typeanalysisfamilynanocoreconfidencehighcreated2026-08-14updated2026-08-14dotnetmalware-familyratc2obfuscationpersistence
SHA-256: 38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72

nanocore: 38cac999 — seventeenth Feb 2015 batch sibling, bare filename "nam.exe"

Executive Summary

Seventeenth confirmed sibling in the NanoCore Feb 2015 batch builder run (1.2.2.0, timestamp 22 Feb 2015 00:49:37 UTC). The sample is a 203 KB PE32 .NET assembly (nam.exe) with no social-engineering masquerade — a bare filename distinct from the domain- and theme-named lures seen in the other sixteen siblings. ConfuserEx-obfuscated, identical build fingerprint, and identical resource encryption pipeline (RijndaelManaged + DeflateStream). No hardcoded C2. Static-only analysis.

What It Is

Property Value Provenance
SHA-256 38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72 metadata.json
File name nam.exe metadata.json
Size 207,872 bytes (203 KB) metadata.json
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections file.txt
Timestamp Sun Feb 22 00:49:37 2015 UTC pefile.txt:34, exiftool.json
Linker .NET Framework v2.0.50727 (CLR 2.0) strings.txt:51
Language Visual Basic .NET (My.Application framework) strings.txt:1613-1618
RAT version NanoCore Client 1.2.2.0 strings.txt:1626
MyTemplate GUID 47a89a76-c40c-4e5f-9273-94732e5f42cf strings.txt:1624
Obfuscator ConfuserEx (massive #=q… mangling) strings.txt:278-1800
Signed No pefile.txt:173-186

The binary is a NanoCore client payload from the same leaked-era builder batch as the prior sixteen siblings. It differs only in its bare filename (nam.exe) and unique MyTemplate GUID. All other static artefacts — size, timestamp, obfuscation density, and resource layout — match the batch fingerprint. ^[strings.txt:1624] ^[strings.txt:1626]

How It Works

This sample is a confirmed cluster sibling of the NanoCore Feb 2015 batch. Shared behaviour is documented on the nanocore entity page. What follows are the per-sample deltas.

Filename & Masquerade

Unlike siblings that carry social-engineering filenames (okfun.exe, hotro.exe, Backdoor.exe, mmdx2.ru.com.exe, EMU.exe, Nemo.exe, gwwsite.nl.exe, gg88.yellowred.in.exe, jvegter.nl.exe, coffeeandsuch.nl.exe, aboddehousing.co.uk.exe, etc.), this binary uses the bare name nam.exe with no domain, brand, or theme masquerade. ^[metadata.json] This may indicate an internal test build, a default builder output name, or a post-builder manual rename.

Build Artefacts

  • Builder version 1.2.2.0 is identical to all sixteen prior siblings. ^[strings.txt:1626]
  • MyTemplate GUID 47a89a76-c40c-4e5f-9273-94732e5f42cf is unique to this sample, confirming the builder generates a fresh GUID per build. ^[strings.txt:1624]
  • Assembly title strings show NanoCore Client / NanoCore Client.exe. ^[strings.txt:55-56]

Obfuscation

  • ConfuserEx name mangling: ~1,500+ mangled tokens (#=q[A-Za-z0-9_$]{10,}==) across the metadata streams, identical pattern to the batch. ^[strings.txt:278-1800]
  • Resource encryption: .rsrc section is 90,464 bytes with entropy ~7.997. No plaintext PK\x03\x04 ZIP header at the resource start (unlike some siblings where the ZIP signature was recovered deeper in the section). The payload is likely encrypted in-place by ConfuserEx and decrypted at runtime via the embedded RijndaelManaged + DeflateStream pipeline (inferred from strings). ^[pefile.txt:118-136]
  • Minimal IAT: Only mscoree.dll._CorExeMain imported. ^[pefile.txt:199]

Persistence & Installation (inferred)

Same patterns as the cluster: get_StartupPath, set_CurrentDirectory, registry manipulation via RegistryKey / RegOpenKeyEx / RegQueryValueEx, file-system copy/delete/write. ^[capa.txt:73-84] ^[capa.txt:95-99]

Network / C2 (inferred)

No hardcoded C2 strings recovered. Network surface inferred from:

  • System.Net.Sockets.Socket, ConnectAsync, SendToServer, get_Connected — raw TCP, no HTTP framing. ^[strings.txt:1594-1604]
  • DnsRecord, AddHostEntry, RebuildHostCache, GetHostEntry — server-driven host list updates. ^[strings.txt:1400-1402]
  • KeepAlive in command strings. ^[strings.txt:1116]

Decompiled Behavior

No Ghidra decompilation was performed for this sample. The ConfuserEx obfuscation layer renders automated decompilation into readable pseudo-C non-productive without first stripping protections (see de4dot / NoFuser workflows on the confuserex-obfuscation technique page). Static inference is drawn from strings, capa, and pefile.

C2 Infrastructure

  • None recovered statically. The builder-configured C2 settings are encrypted inside the .rsrc payload and only decrypted at runtime. Historical NanoCore C2 has used dynamic DNS and direct IP over raw TCP ports (typically 4782, 4783, or builder-configured alternatives). This sample follows the same builder pattern.

Interesting Tidbits

  • Bare filename anomaly: nam.exe is the first sibling in the batch without a social-engineering masquerade. Previous siblings used domain names, game titles, or geographic themes. This may be a builder default or an operator mistake.
  • GUID uniqueness: The MyTemplate GUID is fresh, confirming per-build GUID generation rather than hardcoded reuse.
  • Resource size consistency: The .rsrc section (~90 KB) falls within the tight 88–91 KB range seen across the batch, suggesting a fixed builder template with only GUID and encrypted config varying.
  • Padding artefact: The final string in the binary is qoPADDINGXXPADDING..., a ConfuserEx padding string used to align the last metadata stream. ^[strings.txt:1806]

How To Mess With It (Homelab Replication)

  1. Toolchain: Visual Studio 2013 / VB.NET / .NET Framework 2.0.
  2. Build: Compile a trivial WinForms app with My.Application framework enabled.
  3. Obfuscate: Pass the EXE through ConfuserEx v1.6.0 with preset="maximum". Verify #=q… mangling in strings output.
  4. Verify: Run capa and confirm the same capability fingerprint (communication/socket/tcp, host-interaction/registry, load-code/dotnet, etc.).

Deployable Signatures

YARA rule

rule nanocore_feb2015_batch
{
    meta:
        description = "NanoCore Feb 2015 batch builder v1.2.2.0 client"
        author = "PacketPursuit"
        reference = "38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72"
    strings:
        $a = "NanoCore Client" ascii wide
        $b = "1.2.2.0" ascii wide
        $c = "IClientApp" ascii wide
        $d = "IClientNetwork" ascii wide
        $e = "SendToServer" ascii wide
        $f = "AddHostEntry" ascii wide
        $g = "KeepAlive" ascii wide
        $h = "#=q" ascii
        $i = "MyTemplate" ascii wide
        $j = "ClientLoaderForm" ascii wide
        $k = "RijndaelManaged" ascii wide
        $l = "DeflateStream" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        ($a and $b) or
        (5 of ($c, $d, $e, $f, $g, $j)) or
        ($h and $i and 2 of ($k, $l)) or
        (pe.number_of_sections == 3 and pe.sections[0].name == ".text" and pe.sections[1].name == ".reloc" and pe.sections[2].name == ".rsrc")
}

IOC list

Indicator Value Type
SHA-256 38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72 Hash
Filename nam.exe Filename
Builder version 1.2.2.0 Version
Timestamp 2015-02-22 00:49:37 UTC Compile time
GUID 47a89a76-c40c-4e5f-9273-94732e5f42cf MyTemplate GUID
Resource entropy ~7.997 Section entropy
Sections .text, .reloc, .rsrc Layout

Behavioral fingerprint statement

This binary is a .NET Framework 2.0 PE32 with only mscoree.dll._CorExeMain in its import table. On CLR bootstrap it instantiates a hidden ClientLoaderForm, loads an IClientApp plugin host, manipulates the registry via RegOpenKeyEx/RegQueryValueEx, and communicates over raw TCP sockets using ConnectAsync/SendAsync. The .rsrc section is a high-entropy encrypted blob (entropy ~8.0) decrypted at runtime via RijndaelManaged + DeflateStream. ConfuserEx name mangling (#=q…==) is present throughout the metadata streams.

Detection Signatures

MITRE ATT&CK mapping from capa:

  • T1112 — Modify Registry ^[capa.txt:15]
  • T1620 — Reflective Code Loading ^[capa.txt:16]
  • T1087 — Account Discovery ^[capa.txt:17]
  • T1083 — File and Directory Discovery ^[capa.txt:18]
  • T1012 — Query Registry ^[capa.txt:19]
  • T1082 — System Information Discovery ^[capa.txt:20]
  • T1033 — System Owner/User Discovery ^[capa.txt:21]

References

  • nanocore — cluster entity page with full TTPs and build-stack analysis.
  • confuserex-obfuscation — technique page for deobfuscation and replication.
  • fe81691f — first sibling report in this batch. ^[/intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html]

Provenance

  • file.txt — file v5.45
  • pefile.txt — pefile Python library
  • strings.txt — strings -n 6 -e l
  • capa.txt — Mandiant capa v7.0.0 (static)
  • rabin2-info.txt — radare2 v5.x (rabin2 -I)
  • exiftool.json — ExifTool 12.76
  • No Ghidra decompilation performed; no dynamic analysis performed (CAPE skipped — no Windows guest).