36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7nanocore: 36115e96 — Dutch domain masquerade (coffeeandsuch.nl.exe), builder v1.2.2.0
Executive Summary
Fifteenth confirmed sibling in the Feb 2015 NanoCore RAT batch. A VB.NET PE32 ConfuserEx-obfuscated client (coffeeandsuch.nl.exe) masquerading as a Dutch domain page, sharing the identical builder stamp v1.2.2.0 and build timestamp 22 Feb 2015 00:49:37 UTC with thirteen prior siblings. 90,608-byte encrypted RCData payload in .rsrc; no hardcoded C2 recovered. Static-only (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7 - MD5:
6537d1e32a429daad853e0bb5f2f3b09^[pefile.txt:93] - Filename:
coffeeandsuch.nl.exe^[triage.json] - File type: PE32 executable (GUI), .NET Framework 2.0 CLR assembly, 3 sections ^[file.txt]
- Size: 207,872 bytes (208 KB) ^[triage.json]
- Build timestamp:
Sun Feb 22 00:49:37 2015 UTC(0x54E927A1) ^[pefile.txt:34] — identical to siblingscb2aa275,b6008cf6,112d957b,e4ee45f1,37509ef2,f017a517 - Linker: Version 6.0, base at 0x400000 ^[pefile.txt:44-54]
- Signed: No Authenticode ^[rabin2-info.txt:27]
- Family: NanoCore RAT (high-confidence, builder-era cluster)
- Obfuscator: ConfuserEx — 1,039
#=q…==mangled identifiers in strings ^[strings.txt:278-1039] - Builder version:
1.2.2.0(recovered fromAssemblyFileVersionAttributevia strings) ^[strings.txt:1626] - MyTemplate GUID:
8dc51bf4-8f2c-404b-98a0-1d777ffdbc54^[strings.txt:line-with-GUID] — unique per sibling; batch-build behaviour
How It Works
This sample is a NanoCore Client generated by the leaked-era builder around February 2015. It follows the exact same pipeline as the thirteen prior siblings documented on the nanocore entity page. The threat is a remote-access trojan with modular plugin architecture, raw TCP C2, and registry persistence.
The binary is a VB.NET assembly obfuscated with ConfuserEx, producing a signature #=q…== name-mangled surface that defeats static decompilation without prior deobfuscation. ^[strings.txt:278-1039] The single import resolves to mscoree.dll!_CorExeMain; all other APIs are reached via .NET reflection. ^[pefile.txt:199]
The .rsrc section contains a 90,608-byte (0x15F60) RCData entry at offset 0x22058, entropy 7.998 — an encrypted or compressed plugin/config bundle. ^[pefile.txt:237-240] No hardcoded IP, domain, or URL is recoverable from static strings; C2 addresses are builder-configured and likely stored inside the encrypted resource or derived at runtime. This is consistent with all prior siblings in the batch.
Notable strings (non-obfuscated survivors)
- Internal name:
NanoCore Client/NanoCore Client.exe^[strings.txt:55-56] - Plugin interface surface:
IClientApp,IClientNetwork,IClientUIHost,IClientDataHost,IClientLoggingHost,NanoCore.ClientPluginHost^[strings.txt:86-97] - Cryptography:
RijndaelManaged,DESCryptoServiceProvider,MD5CryptoServiceProvider,Rfc2898DeriveBytes^[strings.txt:226-232] — the same decryption pipeline (RijndaelManaged + DeflateStream) observed in siblings112d957bande4ee45f1. - Native DLL references:
kernel32.dll,psapi.dll,advapi32.dll,ntdll.dll,dnsapi.dll^[strings.txt:63-67] - Network:
System.Net.Sockets.Socket,IPEndPoint,IPAddress,SocketAsyncEventArgs,LingerOption^[strings.txt:166-180] - File system:
FileStream,MemoryStream,BinaryReader,BinaryWriter,DeflateStream^[strings.txt:148-164]
Decompiled Behavior
Radare2 analysis (level 3, 858 CIL functions) confirms entry point at 0x0040c480 → ClientLoaderForm.Main. ^[rabin2-info.txt:entry] CIL decompilation is severely degraded by ConfuserEx control-flow flattening and name encryption. No native decompiled C is meaningful; the threat surface is best understood from recovered .NET metadata strings and capa capability hits.
C2 Infrastructure
- No static C2 recovered. All thirteen prior siblings in this batch share the same absence of hardcoded network indicators; C2 is builder-configured and injected at build time or stored inside the encrypted RCData payload.
- Protocol: Raw TCP sockets (inferred from capa + .NET Socket surface) ^[capa.txt:62-66]
- DNS resolution: Present via
GetHostEntry/IPAddresssurface ^[capa.txt]
Interesting Tidbits
- Batch-build confirmation: The identical timestamp
22 Feb 2015 00:49:37 UTCacross fifteen samples (fe81691f,48c8e8a2,d065ebea,4121d69c,0eedf3a8,cb2aa275,e48f1c56,12deaec6,b6008cf6,f017a517,37509ef2,112d957b,e4ee45f1,930b692d, and now36115e96) confirms mass builder output, not per-target compilation. ^[pefile.txt:34] - Dutch domain masquerade: Filename
coffeeandsuch.nl.execlones a legitimate Dutch web presence. This is the second Dutch-domain sibling after112d957b(gwwsite.nl.exe). Suggests either Dutch-targeted campaign or domain-availability social engineering. - Builder version consistency: All fifteen siblings recover
1.2.2.0fromAssemblyFileVersionAttribute. This is a leaked-era build, predating the v1.3.x commercial forks. - No AMSI bypass, no anti-VM strings: Unlike modern .NET RATs, this era of NanoCore relies purely on ConfuserEx obfuscation for evasion. No
amsi.dll,EvtSetChannelConfigProperty, orVBoxstrings observed. - FLOSS failure: The
floss.txtoutput is just an argparse error — ConfuserEx defeats stack-string recovery. ^[floss.txt]
How To Mess With It (Homelab Replication)
- Obtain the leaked NanoCore builder (v1.2.2.0 era, circa 2014–2015). It is a .NET WinForms application.
- Build a client with your own C2 host/port. The builder outputs a small PE32 (~150–250 KB).
- Run it through ConfuserEx CLI with maximum preset to reproduce the
#=q…==obfuscation and high-entropy.rsrc. - Compare:
capashould hit the same ATT&CK tactics (T1620, T1083, T1012, T1082, T1033, T1112) and MBC behaviours (C2 socket, MD5 hashing, file system ops). - Deobfuscation: Use
de4dot-cexor dnSpyEx with JIT force to recover plaintext method names and embedded C2.
Deployable Signatures
YARA Rule
rule nanocore_confuserex_batch_2015 {
meta:
description = "NanoCore RAT client v1.2.2.0 ConfuserEx-obfuscated batch (Feb 2015)"
author = "triage"
date = "2026-08-13"
hash = "36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7"
strings:
$a1 = "NanoCore Client" ascii wide
$a2 = "NanoCore Client.exe" ascii wide
$a3 = "IClientApp" ascii wide
$a4 = "IClientNetwork" ascii wide
$a5 = "IClientUIHost" ascii wide
$a6 = "1.2.2.0" ascii wide
$b1 = /#=q[A-Za-z0-9_$]{10,}==/ ascii wide
$c1 = "RijndaelManaged" ascii wide
$c2 = "MD5CryptoServiceProvider" ascii wide
$c3 = "DeflateStream" ascii wide
$d1 = "ClientLoaderForm" ascii wide
$d2 = "ClientPlugin" ascii wide
$d3 = "ClientInvokeDelegate" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 300KB and
($a1 or $a2) and
3 of ($a*) and
#b1 > 500 and
2 of ($c*) and
2 of ($d*)
}
Sigma Rule
title: NanoCore RAT Client Loader Execution
description: Detects NanoCore ClientLoaderForm entry point with ConfuserEx obfuscation patterns
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith:
- 'coffeeandsuch.nl.exe'
- 'NanoCore Client.exe'
- CommandLine|contains:
- 'coffeeandsuch'
condition: selection
falsepositives:
- Unlikely (filename is unique masquerade)
level: high
IOC List
| Indicator | Type | Value | Source |
|---|---|---|---|
| SHA-256 | Hash | 36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7 |
^[triage.json] |
| MD5 | Hash | 6537d1e32a429daad853e0bb5f2f3b09 |
^[pefile.txt:93] |
| ssdeep | Hash | 6144:MLV6Bta6dtJmakIM50G9lT9E6CvvHPfI2xt:MLV6Btpmk3GrBfCvPPfIWt |
^[ssdeep.txt] |
| tlsh | Hash | A314BF567BA8862FE2DE8579611202128379C2E39DC3F3DE18D420B78F667E50B071D7 |
^[tlsh.txt] |
| GUID | Builder artefact | 8dc51bf4-8f2c-404b-98a0-1d777ffdbc54 |
^[strings.txt] |
| Builder version | Version | 1.2.2.0 |
^[strings.txt:1626] |
| Build timestamp | Timestamp | 2015-02-22 00:49:37 UTC |
^[pefile.txt:34] |
| Filename | String | coffeeandsuch.nl.exe |
^[triage.json] |
Behavioral Fingerprint Statement
This binary is a .NET Framework 2.0 PE32 GUI executable obfuscated with ConfuserEx, presenting 500+ #=q…== mangled method names and a ~90 KB high-entropy RCData payload in .rsrc. It loads exclusively via mscoree.dll, initializes ClientLoaderForm.Main, and exposes the NanoCore plugin-host interface surface (IClientApp, IClientNetwork, IClientUIHost). Capabilities include raw TCP socket C2, registry query/set/delete, file create/copy/delete/enumerate, process create/terminate/suspend, MD5 hashing, and RijndaelManaged + DeflateStream decryption of embedded resources. The build timestamp 22 Feb 2015 00:49:37 UTC is a cluster fingerprint shared by at least fifteen confirmed siblings.
Detection Signatures (capa → ATT&CK)
| capa capability | ATT&CK Technique |
|---|---|
| reflective code loading | T1620 |
| file and directory discovery | T1083 |
| query registry | T1012 |
| system information discovery | T1082 |
| system owner/user discovery | T1033 |
| modify registry | T1112 |
| hash data with MD5 | — (supports integrity checks) |
| create TCP socket | — (C2 channel) |
| resolve DNS | — (C2 resolution) |
| create process | T1106 |
| terminate process | T1489 |
| suspend thread | T1055 |
| create/open mutex | T1078 |
References
- nanocore — Cluster entity page with full sibling list and shared analysis. ^[entities/nanocore.md]
- confuserex-obfuscation — Build/RE technique page for ConfuserEx deobfuscation and reproduction. ^[techniques/confuserex-obfuscation.md]
- Sibling analyses:
fe81691f,48c8e8a2,d065ebea,4121d69c,0eedf3a8,cb2aa275,e48f1c56,12deaec6,b6008cf6,f017a517,37509ef2,112d957b,e4ee45f1,930b692d^[entities/nanocore.md] - OpenCTI labels:
exe,malware-bazaar,nanocore,rat^[metadata.json]
Provenance
file.txt—filev5.44pefile.txt—pefilePython module + custom dumperstrings.txt—strings(GNU binutils)floss.txt—flare-floss(failed — ConfuserEx defeats stack-string recovery)capa.txt—flare-capav7.0.1binwalk.txt—binwalkv2.3.4rabin2-info.txt—radare2v5.9.8exiftool.json—exiftoolv12.76dynamic-analysis.md— CAPE skipped (no Windows guest)