38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72nanocore: 38cac999 — seventeenth Feb 2015 batch sibling, bare filename "nam.exe"
Executive Summary
Seventeenth confirmed sibling in the NanoCore Feb 2015 batch builder run (1.2.2.0, timestamp 22 Feb 2015 00:49:37 UTC). The sample is a 203 KB PE32 .NET assembly (nam.exe) with no social-engineering masquerade — a bare filename distinct from the domain- and theme-named lures seen in the other sixteen siblings. ConfuserEx-obfuscated, identical build fingerprint, and identical resource encryption pipeline (RijndaelManaged + DeflateStream). No hardcoded C2. Static-only analysis.
What It Is
| Property | Value | Provenance |
|---|---|---|
| SHA-256 | 38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72 |
metadata.json |
| File name | nam.exe |
metadata.json |
| Size | 207,872 bytes (203 KB) | metadata.json |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | file.txt |
| Timestamp | Sun Feb 22 00:49:37 2015 UTC | pefile.txt:34, exiftool.json |
| Linker | .NET Framework v2.0.50727 (CLR 2.0) | strings.txt:51 |
| Language | Visual Basic .NET (My.Application framework) | strings.txt:1613-1618 |
| RAT version | NanoCore Client 1.2.2.0 | strings.txt:1626 |
| MyTemplate GUID | 47a89a76-c40c-4e5f-9273-94732e5f42cf |
strings.txt:1624 |
| Obfuscator | ConfuserEx (massive #=q… mangling) |
strings.txt:278-1800 |
| Signed | No | pefile.txt:173-186 |
The binary is a NanoCore client payload from the same leaked-era builder batch as the prior sixteen siblings. It differs only in its bare filename (nam.exe) and unique MyTemplate GUID. All other static artefacts — size, timestamp, obfuscation density, and resource layout — match the batch fingerprint. ^[strings.txt:1624] ^[strings.txt:1626]
How It Works
This sample is a confirmed cluster sibling of the NanoCore Feb 2015 batch. Shared behaviour is documented on the nanocore entity page. What follows are the per-sample deltas.
Filename & Masquerade
Unlike siblings that carry social-engineering filenames (okfun.exe, hotro.exe, Backdoor.exe, mmdx2.ru.com.exe, EMU.exe, Nemo.exe, gwwsite.nl.exe, gg88.yellowred.in.exe, jvegter.nl.exe, coffeeandsuch.nl.exe, aboddehousing.co.uk.exe, etc.), this binary uses the bare name nam.exe with no domain, brand, or theme masquerade. ^[metadata.json] This may indicate an internal test build, a default builder output name, or a post-builder manual rename.
Build Artefacts
- Builder version
1.2.2.0is identical to all sixteen prior siblings. ^[strings.txt:1626] - MyTemplate GUID
47a89a76-c40c-4e5f-9273-94732e5f42cfis unique to this sample, confirming the builder generates a fresh GUID per build. ^[strings.txt:1624] - Assembly title strings show
NanoCore Client/NanoCore Client.exe. ^[strings.txt:55-56]
Obfuscation
- ConfuserEx name mangling: ~1,500+ mangled tokens (
#=q[A-Za-z0-9_$]{10,}==) across the metadata streams, identical pattern to the batch. ^[strings.txt:278-1800] - Resource encryption:
.rsrcsection is 90,464 bytes with entropy ~7.997. No plaintextPK\x03\x04ZIP header at the resource start (unlike some siblings where the ZIP signature was recovered deeper in the section). The payload is likely encrypted in-place by ConfuserEx and decrypted at runtime via the embeddedRijndaelManaged+DeflateStreampipeline (inferred from strings). ^[pefile.txt:118-136] - Minimal IAT: Only
mscoree.dll._CorExeMainimported. ^[pefile.txt:199]
Persistence & Installation (inferred)
Same patterns as the cluster: get_StartupPath, set_CurrentDirectory, registry manipulation via RegistryKey / RegOpenKeyEx / RegQueryValueEx, file-system copy/delete/write. ^[capa.txt:73-84] ^[capa.txt:95-99]
Network / C2 (inferred)
No hardcoded C2 strings recovered. Network surface inferred from:
System.Net.Sockets.Socket,ConnectAsync,SendToServer,get_Connected— raw TCP, no HTTP framing. ^[strings.txt:1594-1604]DnsRecord,AddHostEntry,RebuildHostCache,GetHostEntry— server-driven host list updates. ^[strings.txt:1400-1402]KeepAlivein command strings. ^[strings.txt:1116]
Decompiled Behavior
No Ghidra decompilation was performed for this sample. The ConfuserEx obfuscation layer renders automated decompilation into readable pseudo-C non-productive without first stripping protections (see de4dot / NoFuser workflows on the confuserex-obfuscation technique page). Static inference is drawn from strings, capa, and pefile.
C2 Infrastructure
- None recovered statically. The builder-configured C2 settings are encrypted inside the
.rsrcpayload and only decrypted at runtime. Historical NanoCore C2 has used dynamic DNS and direct IP over raw TCP ports (typically 4782, 4783, or builder-configured alternatives). This sample follows the same builder pattern.
Interesting Tidbits
- Bare filename anomaly:
nam.exeis the first sibling in the batch without a social-engineering masquerade. Previous siblings used domain names, game titles, or geographic themes. This may be a builder default or an operator mistake. - GUID uniqueness: The
MyTemplateGUID is fresh, confirming per-build GUID generation rather than hardcoded reuse. - Resource size consistency: The
.rsrcsection (~90 KB) falls within the tight 88–91 KB range seen across the batch, suggesting a fixed builder template with only GUID and encrypted config varying. - Padding artefact: The final string in the binary is
qoPADDINGXXPADDING..., a ConfuserEx padding string used to align the last metadata stream. ^[strings.txt:1806]
How To Mess With It (Homelab Replication)
- Toolchain: Visual Studio 2013 / VB.NET / .NET Framework 2.0.
- Build: Compile a trivial WinForms app with
My.Applicationframework enabled. - Obfuscate: Pass the EXE through ConfuserEx v1.6.0 with
preset="maximum". Verify#=q…mangling instringsoutput. - Verify: Run
capaand confirm the same capability fingerprint (communication/socket/tcp,host-interaction/registry,load-code/dotnet, etc.).
Deployable Signatures
YARA rule
rule nanocore_feb2015_batch
{
meta:
description = "NanoCore Feb 2015 batch builder v1.2.2.0 client"
author = "PacketPursuit"
reference = "38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72"
strings:
$a = "NanoCore Client" ascii wide
$b = "1.2.2.0" ascii wide
$c = "IClientApp" ascii wide
$d = "IClientNetwork" ascii wide
$e = "SendToServer" ascii wide
$f = "AddHostEntry" ascii wide
$g = "KeepAlive" ascii wide
$h = "#=q" ascii
$i = "MyTemplate" ascii wide
$j = "ClientLoaderForm" ascii wide
$k = "RijndaelManaged" ascii wide
$l = "DeflateStream" ascii wide
condition:
uint16(0) == 0x5A4D and
($a and $b) or
(5 of ($c, $d, $e, $f, $g, $j)) or
($h and $i and 2 of ($k, $l)) or
(pe.number_of_sections == 3 and pe.sections[0].name == ".text" and pe.sections[1].name == ".reloc" and pe.sections[2].name == ".rsrc")
}
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72 |
Hash |
| Filename | nam.exe |
Filename |
| Builder version | 1.2.2.0 |
Version |
| Timestamp | 2015-02-22 00:49:37 UTC |
Compile time |
| GUID | 47a89a76-c40c-4e5f-9273-94732e5f42cf |
MyTemplate GUID |
| Resource entropy | ~7.997 | Section entropy |
| Sections | .text, .reloc, .rsrc |
Layout |
Behavioral fingerprint statement
This binary is a .NET Framework 2.0 PE32 with only mscoree.dll._CorExeMain in its import table. On CLR bootstrap it instantiates a hidden ClientLoaderForm, loads an IClientApp plugin host, manipulates the registry via RegOpenKeyEx/RegQueryValueEx, and communicates over raw TCP sockets using ConnectAsync/SendAsync. The .rsrc section is a high-entropy encrypted blob (entropy ~8.0) decrypted at runtime via RijndaelManaged + DeflateStream. ConfuserEx name mangling (#=q…==) is present throughout the metadata streams.
Detection Signatures
MITRE ATT&CK mapping from capa:
- T1112 — Modify Registry ^[capa.txt:15]
- T1620 — Reflective Code Loading ^[capa.txt:16]
- T1087 — Account Discovery ^[capa.txt:17]
- T1083 — File and Directory Discovery ^[capa.txt:18]
- T1012 — Query Registry ^[capa.txt:19]
- T1082 — System Information Discovery ^[capa.txt:20]
- T1033 — System Owner/User Discovery ^[capa.txt:21]
References
- nanocore — cluster entity page with full TTPs and build-stack analysis.
- confuserex-obfuscation — technique page for deobfuscation and replication.
fe81691f— first sibling report in this batch. ^[/intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html]
Provenance
file.txt—filev5.45pefile.txt— pefile Python librarystrings.txt—strings -n 6 -e lcapa.txt— Mandiant capa v7.0.0 (static)rabin2-info.txt— radare2 v5.x (rabin2 -I)exiftool.json— ExifTool 12.76- No Ghidra decompilation performed; no dynamic analysis performed (CAPE skipped — no Windows guest).