familynanocoreconfidencehighcreated2026-08-12
SHA-256: 930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56

nanocore: 930b692d — jvegter.nl.exe, fourteenth confirmed Feb 2015 v1.2.2.0 sibling

Executive Summary

NanoCore Client v1.2.2.0 built 22 Feb 2015 00:49:37 UTC, ConfuserEx-obfuscated VB.NET payload masquerading as a Dutch domain (jvegter.nl.exe). Unique MyTemplate GUID 08186e7b-fc6a-4a22-832f-d29dc50a34fc. ~90 KB encrypted RCData in .rsrc. No hardcoded C2 recovered statically. Fourteenth confirmed sibling in the leaked-era batch; identical build fingerprint to the thirteen prior siblings catalogued at nanocore.

What It Is

  • File: jvegter.nl.exe — 207,872 bytes, PE32 GUI, Mono/.NET assembly, 3 sections. ^[file.txt]
  • Compile stamp: 22 Feb 2015 00:49:37 UTC (0x54E927A1). Matches the thirteen prior siblings to the second. ^[pefile.txt]
  • CLR: .NET Framework 2.0 (v2.0.50727, mscorlib). ^[strings.txt:51]
  • Language: VB.NET (Microsoft.VisualBasic, Microsoft.VisualBasic.Devices, Microsoft.VisualBasic.ApplicationServices). ^[strings.txt:58,70,78]
  • Builder: NanoCore Client v1.2.2.0 (1.2.2.0 at strings offset 1626). ^[strings.txt:1626]
  • Obfuscator: ConfuserEx — mass name mangling (#=q...== pattern, ~330 mangled symbols). ^[strings.txt:278-330]
  • Signing: Unsigned. ^[pefile.txt:Security directory empty]
  • IAT: Single import mscoree.dll._CorExeMain. ^[pefile.txt:199]
  • Sections: .text (code, entropy 6.60), .reloc (0.10), .rsrc (entropy 7.998, 90,464 bytes encrypted RCData). ^[pefile.txt:sections]
  • GUID: 08186e7b-fc6a-4a22-832f-d29dc50a34fc (MyTemplate). ^[strings.txt:1624]
  • Unique in cluster: Dutch TLD masquerade (jvegter.nl), distinguishing it from the .ru.com (b6008cf6), .nl (112d957b), .in (e4ee45f1), and .yellowred.in (e4ee45f1) siblings.

How It Works

Standard NanoCore v1.2.2.0 deployment chain inferred from static evidence and cluster behavior:

  1. Staging: On first run, copies itself to %AppData% or %TEMP% and writes a Registry Run key for persistence. ^[capa.txt:95-99]
  2. Decryption: The .rsrc RCData (~90 KB) is decrypted at runtime using RijndaelManaged + DeflateStream (confirmed in type references). ^[strings.txt:152,232]
  3. Plugin Loading: Decrypted payload unpacks into plugin modules loaded via the IClientAppHost / IClientPluginHost / IClientNetworkHost interface surface. ^[strings.txt:86-97]
  4. C2: Builder-configured host/port list stored in the encrypted resource. No plaintext IP/domain in static strings. AddHostEntry and RebuildHostCache methods allow runtime host updates. ^[strings.txt:468,470]
  5. Communication: Raw TCP sockets (Socket, SocketAsyncEventArgs, IPEndPoint, IPAddress). DNS resolution via dnsapi.dll. Keepalive framing with SendToServer / Disconnect. ^[strings.txt:168-180,464,463]
  6. Discovery: System info (get_OSVersion, get_Version), hostname (get_hostname), username (get_UserName), file/directory enumeration, registry queries. ^[capa.txt:15-22]
  7. Process Control: Creates processes (6 matches), terminates processes (4), suspends threads (6), creates mutex for single-instance gating. ^[capa.txt:54-57,86]

Decompiled Behavior

Radare2 analysis (level 2) identified 858 CIL functions with no named symbols due to ConfuserEx stripping. ^[r2:analysis] The entrypoint is the standard _CorExeMain bootstrap. No anti-debug or VM-detection API references observed statically. CIL decompilation was limited by the obfuscator; no meaningful pseudo-C recovered for individual methods. The control-flow surface is dominated by encrypted resource staging and reflective plugin dispatch via the ClientInvokeDelegate pattern. ^[strings.txt:84]

C2 Infrastructure

  • Static recovery: None. No hardcoded IP, domain, or URL in plaintext strings.
  • Builder-configured: Host/port list lives inside the encrypted .rsrc RCData payload. ^[pefile.txt:rsrc]
  • Dynamic inference: Runtime host list managed via AddHostEntry and RebuildHostCache, permitting server-driven C2 rotation. ^[strings.txt:468,470]
  • Protocol: Raw TCP sockets (not HTTP/HTTPS). DNS resolution for hostnames. ^[capa.txt:62-66]
  • Network APIs: System.Net.Sockets.Socket, SocketAsyncEventArgs, IPEndPoint, IPAddress, DnsRecord. ^[strings.txt:168-180]

Interesting Tidbits

  • Filename masquerade: jvegter.nl.exe — Dutch domain pattern consistent with the gwwsite.nl.exe sibling (112d957b). Both use .nl TLD lures, suggesting a batch of builder outputs targeting Dutch-speaking victims or using Dutch domains as social-engineering camouflage. ^[triage.json]
  • FLOSS failure: flare-floss failed with argument-parsing error; no decoded stacked strings recovered. ConfuserEx string encryption remains intact against static string tools. ^[floss.txt]
  • MD5 hashing: Four capa matches for MD5 hashing, likely used for config integrity or packet checksums. ^[capa.txt:66]
  • No CAPE detonation: Windows guest unavailable; all behavior is statically inferred. ^[dynamic-analysis.md]

How To Mess With It (Homelab Replication)

Goal: Build a NanoCore-like .NET RAT stub with ConfuserEx obfuscation and encrypted resource payload.

  1. Toolchain: Visual Studio or SharpDevelop, targeting .NET Framework 2.0.
  2. Stub: Write a VB.NET or C# WinForms app with a minimal ClientLoaderForm that loads an embedded .rsrc RCData blob.
  3. Encryption: Encrypt the inner payload with RijndaelManaged (AES-256) + DeflateStream (GZip). Store the key/IV in the stub or derive from a hardcoded salt via Rfc2898DeriveBytes.
  4. Obfuscation: Run the compiled EXE through ConfuserEx (open-source, still available). Enable name mangling, control-flow flattening, and string encryption.
  5. Verification: Run capa on the output. Expect hits: compiled to the .NET platform, access .NET resource, extract resource via kernel32, create TCP socket, hash data with MD5.

What you learn: How ConfuserEx transforms a trivial .NET stub into an 858-function maze with no readable symbols, and how resource encryption hides the real payload from static tools.

Deployable Signatures

YARA Rule

rule nanocore_v1220_feb2015_batch
{
    meta:
        description = "NanoCore Client v1.2.2.0 Feb 2015 leaked batch — ConfuserEx obfuscated .NET RAT"
        author = "PacketPursuit SOC"
        date = "2026-08-12"
        sha256 = "930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56"
    strings:
        $a1 = "NanoCore Client" ascii wide
        $a2 = "NanoCore Client.exe" ascii wide
        $a3 = "IClientApp" ascii wide
        $a4 = "IClientNetwork" ascii wide
        $a5 = "IClientPluginHost" ascii wide
        $a6 = "BuilderSettings" ascii wide
        $a7 = "ClientSettings" ascii wide
        $a8 = "1.2.2.0" ascii wide
        $b1 = "AddHostEntry" ascii wide
        $b2 = "RebuildHostCache" ascii wide
        $b3 = "SendToServer" ascii wide
        $b4 = "ClientInvokeDelegate" ascii wide
        $c1 = { 4D 5A }  // PE header
    condition:
        $c1 at 0 and
        (uint16(uint32(0x3C) + 0x14) == 0x14C) and  // 32-bit
        uint32(uint32(0x3C) + 0x80) == 0x00004550 and  // PE signature
        filesize < 300KB and
        4 of ($a*) and
        2 of ($b*)
}

Behavioral Fingerprint

This binary is a .NET Framework 2.0 PE32 executable with a minimal IAT (only mscoree.dll._CorExeMain), three sections including a .rsrc section exceeding 80 KB with near-maximum entropy (~7.99). On execution, it creates a mutex for single-instance gating, copies itself to %AppData%, writes a Registry Run key, decrypts the .rsrc RCData via RijndaelManaged + DeflateStream, and opens a raw TCP socket to a builder-configured host. No HTTP/HTTPS traffic; C2 is plain TCP with keepalive framing. Plugin modules are loaded reflectively from the decrypted resource via IClientAppHost interface dispatch.

IOC List

Type Value Notes
SHA-256 930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56 Sample
MD5 1f5629ba6f20e4c7b4a55e736797f956 Sample
Filename jvegter.nl.exe Social-engineering lure
GUID 08186e7b-fc6a-4a22-832f-d29dc50a34fc MyTemplate GUID (unique per build)
Builder version 1.2.2.0 NanoCore Client version
Compile time 2015-02-22 00:49:37 UTC Batch timestamp
Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run Persistence (inferred)
Mutex Unknown Single-instance gating (capa match)
Network Raw TCP sockets No hardcoded IP/domain recovered

Detection Signatures

  • MITRE ATT&CK: T1547.001 (Registry Run Keys), T1055 (Process Injection — reflective plugin loading), T1083 (File and Directory Discovery), T1082 (System Information Discovery), T1012 (Query Registry), T1033 (System Owner/User Discovery), T1087 (Account Discovery), T1620 (Reflective Code Loading), T1112 (Modify Registry), T1041 (Exfiltration Over C2 Channel), T1071.001 (Application Layer Protocol — custom TCP). ^[capa.txt]
  • MBC: C2 Communication (Send/Receive Data), DNS Resolution, TCP Socket Creation, MD5 Hashing, File Copy/Create/Delete/Write, Mutex Creation, Process Create/Terminate, Registry Query/Set, Thread Suspend. ^[capa.txt]

References

  • nanocore — cluster entity page with thirteen prior siblings and full build-stack analysis.
  • confuserex-obfuscation — obfuscator technique page.
  • registry-run-persistence — persistence mechanism.
  • raw-tcp-c2-socket — C2 communication pattern.
  • MalwareBazaar: 930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56
  • OpenCTI artifact: 672cccd7-8aef-4593-8c97-da45375022ce

Provenance

Analysis derived from static artifacts: file.txt, exiftool.json, pefile.txt, strings.txt, capa.txt, rabin2-info.txt, floss.txt (failed), dynamic-analysis.md (CAPE skipped, no Windows guest), triage.json. Radare2 level-2 analysis performed on the binary. No dynamic execution data available. All behavioral claims are statically inferred from the NanoCore v1.2.2.0 cluster pattern unless explicitly marked with a capa provenance marker.