37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242nanocore: 37509ef2 — Eleventh confirmed sibling, Nemo.exe masquerade, unique GUID 6d10e433
Executive Summary
An 88 KB ConfuserEx-obfuscated VB.NET NanoCore RAT client from the leaked-era builder v1.2.2.0, compiled 22 Feb 2015. This is the eleventh confirmed sibling in a builder-batch cluster spanning ten prior samples (fe81691f through f017a517). The only static deltas are the auto-generated My.Application GUID ($6d10e433-cda2-420f-9bab-c964ccf1d3ca), the encrypted RCData payload in .rsrc, and the original filename (Nemo.exe), which masquerades as a Disney/Finding Nemo themed executable. Static-only analysis — no CAPE detonation.
What It Is
| Attribute | Observation | Source |
|---|---|---|
| SHA-256 | 37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242 |
metadata.json |
| Original filename | Nemo.exe |
triage.json |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | file.txt |
| Size | 207,872 bytes (203 KB on disk) | pefile.txt |
| Compile timestamp | Sun Feb 22 00:49:37 2015 UTC | rabin2-info.txt |
| Builder version | 1.2.2.0 |
strings.txt:1626 |
| Language | VB.NET (Visual Basic) — MyTemplate auto-generated class |
strings.txt:1613 |
| Assembly GUID | $6d10e433-cda2-420f-9bab-c964ccf1d3ca |
strings.txt:1624 |
| Obfuscator | ConfuserEx — 1,039 #=q…== mangled identifiers |
strings.txt (wc -l) |
| Framework | .NET Framework 2.0 (CLR v2.0.50727) | strings.txt:51 |
| Signing | Unsigned | pefile.txt:199 |
| IAT | mscoree.dll._CorExeMain only |
pefile.txt:199 |
This sample is structurally identical to the ten confirmed NanoCore siblings documented at nanocore. Same compilation timestamp (22 Feb 2015 00:49:37 UTC), same builder version (1.2.2.0), same ConfuserEx obfuscation layer, same three-section PE layout (.text, .reloc, .rsrc), and same modular plugin-host interface surface (IClientApp, IClientNetwork, IClientUIHost, etc.). The only meaningful static deltas are the auto-generated GUID and the encrypted .rsrc payload.
How It Works
Cluster context. This is a cluster sibling — the threat logic, build pipeline, and behavioral fingerprint are documented on the nanocore entity page. The per-sample delta analysis below focuses on what makes 37509ef2 distinct from its ten siblings.
Filename masquerade. The original filename Nemo.exe (Disney's Finding Nemo) is a social-engineering lure targeting children or casual users, in contrast to the business-document lures (Backdoor.exe, hotro.exe, jp.exe) and emulator masquerades (EMU.exe) seen in prior siblings. This confirms the builder was used for varied distribution campaigns with thematically diverse filenames. ^[triage.json]
Encrypted RCData size. The .rsrc section contains a single RT_RCDATA entry (ID 1) of 88,928 bytes — slightly smaller than sibling f017a517 (89,960 bytes) and comparable to b6008cf6 (~90 KB). The payload is encrypted in-place; no hardcoded C2 strings, keys, or config blobs are recoverable statically. ^[pefile.txt:237-238]
No anti-analysis. No VM-detection, debug-check, or sandbox-gate strings are present. The only defense-evasion layer is the ConfuserEx IL obfuscation (#=q…== name mangling, resource encryption, control-flow flattening). ^[capa.txt:16]
VB.NET provenance. The MyTemplate auto-generated class and GUID $6d10e433-cda2-420f-9bab-c964ccf1d3ca prove the project was built with Visual Studio's VB.NET My Application Framework, not C#. The GUID is unique across all eleven confirmed siblings and serves as a per-build fingerprint. ^[strings.txt:1613] ^[strings.txt:1624]
Decompiled Behavior
Ghidra/pc decompilation not attempted — the binary is a .NET CIL assembly with ConfuserEx obfuscation (1,039 mangled names). Radare2 analysis (level 2) found 858 CIL functions and 465 symbols, all obfuscated. The meaningful behavior is inferable from:
- capa static detection — raw TCP socket C2, MD5 hashing, registry read/write, file system ops, process creation, mutex creation, thread suspension. ^[capa.txt]
- String table — the unobfuscated .NET metadata reveals the full plugin-host API surface (
IClientApp,IClientNetwork,IClientDataHost,IClientUIHost,IClientLoggingHost, etc.) and network APIs (Socket,IPEndPoint,IPAddress,Dns,SocketAsyncEventArgs). ^[strings.txt:84-97] ^[strings.txt:168-180] - No hardcoded C2 — host/port list is encrypted inside the RCData payload and resolved at runtime via
AddHostEntry/RebuildHostCache. ^[strings.txt:468]
C2 Infrastructure
No static C2 recovered. The NanoCore builder encrypts the host list inside the .rsrc RCData payload. Runtime C2 is raw TCP (not HTTP/HTTPS) with builder-configured host/port pairs and keepalive framing. For the cluster's C2 behavior, see nanocore entity page. ^[capa.txt:62-66]
Interesting Tidbits
- Disney masquerade:
Nemo.exeis the first confirmed sibling with a children's-movie themed filename, expanding the known lure spectrum beyond business documents and emulator utilities. ^[triage.json] - Smallest RCData in cluster: 88,928 bytes vs 89,960 in
f017a517. The ~1 KB difference is likely a shorter host list or fewer plugin modules in this build. ^[pefile.txt:238] - No YARA hits beyond generic PE: MalwareBazaar tagged it
nanocore/rat; our YARA only matchedPE_File_Generic. ConfuserEx obfuscation defeats family-specific string signatures. ^[yara.txt] - floss failure: The flare-floss run failed with an argument-parsing error (
--noflag collision), so no decoded strings were produced. The unobfuscated metadata in#Stringsis sufficient for family identification. ^[floss.txt]
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2013/2015 + VB.NET WinForms project + .NET Framework 2.0 target.
Compiler flags: Standard Debug/Release build. Enable "My Application Framework" in project properties (this auto-generates MyTemplate and a unique GUID).
Obfuscation: Pass the compiled EXE through ConfuserEx (open-source, .NET 4.x). Enable name mangling (#=q…==), resource encryption, and control-flow flattening.
Verification: Run capa on the output. You should see the same capability fingerprint as this sample: create TCP socket, hash data with MD5, query or enumerate registry key, create process in .NET, suspend thread, etc. Compare to capa.txt in this analysis directory.
What you'll learn: How a commodity .NET RAT builder packages plugins, encrypts config, and obfuscates IL to evade static signatures. The builder's output is structurally identical across samples — only the RCData payload and GUID differ.
Deployable Signatures
YARA Rule
rule nanocore_vbnet_confuserex_2015_batch
{
meta:
description = "NanoCore RAT client v1.2.2.0 — VB.NET ConfuserEx obfuscated, Feb 2015 builder batch"
author = "PacketPursuit"
date = "2026-08-08"
version = "1.0"
hash = "37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242"
family = "nanocore"
strings:
$vb1 = "MyTemplate" ascii wide
$vb2 = "NanoCore Client" ascii wide
$vb3 = "NanoCore Client.exe" ascii wide
$vb4 = "1.2.2.0" ascii wide
$iface1 = "IClientApp" ascii wide
$iface2 = "IClientNetwork" ascii wide
$iface3 = "IClientUIHost" ascii wide
$iface4 = "IClientPluginHost" ascii wide
$host1 = "AddHostEntry" ascii wide
$host2 = "RebuildHostCache" ascii wide
$conf1 = "#=q" ascii wide
condition:
uint16(0) == 0x5A4D
and pe.number_of_sections == 3
and pe.imports("mscoree.dll", "_CorExeMain")
and ($vb1 or $vb2 or $vb3 or $vb4)
and 2 of ($iface*)
and #conf1 > 500
and filesize < 250KB
}
Sigma Rule (process creation)
title: NanoCore RAT Client Execution — VB.NET ConfuserEx Batch
description: Detects execution of NanoCore RAT client with known builder artefacts
logsource:
category: process_creation
product: windows
detection:
selection:
- CommandLine|contains:
- 'NanoCore Client.exe'
- OriginalFileName:
- 'NanoCore Client.exe'
- Image|endswith:
- '\Nemo.exe'
condition: selection
falsepositives:
- Unlikely — the filename and internal name are unique to the malware family.
level: high
IOC List
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | Hash | 37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242 |
| MD5 | Hash | c3db1215f116879ae1799ec7d0f09073 |
| SSDeep | Hash | 6144:MLV6Bta6dtJmakIM5fBGmPDZ1ZgJB6QUWlvH:MLV6BtpmkqBGmPDZ1gB65Wlv |
| Filename | Artefact | Nemo.exe |
| Internal name | Artefact | NanoCore Client.exe |
| Builder version | Artefact | 1.2.2.0 |
| GUID | Artefact | $6d10e433-cda2-420f-9bab-c964ccf1d3ca |
| Compile timestamp | Artefact | 2015-02-22 00:49:37 UTC |
| Resource entry | Artefact | RT_RCDATA ID 1, 88,928 bytes |
| .NET runtime | Artefact | CLR v2.0.50727 |
| IAT import | Artefact | mscoree.dll._CorExeMain (only import) |
Behavioral Fingerprint
This binary is a .NET Framework 2.0 PE32 GUI executable compiled in VB.NET with the Visual Studio My Application Framework (evidenced by MyTemplate class and auto-generated GUID). It contains a single imported symbol (mscoree.dll._CorExeMain) and a three-section PE layout (.text, .reloc, .rsrc). The .rsrc section holds an 88,928-byte encrypted RCData payload. At runtime, the binary resolves its C2 host list from this encrypted resource, establishes raw TCP socket connections (not HTTP/HTTPS), and exposes a modular plugin architecture via named interfaces (IClientApp, IClientNetwork, IClientUIHost). It registers for auto-start via the Registry Run key and performs file-system self-copying. The IL is heavily obfuscated with ConfuserEx (#=q…== name mangling, 1,000+ instances). No VM-detection or anti-debug logic is present statically.
Detection Signatures (capa → ATT&CK)
| capa Capability | ATT&CK Technique |
|---|---|
| modify registry | T1112 |
| reflective code loading | T1620 |
| account discovery | T1087 |
| file and directory discovery | T1083 |
| query registry | T1012 |
| system information discovery | T1082 |
| system owner/user discovery | T1033 |
| hash data with MD5 | T1001.002 (data obfuscation via hashing) |
| create TCP socket | T1095 |
| create or open mutex | T1071.001 |
| create process | T1059 |
| suspend thread | T1055 |
| set registry value | T1547.001 |
| delete registry value | T1112 |
| load .NET assembly | T1620 |
References
- nanocore — Family entity page with full cluster analysis and TTPs.
- confuserex-obfuscation — Technique page for the primary obfuscator.
- registry-run-persistence — Procedure page for the observed persistence mechanism.
- MalwareBazaar artifact:
986fbd1f-00a4-4b80-8d83-ae5327332022
Provenance
file.txt— file(1) v5.44pefile.txt— pefile v2023.2.7rabin2-info.txt— radare2 v5.8.8strings.txt— strings(1) from binutilscapa.txt— Mandiant capa v7.0.1 (static analysis)floss.txt— flare-floss v2.3.0 (failed — argument parsing error)binwalk.txt— binwalk v2.3.4exiftool.json— ExifTool v12.76triage.json— internal triage pipelinemetadata.json— OpenCTI artifact metadata