typeanalysisfamilynanocoreconfidencehighcreated2026-08-13updated2026-08-13malware-familyratdotnetobfuscationc2persistence
SHA-256: 36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7

nanocore: 36115e96 — Dutch domain masquerade (coffeeandsuch.nl.exe), builder v1.2.2.0

Executive Summary

Fifteenth confirmed sibling in the Feb 2015 NanoCore RAT batch. A VB.NET PE32 ConfuserEx-obfuscated client (coffeeandsuch.nl.exe) masquerading as a Dutch domain page, sharing the identical builder stamp v1.2.2.0 and build timestamp 22 Feb 2015 00:49:37 UTC with thirteen prior siblings. 90,608-byte encrypted RCData payload in .rsrc; no hardcoded C2 recovered. Static-only (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: 36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7
  • MD5: 6537d1e32a429daad853e0bb5f2f3b09 ^[pefile.txt:93]
  • Filename: coffeeandsuch.nl.exe ^[triage.json]
  • File type: PE32 executable (GUI), .NET Framework 2.0 CLR assembly, 3 sections ^[file.txt]
  • Size: 207,872 bytes (208 KB) ^[triage.json]
  • Build timestamp: Sun Feb 22 00:49:37 2015 UTC (0x54E927A1) ^[pefile.txt:34] — identical to siblings cb2aa275, b6008cf6, 112d957b, e4ee45f1, 37509ef2, f017a517
  • Linker: Version 6.0, base at 0x400000 ^[pefile.txt:44-54]
  • Signed: No Authenticode ^[rabin2-info.txt:27]
  • Family: NanoCore RAT (high-confidence, builder-era cluster)
  • Obfuscator: ConfuserEx — 1,039 #=q…== mangled identifiers in strings ^[strings.txt:278-1039]
  • Builder version: 1.2.2.0 (recovered from AssemblyFileVersionAttribute via strings) ^[strings.txt:1626]
  • MyTemplate GUID: 8dc51bf4-8f2c-404b-98a0-1d777ffdbc54 ^[strings.txt:line-with-GUID] — unique per sibling; batch-build behaviour

How It Works

This sample is a NanoCore Client generated by the leaked-era builder around February 2015. It follows the exact same pipeline as the thirteen prior siblings documented on the nanocore entity page. The threat is a remote-access trojan with modular plugin architecture, raw TCP C2, and registry persistence.

The binary is a VB.NET assembly obfuscated with ConfuserEx, producing a signature #=q…== name-mangled surface that defeats static decompilation without prior deobfuscation. ^[strings.txt:278-1039] The single import resolves to mscoree.dll!_CorExeMain; all other APIs are reached via .NET reflection. ^[pefile.txt:199]

The .rsrc section contains a 90,608-byte (0x15F60) RCData entry at offset 0x22058, entropy 7.998 — an encrypted or compressed plugin/config bundle. ^[pefile.txt:237-240] No hardcoded IP, domain, or URL is recoverable from static strings; C2 addresses are builder-configured and likely stored inside the encrypted resource or derived at runtime. This is consistent with all prior siblings in the batch.

Notable strings (non-obfuscated survivors)

  • Internal name: NanoCore Client / NanoCore Client.exe ^[strings.txt:55-56]
  • Plugin interface surface: IClientApp, IClientNetwork, IClientUIHost, IClientDataHost, IClientLoggingHost, NanoCore.ClientPluginHost ^[strings.txt:86-97]
  • Cryptography: RijndaelManaged, DESCryptoServiceProvider, MD5CryptoServiceProvider, Rfc2898DeriveBytes ^[strings.txt:226-232] — the same decryption pipeline (RijndaelManaged + DeflateStream) observed in siblings 112d957b and e4ee45f1.
  • Native DLL references: kernel32.dll, psapi.dll, advapi32.dll, ntdll.dll, dnsapi.dll ^[strings.txt:63-67]
  • Network: System.Net.Sockets.Socket, IPEndPoint, IPAddress, SocketAsyncEventArgs, LingerOption ^[strings.txt:166-180]
  • File system: FileStream, MemoryStream, BinaryReader, BinaryWriter, DeflateStream ^[strings.txt:148-164]

Decompiled Behavior

Radare2 analysis (level 3, 858 CIL functions) confirms entry point at 0x0040c480 → ClientLoaderForm.Main. ^[rabin2-info.txt:entry] CIL decompilation is severely degraded by ConfuserEx control-flow flattening and name encryption. No native decompiled C is meaningful; the threat surface is best understood from recovered .NET metadata strings and capa capability hits.

C2 Infrastructure

  • No static C2 recovered. All thirteen prior siblings in this batch share the same absence of hardcoded network indicators; C2 is builder-configured and injected at build time or stored inside the encrypted RCData payload.
  • Protocol: Raw TCP sockets (inferred from capa + .NET Socket surface) ^[capa.txt:62-66]
  • DNS resolution: Present via GetHostEntry / IPAddress surface ^[capa.txt]

Interesting Tidbits

  • Batch-build confirmation: The identical timestamp 22 Feb 2015 00:49:37 UTC across fifteen samples (fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8, cb2aa275, e48f1c56, 12deaec6, b6008cf6, f017a517, 37509ef2, 112d957b, e4ee45f1, 930b692d, and now 36115e96) confirms mass builder output, not per-target compilation. ^[pefile.txt:34]
  • Dutch domain masquerade: Filename coffeeandsuch.nl.exe clones a legitimate Dutch web presence. This is the second Dutch-domain sibling after 112d957b (gwwsite.nl.exe). Suggests either Dutch-targeted campaign or domain-availability social engineering.
  • Builder version consistency: All fifteen siblings recover 1.2.2.0 from AssemblyFileVersionAttribute. This is a leaked-era build, predating the v1.3.x commercial forks.
  • No AMSI bypass, no anti-VM strings: Unlike modern .NET RATs, this era of NanoCore relies purely on ConfuserEx obfuscation for evasion. No amsi.dll, EvtSetChannelConfigProperty, or VBox strings observed.
  • FLOSS failure: The floss.txt output is just an argparse error — ConfuserEx defeats stack-string recovery. ^[floss.txt]

How To Mess With It (Homelab Replication)

  1. Obtain the leaked NanoCore builder (v1.2.2.0 era, circa 2014–2015). It is a .NET WinForms application.
  2. Build a client with your own C2 host/port. The builder outputs a small PE32 (~150–250 KB).
  3. Run it through ConfuserEx CLI with maximum preset to reproduce the #=q…== obfuscation and high-entropy .rsrc.
  4. Compare: capa should hit the same ATT&CK tactics (T1620, T1083, T1012, T1082, T1033, T1112) and MBC behaviours (C2 socket, MD5 hashing, file system ops).
  5. Deobfuscation: Use de4dot-cex or dnSpyEx with JIT force to recover plaintext method names and embedded C2.

Deployable Signatures

YARA Rule

rule nanocore_confuserex_batch_2015 {
    meta:
        description = "NanoCore RAT client v1.2.2.0 ConfuserEx-obfuscated batch (Feb 2015)"
        author = "triage"
        date = "2026-08-13"
        hash = "36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7"
    strings:
        $a1 = "NanoCore Client" ascii wide
        $a2 = "NanoCore Client.exe" ascii wide
        $a3 = "IClientApp" ascii wide
        $a4 = "IClientNetwork" ascii wide
        $a5 = "IClientUIHost" ascii wide
        $a6 = "1.2.2.0" ascii wide
        $b1 = /#=q[A-Za-z0-9_$]{10,}==/ ascii wide
        $c1 = "RijndaelManaged" ascii wide
        $c2 = "MD5CryptoServiceProvider" ascii wide
        $c3 = "DeflateStream" ascii wide
        $d1 = "ClientLoaderForm" ascii wide
        $d2 = "ClientPlugin" ascii wide
        $d3 = "ClientInvokeDelegate" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 300KB and
        ($a1 or $a2) and
        3 of ($a*) and
        #b1 > 500 and
        2 of ($c*) and
        2 of ($d*)
}

Sigma Rule

title: NanoCore RAT Client Loader Execution
description: Detects NanoCore ClientLoaderForm entry point with ConfuserEx obfuscation patterns
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Image|endswith:
            - 'coffeeandsuch.nl.exe'
            - 'NanoCore Client.exe'
        - CommandLine|contains:
            - 'coffeeandsuch'
    condition: selection
falsepositives:
    - Unlikely (filename is unique masquerade)
level: high

IOC List

Indicator Type Value Source
SHA-256 Hash 36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7 ^[triage.json]
MD5 Hash 6537d1e32a429daad853e0bb5f2f3b09 ^[pefile.txt:93]
ssdeep Hash 6144:MLV6Bta6dtJmakIM50G9lT9E6CvvHPfI2xt:MLV6Btpmk3GrBfCvPPfIWt ^[ssdeep.txt]
tlsh Hash A314BF567BA8862FE2DE8579611202128379C2E39DC3F3DE18D420B78F667E50B071D7 ^[tlsh.txt]
GUID Builder artefact 8dc51bf4-8f2c-404b-98a0-1d777ffdbc54 ^[strings.txt]
Builder version Version 1.2.2.0 ^[strings.txt:1626]
Build timestamp Timestamp 2015-02-22 00:49:37 UTC ^[pefile.txt:34]
Filename String coffeeandsuch.nl.exe ^[triage.json]

Behavioral Fingerprint Statement

This binary is a .NET Framework 2.0 PE32 GUI executable obfuscated with ConfuserEx, presenting 500+ #=q…== mangled method names and a ~90 KB high-entropy RCData payload in .rsrc. It loads exclusively via mscoree.dll, initializes ClientLoaderForm.Main, and exposes the NanoCore plugin-host interface surface (IClientApp, IClientNetwork, IClientUIHost). Capabilities include raw TCP socket C2, registry query/set/delete, file create/copy/delete/enumerate, process create/terminate/suspend, MD5 hashing, and RijndaelManaged + DeflateStream decryption of embedded resources. The build timestamp 22 Feb 2015 00:49:37 UTC is a cluster fingerprint shared by at least fifteen confirmed siblings.

Detection Signatures (capa → ATT&CK)

capa capability ATT&CK Technique
reflective code loading T1620
file and directory discovery T1083
query registry T1012
system information discovery T1082
system owner/user discovery T1033
modify registry T1112
hash data with MD5 — (supports integrity checks)
create TCP socket — (C2 channel)
resolve DNS — (C2 resolution)
create process T1106
terminate process T1489
suspend thread T1055
create/open mutex T1078

References

  • nanocore — Cluster entity page with full sibling list and shared analysis. ^[entities/nanocore.md]
  • confuserex-obfuscation — Build/RE technique page for ConfuserEx deobfuscation and reproduction. ^[techniques/confuserex-obfuscation.md]
  • Sibling analyses: fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8, cb2aa275, e48f1c56, 12deaec6, b6008cf6, f017a517, 37509ef2, 112d957b, e4ee45f1, 930b692d ^[entities/nanocore.md]
  • OpenCTI labels: exe, malware-bazaar, nanocore, rat ^[metadata.json]

Provenance

  • file.txt — file v5.44
  • pefile.txt — pefile Python module + custom dumper
  • strings.txt — strings (GNU binutils)
  • floss.txt — flare-floss (failed — ConfuserEx defeats stack-string recovery)
  • capa.txt — flare-capa v7.0.1
  • binwalk.txt — binwalk v2.3.4
  • rabin2-info.txt — radare2 v5.9.8
  • exiftool.json — exiftool v12.76
  • dynamic-analysis.md — CAPE skipped (no Windows guest)