4121d69c165b16754eb62f1b87930e7c66a69e4c4a5e6526c10e1c4fea547b2fNanoCore RAT — 4121d69c (Backdoor.exe)
Build / RE
Toolchain: VB.NET targeting .NET Framework 2.0 (CLR v2.0.50727), compiled with Visual Studio / SharpDevelop. ^[strings.txt:51] ^[strings.txt:58-79]
Internal name: NanoCore Client.exe; builder version 1.2.2.0. ^[strings.txt:55-56] ^[strings.txt:1626]
Obfuscation: ConfuserEx — pervasive #=q…== name mangling across types, methods, fields, and properties. ^[strings.txt:278-711] Minimal native IAT: only mscoree.dll._CorExeMain imported. ^[pefile.txt:199]
Resources: Single RT_RCDATA resource in .rsrc, 0x15F68 bytes, entropy ~7.998 — encrypted plugin/config bundle. ^[pefile.txt:132,237-238]
Anti-analysis: No explicit anti-VM or anti-debug strings observed; the obfuscation layer itself is the primary barrier. ConfuserEx control-flow flattening and constant encryption expected. EnterDebugMode capability observed. ^[capa.txt:92]
Signing: Unsigned. ^[rabin2-info.txt:27]
Compilation timestamp: Sun Feb 22 00:49:37 2015 UTC. ^[exiftool.json:15] ^[pefile.txt:34]
Deploy / ATT&CK
Persistence: Registry Run key modification (T1547.001) and file-system self-copy inferred from capa hits. ^[capa.txt:15] ^[capa.txt:73-75,98-99]
Discovery: Account Discovery (T1087), File and Directory Discovery (T1083), Query Registry (T1012), System Information Discovery (T1082), System Owner/User Discovery (T1033). ^[capa.txt:17-21]
Defense Evasion: Reflective Code Loading (T1620) — plugin architecture loads encrypted modules from memory. ^[capa.txt:16] ConfuserEx obfuscation acts as T1027.002.
C2: Raw TCP sockets with DNS resolution. AddHostEntry and RebuildHostCache methods support dynamic host-list updates. ^[capa.txt:62-66] ^[strings.txt:468-470]
Plugin IPC: Named/anonymous pipes — CreatePipe, ClosePipe, PipeExists, PipeCreated. ^[strings.txt:458-463,1112-1113]
Process: Creation (6 matches), termination (4 matches), thread suspension (6 matches), mutex creation. ^[capa.txt:54-57,91-93,102]
Cryptography: MD5 hashing (4 matches), PRNG via .NET Random. ^[capa.txt:66-68,37-38]
File System: Copy, create directory, delete directory/file, read, write, enumerate, check existence. ^[capa.txt:73-84]
Console / Debug: Console buffer manipulation, debug mode entry. ^[capa.txt:71,92]
Confidence
High. Internal name, namespace (NanoCore.ClientPlugin), builder version, ConfuserEx obfuscation pattern, plugin interfaces (IClientApp, IClientNetwork, IClientUIHost), and Feb 2015 compilation timestamp are all consistent with leaked-era NanoCore RAT builder output. This sample is the fourth confirmed sibling in the same Feb 2015 batch alongside fe81691f, 48c8e8a2, and d065ebea. Filename on disk: Backdoor.exe. ^[metadata.json]