typeanalysisfamilynanocoreconfidencehighcreated2026-07-03updated2026-07-03malware-familyratdotnetc2persistenceobfuscation
SHA-256: 4121d69c165b16754eb62f1b87930e7c66a69e4c4a5e6526c10e1c4fea547b2f

NanoCore RAT — 4121d69c (Backdoor.exe)

Build / RE

Toolchain: VB.NET targeting .NET Framework 2.0 (CLR v2.0.50727), compiled with Visual Studio / SharpDevelop. ^[strings.txt:51] ^[strings.txt:58-79] Internal name: NanoCore Client.exe; builder version 1.2.2.0. ^[strings.txt:55-56] ^[strings.txt:1626] Obfuscation: ConfuserEx — pervasive #=q…== name mangling across types, methods, fields, and properties. ^[strings.txt:278-711] Minimal native IAT: only mscoree.dll._CorExeMain imported. ^[pefile.txt:199] Resources: Single RT_RCDATA resource in .rsrc, 0x15F68 bytes, entropy ~7.998 — encrypted plugin/config bundle. ^[pefile.txt:132,237-238] Anti-analysis: No explicit anti-VM or anti-debug strings observed; the obfuscation layer itself is the primary barrier. ConfuserEx control-flow flattening and constant encryption expected. EnterDebugMode capability observed. ^[capa.txt:92] Signing: Unsigned. ^[rabin2-info.txt:27] Compilation timestamp: Sun Feb 22 00:49:37 2015 UTC. ^[exiftool.json:15] ^[pefile.txt:34]

Deploy / ATT&CK

Persistence: Registry Run key modification (T1547.001) and file-system self-copy inferred from capa hits. ^[capa.txt:15] ^[capa.txt:73-75,98-99] Discovery: Account Discovery (T1087), File and Directory Discovery (T1083), Query Registry (T1012), System Information Discovery (T1082), System Owner/User Discovery (T1033). ^[capa.txt:17-21] Defense Evasion: Reflective Code Loading (T1620) — plugin architecture loads encrypted modules from memory. ^[capa.txt:16] ConfuserEx obfuscation acts as T1027.002. C2: Raw TCP sockets with DNS resolution. AddHostEntry and RebuildHostCache methods support dynamic host-list updates. ^[capa.txt:62-66] ^[strings.txt:468-470] Plugin IPC: Named/anonymous pipes — CreatePipe, ClosePipe, PipeExists, PipeCreated. ^[strings.txt:458-463,1112-1113] Process: Creation (6 matches), termination (4 matches), thread suspension (6 matches), mutex creation. ^[capa.txt:54-57,91-93,102] Cryptography: MD5 hashing (4 matches), PRNG via .NET Random. ^[capa.txt:66-68,37-38] File System: Copy, create directory, delete directory/file, read, write, enumerate, check existence. ^[capa.txt:73-84] Console / Debug: Console buffer manipulation, debug mode entry. ^[capa.txt:71,92]

Confidence

High. Internal name, namespace (NanoCore.ClientPlugin), builder version, ConfuserEx obfuscation pattern, plugin interfaces (IClientApp, IClientNetwork, IClientUIHost), and Feb 2015 compilation timestamp are all consistent with leaked-era NanoCore RAT builder output. This sample is the fourth confirmed sibling in the same Feb 2015 batch alongside fe81691f, 48c8e8a2, and d065ebea. Filename on disk: Backdoor.exe. ^[metadata.json]