete file | T1070 |
| create process | T1106 |
| create mutex | — (single instance) |
| enumerate registry | T1012 |
| get session integrity level | T1033 |
| suspend thread | T1055 |
Dynamic execution would likely surface additional TTPs such as T1547.001 (Registry Run Keys), T1059.001 (PowerShell), and T1021 (Remote Services) depending on builder configuration.
References
- SHA-256:
12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac - Wiki entity: nanocore
- Wiki technique: confuserex-obfuscation
- Primary cluster sibling:
fe81691f— /intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html - OpenCTI labels:
nanocore,rat,malware-bazaar^[metadata.json] - Sample source: abuse.ch / MalwareBazaar (via OpenCTI
urlhaus-recent-payloadsconnector)
Provenance
- Report built from static artefacts generated by the triage pipeline on 2026-05-26.
- Tools:
file,strings,floss(failed — invalid args),capav5 (static, dotnet),binwalk,radare2(CIL analysis, 858 functions),pefile,exiftool,ssdeep,tlsh. - No CAPE dynamic analysis: Windows guest unavailable. All runtime/C2 claims are inferred from static imports, capa capability map, and known NanoCore builder behavior documented across the cluster.