typeanalysisfamilynanocoreconfidencehighcreated2026-08-08updated2026-08-08malware-familyratdotnetc2persistenceobfuscationconfuserex
SHA-256: 37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242

nanocore: 37509ef2 — Eleventh confirmed sibling, Nemo.exe masquerade, unique GUID 6d10e433

Executive Summary

An 88 KB ConfuserEx-obfuscated VB.NET NanoCore RAT client from the leaked-era builder v1.2.2.0, compiled 22 Feb 2015. This is the eleventh confirmed sibling in a builder-batch cluster spanning ten prior samples (fe81691f through f017a517). The only static deltas are the auto-generated My.Application GUID ($6d10e433-cda2-420f-9bab-c964ccf1d3ca), the encrypted RCData payload in .rsrc, and the original filename (Nemo.exe), which masquerades as a Disney/Finding Nemo themed executable. Static-only analysis — no CAPE detonation.

What It Is

Attribute Observation Source
SHA-256 37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242 metadata.json
Original filename Nemo.exe triage.json
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections file.txt
Size 207,872 bytes (203 KB on disk) pefile.txt
Compile timestamp Sun Feb 22 00:49:37 2015 UTC rabin2-info.txt
Builder version 1.2.2.0 strings.txt:1626
Language VB.NET (Visual Basic) — MyTemplate auto-generated class strings.txt:1613
Assembly GUID $6d10e433-cda2-420f-9bab-c964ccf1d3ca strings.txt:1624
Obfuscator ConfuserEx — 1,039 #=q…== mangled identifiers strings.txt (wc -l)
Framework .NET Framework 2.0 (CLR v2.0.50727) strings.txt:51
Signing Unsigned pefile.txt:199
IAT mscoree.dll._CorExeMain only pefile.txt:199

This sample is structurally identical to the ten confirmed NanoCore siblings documented at nanocore. Same compilation timestamp (22 Feb 2015 00:49:37 UTC), same builder version (1.2.2.0), same ConfuserEx obfuscation layer, same three-section PE layout (.text, .reloc, .rsrc), and same modular plugin-host interface surface (IClientApp, IClientNetwork, IClientUIHost, etc.). The only meaningful static deltas are the auto-generated GUID and the encrypted .rsrc payload.

How It Works

Cluster context. This is a cluster sibling — the threat logic, build pipeline, and behavioral fingerprint are documented on the nanocore entity page. The per-sample delta analysis below focuses on what makes 37509ef2 distinct from its ten siblings.

Filename masquerade. The original filename Nemo.exe (Disney's Finding Nemo) is a social-engineering lure targeting children or casual users, in contrast to the business-document lures (Backdoor.exe, hotro.exe, jp.exe) and emulator masquerades (EMU.exe) seen in prior siblings. This confirms the builder was used for varied distribution campaigns with thematically diverse filenames. ^[triage.json]

Encrypted RCData size. The .rsrc section contains a single RT_RCDATA entry (ID 1) of 88,928 bytes — slightly smaller than sibling f017a517 (89,960 bytes) and comparable to b6008cf6 (~90 KB). The payload is encrypted in-place; no hardcoded C2 strings, keys, or config blobs are recoverable statically. ^[pefile.txt:237-238]

No anti-analysis. No VM-detection, debug-check, or sandbox-gate strings are present. The only defense-evasion layer is the ConfuserEx IL obfuscation (#=q…== name mangling, resource encryption, control-flow flattening). ^[capa.txt:16]

VB.NET provenance. The MyTemplate auto-generated class and GUID $6d10e433-cda2-420f-9bab-c964ccf1d3ca prove the project was built with Visual Studio's VB.NET My Application Framework, not C#. The GUID is unique across all eleven confirmed siblings and serves as a per-build fingerprint. ^[strings.txt:1613] ^[strings.txt:1624]

Decompiled Behavior

Ghidra/pc decompilation not attempted — the binary is a .NET CIL assembly with ConfuserEx obfuscation (1,039 mangled names). Radare2 analysis (level 2) found 858 CIL functions and 465 symbols, all obfuscated. The meaningful behavior is inferable from:

  1. capa static detection — raw TCP socket C2, MD5 hashing, registry read/write, file system ops, process creation, mutex creation, thread suspension. ^[capa.txt]
  2. String table — the unobfuscated .NET metadata reveals the full plugin-host API surface (IClientApp, IClientNetwork, IClientDataHost, IClientUIHost, IClientLoggingHost, etc.) and network APIs (Socket, IPEndPoint, IPAddress, Dns, SocketAsyncEventArgs). ^[strings.txt:84-97] ^[strings.txt:168-180]
  3. No hardcoded C2 — host/port list is encrypted inside the RCData payload and resolved at runtime via AddHostEntry / RebuildHostCache. ^[strings.txt:468]

C2 Infrastructure

No static C2 recovered. The NanoCore builder encrypts the host list inside the .rsrc RCData payload. Runtime C2 is raw TCP (not HTTP/HTTPS) with builder-configured host/port pairs and keepalive framing. For the cluster's C2 behavior, see nanocore entity page. ^[capa.txt:62-66]

Interesting Tidbits

  • Disney masquerade: Nemo.exe is the first confirmed sibling with a children's-movie themed filename, expanding the known lure spectrum beyond business documents and emulator utilities. ^[triage.json]
  • Smallest RCData in cluster: 88,928 bytes vs 89,960 in f017a517. The ~1 KB difference is likely a shorter host list or fewer plugin modules in this build. ^[pefile.txt:238]
  • No YARA hits beyond generic PE: MalwareBazaar tagged it nanocore/rat; our YARA only matched PE_File_Generic. ConfuserEx obfuscation defeats family-specific string signatures. ^[yara.txt]
  • floss failure: The flare-floss run failed with an argument-parsing error (--no flag collision), so no decoded strings were produced. The unobfuscated metadata in #Strings is sufficient for family identification. ^[floss.txt]

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2013/2015 + VB.NET WinForms project + .NET Framework 2.0 target.

Compiler flags: Standard Debug/Release build. Enable "My Application Framework" in project properties (this auto-generates MyTemplate and a unique GUID).

Obfuscation: Pass the compiled EXE through ConfuserEx (open-source, .NET 4.x). Enable name mangling (#=q…==), resource encryption, and control-flow flattening.

Verification: Run capa on the output. You should see the same capability fingerprint as this sample: create TCP socket, hash data with MD5, query or enumerate registry key, create process in .NET, suspend thread, etc. Compare to capa.txt in this analysis directory.

What you'll learn: How a commodity .NET RAT builder packages plugins, encrypts config, and obfuscates IL to evade static signatures. The builder's output is structurally identical across samples — only the RCData payload and GUID differ.

Deployable Signatures

YARA Rule

rule nanocore_vbnet_confuserex_2015_batch
{
    meta:
        description = "NanoCore RAT client v1.2.2.0 — VB.NET ConfuserEx obfuscated, Feb 2015 builder batch"
        author      = "PacketPursuit"
        date        = "2026-08-08"
        version     = "1.0"
        hash        = "37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242"
        family      = "nanocore"

    strings:
        $vb1   = "MyTemplate" ascii wide
        $vb2   = "NanoCore Client" ascii wide
        $vb3   = "NanoCore Client.exe" ascii wide
        $vb4   = "1.2.2.0" ascii wide
        $iface1 = "IClientApp" ascii wide
        $iface2 = "IClientNetwork" ascii wide
        $iface3 = "IClientUIHost" ascii wide
        $iface4 = "IClientPluginHost" ascii wide
        $host1  = "AddHostEntry" ascii wide
        $host2  = "RebuildHostCache" ascii wide
        $conf1  = "#=q" ascii wide

    condition:
        uint16(0) == 0x5A4D
        and pe.number_of_sections == 3
        and pe.imports("mscoree.dll", "_CorExeMain")
        and ($vb1 or $vb2 or $vb3 or $vb4)
        and 2 of ($iface*)
        and #conf1 > 500
        and filesize < 250KB
}

Sigma Rule (process creation)

title: NanoCore RAT Client Execution — VB.NET ConfuserEx Batch
description: Detects execution of NanoCore RAT client with known builder artefacts
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - CommandLine|contains:
            - 'NanoCore Client.exe'
        - OriginalFileName:
            - 'NanoCore Client.exe'
        - Image|endswith:
            - '\Nemo.exe'
    condition: selection
falsepositives:
    - Unlikely — the filename and internal name are unique to the malware family.
level: high

IOC List

Indicator Type Value
SHA-256 Hash 37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242
MD5 Hash c3db1215f116879ae1799ec7d0f09073
SSDeep Hash 6144:MLV6Bta6dtJmakIM5fBGmPDZ1ZgJB6QUWlvH:MLV6BtpmkqBGmPDZ1gB65Wlv
Filename Artefact Nemo.exe
Internal name Artefact NanoCore Client.exe
Builder version Artefact 1.2.2.0
GUID Artefact $6d10e433-cda2-420f-9bab-c964ccf1d3ca
Compile timestamp Artefact 2015-02-22 00:49:37 UTC
Resource entry Artefact RT_RCDATA ID 1, 88,928 bytes
.NET runtime Artefact CLR v2.0.50727
IAT import Artefact mscoree.dll._CorExeMain (only import)

Behavioral Fingerprint

This binary is a .NET Framework 2.0 PE32 GUI executable compiled in VB.NET with the Visual Studio My Application Framework (evidenced by MyTemplate class and auto-generated GUID). It contains a single imported symbol (mscoree.dll._CorExeMain) and a three-section PE layout (.text, .reloc, .rsrc). The .rsrc section holds an 88,928-byte encrypted RCData payload. At runtime, the binary resolves its C2 host list from this encrypted resource, establishes raw TCP socket connections (not HTTP/HTTPS), and exposes a modular plugin architecture via named interfaces (IClientApp, IClientNetwork, IClientUIHost). It registers for auto-start via the Registry Run key and performs file-system self-copying. The IL is heavily obfuscated with ConfuserEx (#=q…== name mangling, 1,000+ instances). No VM-detection or anti-debug logic is present statically.

Detection Signatures (capa → ATT&CK)

capa Capability ATT&CK Technique
modify registry T1112
reflective code loading T1620
account discovery T1087
file and directory discovery T1083
query registry T1012
system information discovery T1082
system owner/user discovery T1033
hash data with MD5 T1001.002 (data obfuscation via hashing)
create TCP socket T1095
create or open mutex T1071.001
create process T1059
suspend thread T1055
set registry value T1547.001
delete registry value T1112
load .NET assembly T1620

References

  • nanocore — Family entity page with full cluster analysis and TTPs.
  • confuserex-obfuscation — Technique page for the primary obfuscator.
  • registry-run-persistence — Procedure page for the observed persistence mechanism.
  • MalwareBazaar artifact: 986fbd1f-00a4-4b80-8d83-ae5327332022

Provenance

  • file.txt — file(1) v5.44
  • pefile.txt — pefile v2023.2.7
  • rabin2-info.txt — radare2 v5.8.8
  • strings.txt — strings(1) from binutils
  • capa.txt — Mandiant capa v7.0.1 (static analysis)
  • floss.txt — flare-floss v2.3.0 (failed — argument parsing error)
  • binwalk.txt — binwalk v2.3.4
  • exiftool.json — ExifTool v12.76
  • triage.json — internal triage pipeline
  • metadata.json — OpenCTI artifact metadata