930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56nanocore: 930b692d — jvegter.nl.exe, fourteenth confirmed Feb 2015 v1.2.2.0 sibling
Executive Summary
NanoCore Client v1.2.2.0 built 22 Feb 2015 00:49:37 UTC, ConfuserEx-obfuscated VB.NET payload masquerading as a Dutch domain (jvegter.nl.exe). Unique MyTemplate GUID 08186e7b-fc6a-4a22-832f-d29dc50a34fc. ~90 KB encrypted RCData in .rsrc. No hardcoded C2 recovered statically. Fourteenth confirmed sibling in the leaked-era batch; identical build fingerprint to the thirteen prior siblings catalogued at nanocore.
What It Is
- File:
jvegter.nl.exe— 207,872 bytes, PE32 GUI, Mono/.NET assembly, 3 sections. ^[file.txt] - Compile stamp: 22 Feb 2015 00:49:37 UTC (
0x54E927A1). Matches the thirteen prior siblings to the second. ^[pefile.txt] - CLR: .NET Framework 2.0 (
v2.0.50727,mscorlib). ^[strings.txt:51] - Language: VB.NET (
Microsoft.VisualBasic,Microsoft.VisualBasic.Devices,Microsoft.VisualBasic.ApplicationServices). ^[strings.txt:58,70,78] - Builder: NanoCore Client v1.2.2.0 (
1.2.2.0at strings offset 1626). ^[strings.txt:1626] - Obfuscator: ConfuserEx — mass name mangling (
#=q...==pattern, ~330 mangled symbols). ^[strings.txt:278-330] - Signing: Unsigned. ^[pefile.txt:Security directory empty]
- IAT: Single import
mscoree.dll._CorExeMain. ^[pefile.txt:199] - Sections:
.text(code, entropy 6.60),.reloc(0.10),.rsrc(entropy 7.998, 90,464 bytes encrypted RCData). ^[pefile.txt:sections] - GUID:
08186e7b-fc6a-4a22-832f-d29dc50a34fc(MyTemplate). ^[strings.txt:1624] - Unique in cluster: Dutch TLD masquerade (
jvegter.nl), distinguishing it from the.ru.com(b6008cf6),.nl(112d957b),.in(e4ee45f1), and.yellowred.in(e4ee45f1) siblings.
How It Works
Standard NanoCore v1.2.2.0 deployment chain inferred from static evidence and cluster behavior:
- Staging: On first run, copies itself to
%AppData%or%TEMP%and writes a Registry Run key for persistence. ^[capa.txt:95-99] - Decryption: The
.rsrcRCData (~90 KB) is decrypted at runtime usingRijndaelManaged+DeflateStream(confirmed in type references). ^[strings.txt:152,232] - Plugin Loading: Decrypted payload unpacks into plugin modules loaded via the
IClientAppHost/IClientPluginHost/IClientNetworkHostinterface surface. ^[strings.txt:86-97] - C2: Builder-configured host/port list stored in the encrypted resource. No plaintext IP/domain in static strings.
AddHostEntryandRebuildHostCachemethods allow runtime host updates. ^[strings.txt:468,470] - Communication: Raw TCP sockets (
Socket,SocketAsyncEventArgs,IPEndPoint,IPAddress). DNS resolution viadnsapi.dll. Keepalive framing withSendToServer/Disconnect. ^[strings.txt:168-180,464,463] - Discovery: System info (
get_OSVersion,get_Version), hostname (get_hostname), username (get_UserName), file/directory enumeration, registry queries. ^[capa.txt:15-22] - Process Control: Creates processes (6 matches), terminates processes (4), suspends threads (6), creates mutex for single-instance gating. ^[capa.txt:54-57,86]
Decompiled Behavior
Radare2 analysis (level 2) identified 858 CIL functions with no named symbols due to ConfuserEx stripping. ^[r2:analysis] The entrypoint is the standard _CorExeMain bootstrap. No anti-debug or VM-detection API references observed statically. CIL decompilation was limited by the obfuscator; no meaningful pseudo-C recovered for individual methods. The control-flow surface is dominated by encrypted resource staging and reflective plugin dispatch via the ClientInvokeDelegate pattern. ^[strings.txt:84]
C2 Infrastructure
- Static recovery: None. No hardcoded IP, domain, or URL in plaintext strings.
- Builder-configured: Host/port list lives inside the encrypted
.rsrcRCData payload. ^[pefile.txt:rsrc] - Dynamic inference: Runtime host list managed via
AddHostEntryandRebuildHostCache, permitting server-driven C2 rotation. ^[strings.txt:468,470] - Protocol: Raw TCP sockets (not HTTP/HTTPS). DNS resolution for hostnames. ^[capa.txt:62-66]
- Network APIs:
System.Net.Sockets.Socket,SocketAsyncEventArgs,IPEndPoint,IPAddress,DnsRecord. ^[strings.txt:168-180]
Interesting Tidbits
- Filename masquerade:
jvegter.nl.exe— Dutch domain pattern consistent with thegwwsite.nl.exesibling (112d957b). Both use.nlTLD lures, suggesting a batch of builder outputs targeting Dutch-speaking victims or using Dutch domains as social-engineering camouflage. ^[triage.json] - FLOSS failure:
flare-flossfailed with argument-parsing error; no decoded stacked strings recovered. ConfuserEx string encryption remains intact against static string tools. ^[floss.txt] - MD5 hashing: Four capa matches for MD5 hashing, likely used for config integrity or packet checksums. ^[capa.txt:66]
- No CAPE detonation: Windows guest unavailable; all behavior is statically inferred. ^[dynamic-analysis.md]
How To Mess With It (Homelab Replication)
Goal: Build a NanoCore-like .NET RAT stub with ConfuserEx obfuscation and encrypted resource payload.
- Toolchain: Visual Studio or SharpDevelop, targeting .NET Framework 2.0.
- Stub: Write a VB.NET or C# WinForms app with a minimal
ClientLoaderFormthat loads an embedded.rsrcRCData blob. - Encryption: Encrypt the inner payload with
RijndaelManaged(AES-256) +DeflateStream(GZip). Store the key/IV in the stub or derive from a hardcoded salt viaRfc2898DeriveBytes. - Obfuscation: Run the compiled EXE through ConfuserEx (open-source, still available). Enable name mangling, control-flow flattening, and string encryption.
- Verification: Run
capaon the output. Expect hits:compiled to the .NET platform,access .NET resource,extract resource via kernel32,create TCP socket,hash data with MD5.
What you learn: How ConfuserEx transforms a trivial .NET stub into an 858-function maze with no readable symbols, and how resource encryption hides the real payload from static tools.
Deployable Signatures
YARA Rule
rule nanocore_v1220_feb2015_batch
{
meta:
description = "NanoCore Client v1.2.2.0 Feb 2015 leaked batch — ConfuserEx obfuscated .NET RAT"
author = "PacketPursuit SOC"
date = "2026-08-12"
sha256 = "930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56"
strings:
$a1 = "NanoCore Client" ascii wide
$a2 = "NanoCore Client.exe" ascii wide
$a3 = "IClientApp" ascii wide
$a4 = "IClientNetwork" ascii wide
$a5 = "IClientPluginHost" ascii wide
$a6 = "BuilderSettings" ascii wide
$a7 = "ClientSettings" ascii wide
$a8 = "1.2.2.0" ascii wide
$b1 = "AddHostEntry" ascii wide
$b2 = "RebuildHostCache" ascii wide
$b3 = "SendToServer" ascii wide
$b4 = "ClientInvokeDelegate" ascii wide
$c1 = { 4D 5A } // PE header
condition:
$c1 at 0 and
(uint16(uint32(0x3C) + 0x14) == 0x14C) and // 32-bit
uint32(uint32(0x3C) + 0x80) == 0x00004550 and // PE signature
filesize < 300KB and
4 of ($a*) and
2 of ($b*)
}
Behavioral Fingerprint
This binary is a .NET Framework 2.0 PE32 executable with a minimal IAT (only mscoree.dll._CorExeMain), three sections including a .rsrc section exceeding 80 KB with near-maximum entropy (~7.99). On execution, it creates a mutex for single-instance gating, copies itself to %AppData%, writes a Registry Run key, decrypts the .rsrc RCData via RijndaelManaged + DeflateStream, and opens a raw TCP socket to a builder-configured host. No HTTP/HTTPS traffic; C2 is plain TCP with keepalive framing. Plugin modules are loaded reflectively from the decrypted resource via IClientAppHost interface dispatch.
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56 |
Sample |
| MD5 | 1f5629ba6f20e4c7b4a55e736797f956 |
Sample |
| Filename | jvegter.nl.exe |
Social-engineering lure |
| GUID | 08186e7b-fc6a-4a22-832f-d29dc50a34fc |
MyTemplate GUID (unique per build) |
| Builder version | 1.2.2.0 |
NanoCore Client version |
| Compile time | 2015-02-22 00:49:37 UTC |
Batch timestamp |
| Registry | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
Persistence (inferred) |
| Mutex | Unknown | Single-instance gating (capa match) |
| Network | Raw TCP sockets | No hardcoded IP/domain recovered |
Detection Signatures
- MITRE ATT&CK: T1547.001 (Registry Run Keys), T1055 (Process Injection — reflective plugin loading), T1083 (File and Directory Discovery), T1082 (System Information Discovery), T1012 (Query Registry), T1033 (System Owner/User Discovery), T1087 (Account Discovery), T1620 (Reflective Code Loading), T1112 (Modify Registry), T1041 (Exfiltration Over C2 Channel), T1071.001 (Application Layer Protocol — custom TCP). ^[capa.txt]
- MBC: C2 Communication (Send/Receive Data), DNS Resolution, TCP Socket Creation, MD5 Hashing, File Copy/Create/Delete/Write, Mutex Creation, Process Create/Terminate, Registry Query/Set, Thread Suspend. ^[capa.txt]
References
- nanocore — cluster entity page with thirteen prior siblings and full build-stack analysis.
- confuserex-obfuscation — obfuscator technique page.
- registry-run-persistence — persistence mechanism.
- raw-tcp-c2-socket — C2 communication pattern.
- MalwareBazaar:
930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56 - OpenCTI artifact:
672cccd7-8aef-4593-8c97-da45375022ce
Provenance
Analysis derived from static artifacts: file.txt, exiftool.json, pefile.txt, strings.txt, capa.txt, rabin2-info.txt, floss.txt (failed), dynamic-analysis.md (CAPE skipped, no Windows guest), triage.json. Radare2 level-2 analysis performed on the binary. No dynamic execution data available. All behavioral claims are statically inferred from the NanoCore v1.2.2.0 cluster pattern unless explicitly marked with a capa provenance marker.