4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28nanocore: 4eed8d8f — bare-filename sibling 'sh4.exe', Feb 2015 builder batch
Executive Summary
The twenty-first confirmed sibling in the Feb 22 2015 NanoCore builder batch. A 208 KB VB.NET PE32 client (sh4.exe) carrying NanoCore RAT v1.2.2.0 under ConfuserEx obfuscation. Like sibling b5bbf49b (nega.exe), it uses a bare short filename with no social-engineering masquerade. Identical build timestamp, builder version, and obfuscation fingerprint — only the MyTemplate GUID and encrypted RCData payload differ. No hardcoded C2 recovered; settings are runtime-decrypted from the 90 KB resource package. Static-only (CAPE skipped — no Windows guest).
What It Is
| Property | Value | Provenance |
|---|---|---|
| SHA-256 | 4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28 |
metadata.json |
| File name | sh4.exe |
metadata.json |
| Size | 208,384 bytes (203 KB) | metadata.json |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | file.txt |
| Timestamp | Sun Feb 22 00:49:37 2015 UTC (0x54E927A1) |
pefile.txt:34 |
| Linker | .NET Framework v2.0.50727 (CLR 2.0) | strings.txt:51 |
| Language | Visual Basic .NET (My.Application / MyTemplate) | strings.txt:1613, strings.txt:1618 |
| RAT version | NanoCore Client 1.2.2.0 | strings.txt:1626 |
| Obfuscator | ConfuserEx (#=q…== name mangling, ~1,100+ tokens) |
strings.txt:278+ |
| MyTemplate GUID | a96b9d76-0029-412c-98b8-5276d49306fe |
strings.txt:1624 |
| Signed | No (stripped, unsigned) | pefile.txt:153-154 |
| RCData resource | 90,176 bytes (entropy 7.997), encrypted payload | pefile.txt:131-137 |
Family ascription is high-confidence: every static marker aligns with the 20 prior confirmed siblings in this cluster. See nanocore entity page for the full cluster fingerprint.
How It Works
Per-Sample Deltas vs. Cluster Baseline
-
Filename:
sh4.exe— a bare, meaningless three-character name with no domain or utility masquerade. Second sibling in the batch (afternega.exe) to use a non-descriptive name, suggesting either a test build or distribution via a channel where the filename is irrelevant. ^[metadata.json] -
MyTemplate GUID:
a96b9d76-0029-412c-98b8-5276d49306fe— unique to this sample. Every sibling carries a distinct GUID generated by the VB.NET compiler at build time. ^[strings.txt:1624] -
RCData payload size: 90,176 bytes — at the upper end of the sibling range (88–91 KB), confirming a per-build config/plugin bundle. ^[pefile.txt:131-137]
Cluster-Shared Behavior (see nanocore for full detail)
- Entry: CLR bootstrap →
ClientLoaderForm.Main(WinForms invisible wrapper) →IClientAppplugin host initialization. ^[strings.txt:344] - Obfuscation: ConfuserEx rewrites all identifiers to
#=q[A-Za-z0-9_$]{10,}==tokens, encrypts the.rsrcpayload, and flattens control flow. ^[strings.txt:278] - Persistence: Registry Run key manipulation inferred from
RegistryKey,get_StartupPath, andset_CurrentDirectoryreferences. ^[capa.txt:95-99] - C2: Raw TCP sockets (not HTTP/HTTPS).
System.Net.Sockets.Socket,SendToServer,get_Connected,get_Port,DnsRecord,AddHostEntry,RebuildHostCacheall present. ^[capa.txt:62-66] - Plugin architecture:
IClientApp,IClientNetwork,IClientUIHost,CommandType,BaseCommand,FileCommand,PluginCommand, plus pipe-based IPC (CreatePipe,PipeExists,PipeCreated). ^[strings.txt:86-97, strings.txt:331-348, strings.txt:458-463] - Crypto:
RijndaelManaged,DeflateStream,MD5CryptoServiceProviderpresent for resource decryption and packet integrity. ^[strings.txt:152, strings.txt:232, strings.txt:230]
Decompiled Behavior
Radare2 CIL analysis identifies 858 methods. The entry point lands in method.ClientLoaderForm.Main (0x40c480), which instantiates the invisible WinForms wrapper and delegates to the obfuscated Client constructor chain. ConfuserEx control-flow flattening and delegate trampolines dominate the IL; meaningful decompilation is blocked without dynamic tracing or automated deobfuscation. ^[rabin2-info.txt]
The .rsrc section (offset 0x22058, size 0x15FC0) is the ConfuserEx-encrypted payload package. Its entropy of 7.997 and the PK\x03\x04 ZIP signature deep inside confirm a compressed/encrypted resource bundle — standard for ConfuserEx-protected NanoCore builds. ^[pefile.txt:131-137, binwalk.txt]
C2 Infrastructure
- Static C2: None extracted.
ClientSettings/BuilderSettingsobjects are encrypted inside the.rsrcZIP and decrypted at runtime via the ConfuserEx resource decryption stub. ^[strings.txt:1401-1402] - Protocol: Raw TCP sockets with keepalive framing. Inferred from
Socket,SendToServer,ReceiveAsync, and socket error handling patterns. ^[capa.txt:62-66] - DNS / host cache:
DnsRecord,GetHostEntry,AddHostEntry,RebuildHostCacheshow the client maintains a mutable host list, supporting server-driven redirection. ^[strings.txt:343, strings.txt:468-470] - Named pipes:
CreatePipe,PipeExists,PipeCreated,PipeClosed— used for client ↔ plugin IPC, not C2 transport. ^[strings.txt:459-463]
Interesting Tidbits
- Bare filename, no masquerade:
sh4.exejoinsnega.exeas the only siblings in this batch with non-descriptive names. All others use domain-masquerade (mmdx2.ru.com.exe,cash-win.nl.exe, etc.) or utility-masquerade (EMU.exe,Nemo.exe). ^[metadata.json] - Identical linker timestamp:
0x54E927A1shared across all 21 siblings, confirming a single batch-build event on one operator machine. ^[pefile.txt:34] - SSDeep similarity: The normalized ssdeep hash
ULV6Bta6dtJmakIM53xcEvFcuvYcshares the same block-1 prefix as siblingb5bbf49b, confirming the same code base and ConfuserEx layer. ^[ssdeep.txt] - Single import: Only
mscoree.dll!_CorExeMain— standard for .NET assemblies. A 200 KB PE with one import and.rsrcentropy ~8.0 is a reliable ConfuserEx .NET loader fingerprint. ^[pefile.txt:199] - No Authenticode, no PDB, no debug directory: Clean stripped build consistent with criminal distribution. ^[pefile.txt:153-163]
- TLSH:
6914BF1677A8852FE2DE8679611202578378C2E398C3F7DF28D860B75F663E50A071D3— high-similarity hash useful for fuzzy matching against other NanoCore siblings. ^[tlsh.txt]
How To Mess With It (Homelab Replication)
Goal: Reproduce a ConfuserEx-obfuscated .NET RAT loader matching this sample's static fingerprint.
- Toolchain: Visual Studio 2013/2015 Community + .NET Framework 2.0/3.5 targeting pack.
- Source: Write a trivial VB.NET WinForms app with a
Form1class, add a reference toSystem.Net.Sockets, and instantiate aTcpClientin theLoadevent. - Build: Compile as
Release, x86, .NET Framework 2.0. Output should be ~20–40 KB. - Obfuscate: Run through ConfuserEx (or ConfuserEx-Reborn) with maximum renaming, control-flow flattening, and resource encryption enabled. Output will balloon to ~150–250 KB.
- Verify: Run
capa <output.exe>— should hitload .NET assembly,create TCP socket,resolve DNS,query registry,create mutex, andhash data with MD5.
Deployable Signatures
YARA Rule
rule Nanocore_ConfuserEx_Feb2015_Batch
{
meta:
description = "NanoCore RAT v1.2.2.0 ConfuserEx-obfuscated client, Feb 2015 builder batch"
author = "PacketPursuit"
date = "2026-09-06"
hash = "4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28"
hash = "b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499"
hash = "fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5"
strings:
$ver = "1.2.2.0" ascii wide
$name = "NanoCore Client" ascii wide
$mytemplate = "MyTemplate" ascii wide
$mscoree = "mscoree.dll" ascii
$confuser = /#=q[A-Za-z0-9_$]{10,}==/
$rcdata = { 50 4B 03 04 } // ZIP signature inside .rsrc
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections == 3 and
pe.sections[2].name == ".rsrc" and
math.entropy(pe.sections[2].raw_data_offset, pe.sections[2].raw_data_size) > 7.8 and
$ver and
$name and
$mscoree and
#confuser > 500
}
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28 |
Hash |
| SHA-1 | 55e010e663de73d22d3cad0571e84f574e5d607e |
Hash |
| MD5 | 1dea9128e695458cfeccb5d3e9bb7919 |
Hash |
| Filename | sh4.exe |
Filename |
| GUID | a96b9d76-0029-412c-98b8-5276d49306fe |
Builder GUID |
| Timestamp | 0x54E927A1 (2015-02-22 00:49:37 UTC) |
PE compile time |
| Version | 1.2.2.0 |
Builder version |
| .rsrc entropy | 7.997 | Section entropy |
Behavioral Fingerprint
A 200 KB PE32 .NET assembly with exactly three sections (.text, .reloc, .rsrc) and a single import (mscoree.dll!_CorExeMain). The .rsrc section exhibits entropy ~8.0 and contains a ZIP-structured encrypted payload. Strings include NanoCore Client, builder version 1.2.2.0, MyTemplate, and 500+ ConfuserEx-mangled identifiers (#=q…==). At runtime, decrypts the .rsrc payload via RijndaelManaged + DeflateStream, establishes raw TCP sockets (not HTTP), and maintains a mutable host cache via AddHostEntry/RebuildHostCache. Persistence via Registry Run key.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1547.001 | Registry Run Keys | RegistryKey, set_CurrentDirectory, get_StartupPath ^[capa.txt:95-99] |
| T1620 | Reflective Code Loading | load .NET assembly, encrypted .rsrc plugin package ^[capa.txt:16] |
| T1087 | Account Discovery | get_UserName, WindowsIdentity ^[capa.txt:17] |
| T1083 | File and Directory Discovery | enumerate files, get file size, check if file exists ^[capa.txt:18] |
| T1012 | Query Registry | query or enumerate registry key (6 matches) ^[capa.txt:19] |
| T1082 | System Information Discovery | get OS version, get hostname ^[capa.txt:20] |
| T1033 | System Owner/User Discovery | get session user name ^[capa.txt:21] |
| T1071 | Application Layer Protocol | Raw TCP socket C2 ^[capa.txt:62-66] |
| T1573 | Encrypted Channel | RijndaelManaged for payload and packet encryption ^[strings.txt:232] |
References
- NanoCore entity page: nanocore
- ConfuserEx obfuscation technique: confuserex-obfuscation
- Prior sibling analyses in
by-family/nanocore/ - CAPE detonation: skipped — no Windows guest available ^[dynamic-analysis.md]
Provenance
file.txt— file(1) outputpefile.txt— pefile Python librarystrings.txt— strings(1) outputcapa.txt— Mandiant capa v9.1.0 static analysisrabin2-info.txt— radare2 v5.9.8rabin2 -Issdeep.txt— ssdeep v2.14.1tlsh.txt— TLSH v4.12.0binwalk.txt— binwalk v2.3.4metadata.json— OpenCTI artifact metadata