typeanalysisfamilynanocoreconfidencehighcreated2026-09-06updated2026-09-06dotnetmalware-familyratc2obfuscationpersistence
SHA-256: 4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28

nanocore: 4eed8d8f — bare-filename sibling 'sh4.exe', Feb 2015 builder batch

Executive Summary

The twenty-first confirmed sibling in the Feb 22 2015 NanoCore builder batch. A 208 KB VB.NET PE32 client (sh4.exe) carrying NanoCore RAT v1.2.2.0 under ConfuserEx obfuscation. Like sibling b5bbf49b (nega.exe), it uses a bare short filename with no social-engineering masquerade. Identical build timestamp, builder version, and obfuscation fingerprint — only the MyTemplate GUID and encrypted RCData payload differ. No hardcoded C2 recovered; settings are runtime-decrypted from the 90 KB resource package. Static-only (CAPE skipped — no Windows guest).

What It Is

Property Value Provenance
SHA-256 4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28 metadata.json
File name sh4.exe metadata.json
Size 208,384 bytes (203 KB) metadata.json
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections file.txt
Timestamp Sun Feb 22 00:49:37 2015 UTC (0x54E927A1) pefile.txt:34
Linker .NET Framework v2.0.50727 (CLR 2.0) strings.txt:51
Language Visual Basic .NET (My.Application / MyTemplate) strings.txt:1613, strings.txt:1618
RAT version NanoCore Client 1.2.2.0 strings.txt:1626
Obfuscator ConfuserEx (#=q…== name mangling, ~1,100+ tokens) strings.txt:278+
MyTemplate GUID a96b9d76-0029-412c-98b8-5276d49306fe strings.txt:1624
Signed No (stripped, unsigned) pefile.txt:153-154
RCData resource 90,176 bytes (entropy 7.997), encrypted payload pefile.txt:131-137

Family ascription is high-confidence: every static marker aligns with the 20 prior confirmed siblings in this cluster. See nanocore entity page for the full cluster fingerprint.

How It Works

Per-Sample Deltas vs. Cluster Baseline

  1. Filename: sh4.exe — a bare, meaningless three-character name with no domain or utility masquerade. Second sibling in the batch (after nega.exe) to use a non-descriptive name, suggesting either a test build or distribution via a channel where the filename is irrelevant. ^[metadata.json]

  2. MyTemplate GUID: a96b9d76-0029-412c-98b8-5276d49306fe — unique to this sample. Every sibling carries a distinct GUID generated by the VB.NET compiler at build time. ^[strings.txt:1624]

  3. RCData payload size: 90,176 bytes — at the upper end of the sibling range (88–91 KB), confirming a per-build config/plugin bundle. ^[pefile.txt:131-137]

Cluster-Shared Behavior (see nanocore for full detail)

  • Entry: CLR bootstrap → ClientLoaderForm.Main (WinForms invisible wrapper) → IClientApp plugin host initialization. ^[strings.txt:344]
  • Obfuscation: ConfuserEx rewrites all identifiers to #=q[A-Za-z0-9_$]{10,}== tokens, encrypts the .rsrc payload, and flattens control flow. ^[strings.txt:278]
  • Persistence: Registry Run key manipulation inferred from RegistryKey, get_StartupPath, and set_CurrentDirectory references. ^[capa.txt:95-99]
  • C2: Raw TCP sockets (not HTTP/HTTPS). System.Net.Sockets.Socket, SendToServer, get_Connected, get_Port, DnsRecord, AddHostEntry, RebuildHostCache all present. ^[capa.txt:62-66]
  • Plugin architecture: IClientApp, IClientNetwork, IClientUIHost, CommandType, BaseCommand, FileCommand, PluginCommand, plus pipe-based IPC (CreatePipe, PipeExists, PipeCreated). ^[strings.txt:86-97, strings.txt:331-348, strings.txt:458-463]
  • Crypto: RijndaelManaged, DeflateStream, MD5CryptoServiceProvider present for resource decryption and packet integrity. ^[strings.txt:152, strings.txt:232, strings.txt:230]

Decompiled Behavior

Radare2 CIL analysis identifies 858 methods. The entry point lands in method.ClientLoaderForm.Main (0x40c480), which instantiates the invisible WinForms wrapper and delegates to the obfuscated Client constructor chain. ConfuserEx control-flow flattening and delegate trampolines dominate the IL; meaningful decompilation is blocked without dynamic tracing or automated deobfuscation. ^[rabin2-info.txt]

The .rsrc section (offset 0x22058, size 0x15FC0) is the ConfuserEx-encrypted payload package. Its entropy of 7.997 and the PK\x03\x04 ZIP signature deep inside confirm a compressed/encrypted resource bundle — standard for ConfuserEx-protected NanoCore builds. ^[pefile.txt:131-137, binwalk.txt]

C2 Infrastructure

  • Static C2: None extracted. ClientSettings / BuilderSettings objects are encrypted inside the .rsrc ZIP and decrypted at runtime via the ConfuserEx resource decryption stub. ^[strings.txt:1401-1402]
  • Protocol: Raw TCP sockets with keepalive framing. Inferred from Socket, SendToServer, ReceiveAsync, and socket error handling patterns. ^[capa.txt:62-66]
  • DNS / host cache: DnsRecord, GetHostEntry, AddHostEntry, RebuildHostCache show the client maintains a mutable host list, supporting server-driven redirection. ^[strings.txt:343, strings.txt:468-470]
  • Named pipes: CreatePipe, PipeExists, PipeCreated, PipeClosed — used for client ↔ plugin IPC, not C2 transport. ^[strings.txt:459-463]

Interesting Tidbits

  1. Bare filename, no masquerade: sh4.exe joins nega.exe as the only siblings in this batch with non-descriptive names. All others use domain-masquerade (mmdx2.ru.com.exe, cash-win.nl.exe, etc.) or utility-masquerade (EMU.exe, Nemo.exe). ^[metadata.json]
  2. Identical linker timestamp: 0x54E927A1 shared across all 21 siblings, confirming a single batch-build event on one operator machine. ^[pefile.txt:34]
  3. SSDeep similarity: The normalized ssdeep hash ULV6Bta6dtJmakIM53xcEvFcuvYc shares the same block-1 prefix as sibling b5bbf49b, confirming the same code base and ConfuserEx layer. ^[ssdeep.txt]
  4. Single import: Only mscoree.dll!_CorExeMain — standard for .NET assemblies. A 200 KB PE with one import and .rsrc entropy ~8.0 is a reliable ConfuserEx .NET loader fingerprint. ^[pefile.txt:199]
  5. No Authenticode, no PDB, no debug directory: Clean stripped build consistent with criminal distribution. ^[pefile.txt:153-163]
  6. TLSH: 6914BF1677A8852FE2DE8679611202578378C2E398C3F7DF28D860B75F663E50A071D3 — high-similarity hash useful for fuzzy matching against other NanoCore siblings. ^[tlsh.txt]

How To Mess With It (Homelab Replication)

Goal: Reproduce a ConfuserEx-obfuscated .NET RAT loader matching this sample's static fingerprint.

  1. Toolchain: Visual Studio 2013/2015 Community + .NET Framework 2.0/3.5 targeting pack.
  2. Source: Write a trivial VB.NET WinForms app with a Form1 class, add a reference to System.Net.Sockets, and instantiate a TcpClient in the Load event.
  3. Build: Compile as Release, x86, .NET Framework 2.0. Output should be ~20–40 KB.
  4. Obfuscate: Run through ConfuserEx (or ConfuserEx-Reborn) with maximum renaming, control-flow flattening, and resource encryption enabled. Output will balloon to ~150–250 KB.
  5. Verify: Run capa <output.exe> — should hit load .NET assembly, create TCP socket, resolve DNS, query registry, create mutex, and hash data with MD5.

Deployable Signatures

YARA Rule

rule Nanocore_ConfuserEx_Feb2015_Batch
{
    meta:
        description = "NanoCore RAT v1.2.2.0 ConfuserEx-obfuscated client, Feb 2015 builder batch"
        author = "PacketPursuit"
        date = "2026-09-06"
        hash = "4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28"
        hash = "b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499"
        hash = "fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5"
    strings:
        $ver = "1.2.2.0" ascii wide
        $name = "NanoCore Client" ascii wide
        $mytemplate = "MyTemplate" ascii wide
        $mscoree = "mscoree.dll" ascii
        $confuser = /#=q[A-Za-z0-9_$]{10,}==/
        $rcdata = { 50 4B 03 04 }  // ZIP signature inside .rsrc
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections == 3 and
        pe.sections[2].name == ".rsrc" and
        math.entropy(pe.sections[2].raw_data_offset, pe.sections[2].raw_data_size) > 7.8 and
        $ver and
        $name and
        $mscoree and
        #confuser > 500
}

IOC List

Indicator Value Type
SHA-256 4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28 Hash
SHA-1 55e010e663de73d22d3cad0571e84f574e5d607e Hash
MD5 1dea9128e695458cfeccb5d3e9bb7919 Hash
Filename sh4.exe Filename
GUID a96b9d76-0029-412c-98b8-5276d49306fe Builder GUID
Timestamp 0x54E927A1 (2015-02-22 00:49:37 UTC) PE compile time
Version 1.2.2.0 Builder version
.rsrc entropy 7.997 Section entropy

Behavioral Fingerprint

A 200 KB PE32 .NET assembly with exactly three sections (.text, .reloc, .rsrc) and a single import (mscoree.dll!_CorExeMain). The .rsrc section exhibits entropy ~8.0 and contains a ZIP-structured encrypted payload. Strings include NanoCore Client, builder version 1.2.2.0, MyTemplate, and 500+ ConfuserEx-mangled identifiers (#=q…==). At runtime, decrypts the .rsrc payload via RijndaelManaged + DeflateStream, establishes raw TCP sockets (not HTTP), and maintains a mutable host cache via AddHostEntry/RebuildHostCache. Persistence via Registry Run key.

Detection Signatures

ATT&CK ID Technique Evidence
T1547.001 Registry Run Keys RegistryKey, set_CurrentDirectory, get_StartupPath ^[capa.txt:95-99]
T1620 Reflective Code Loading load .NET assembly, encrypted .rsrc plugin package ^[capa.txt:16]
T1087 Account Discovery get_UserName, WindowsIdentity ^[capa.txt:17]
T1083 File and Directory Discovery enumerate files, get file size, check if file exists ^[capa.txt:18]
T1012 Query Registry query or enumerate registry key (6 matches) ^[capa.txt:19]
T1082 System Information Discovery get OS version, get hostname ^[capa.txt:20]
T1033 System Owner/User Discovery get session user name ^[capa.txt:21]
T1071 Application Layer Protocol Raw TCP socket C2 ^[capa.txt:62-66]
T1573 Encrypted Channel RijndaelManaged for payload and packet encryption ^[strings.txt:232]

References

  • NanoCore entity page: nanocore
  • ConfuserEx obfuscation technique: confuserex-obfuscation
  • Prior sibling analyses in by-family/nanocore/
  • CAPE detonation: skipped — no Windows guest available ^[dynamic-analysis.md]

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile Python library
  • strings.txt — strings(1) output
  • capa.txt — Mandiant capa v9.1.0 static analysis
  • rabin2-info.txt — radare2 v5.9.8 rabin2 -I
  • ssdeep.txt — ssdeep v2.14.1
  • tlsh.txt — TLSH v4.12.0
  • binwalk.txt — binwalk v2.3.4
  • metadata.json — OpenCTI artifact metadata