typeanalysisfamilynanocoreconfidencehighcreated2026-08-18updated2026-08-18malware-familyratdotnetobfuscationc2persistencedefense-evasionmitre-attck
SHA-256: 96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910

nanocore: 96ddc5067 — Dutch domain masquerade (cash-win.nl), builder v1.2.2.0, Feb 2015 batch sibling #19

Executive Summary

Nineteenth confirmed sibling in the leaked-era NanoCore v1.2.2.0 builder batch (22 Feb 2015 00:49:37 UTC). Masquerades as a Dutch domain (cash-win.nl.exe). ConfuserEx-obfuscated VB.NET client with identical builder fingerprint to the prior eighteen — same timestamp, same version, same plugin-host interface surface. No hardcoded C2 recovered; host list encrypted inside the ~90 KB RCData resource. Static-only (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: 96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910 ^[file.txt]
  • File name: cash-win.nl.exe (Dutch domain social-engineering masquerade) ^[metadata.json]
  • Size: 207,872 bytes (203 KB) ^[triage.json]
  • Type: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt]
  • Compile timestamp: 2015-02-22 00:49:37 UTC ^[exiftool.json]
  • Builder version: 1.2.2.0 (confirmed via AssemblyFileVersionAttribute in strings) ^[strings.txt:1626]
  • Unique GUID: 21b9771a-0ead-4a20-9584-91c88cd03202 (MyTemplate auto-generated project GUID) ^[strings.txt:1624]
  • Family: NanoCore RAT — high-confidence, matches the Feb 2015 batch cluster documented at nanocore.
  • Signing: Unsigned. No Authenticode. ^[pefile.txt:152-154]

How It Works

Standard NanoCore Client built with the leaked v1.2.2.0 builder. Runtime flow (inferred from static, consistent with cluster behaviour documented in nanocore):

  1. Entry: CLR loads via mscoree!_CorExeMain; only static import. ^[pefile.txt:199]
  2. Obfuscation: ConfuserEx mass name-mangling (#=q…==) on every class/method/field — 618 mangled identifiers observed. ^[strings.txt]
  3. Resource decryption: Reads encrypted payload from .rsrc RCData (89,952 bytes, entropy near-maximum). Decrypts with RijndaelManaged → DeflateStream pipeline. ^[strings.txt:152,232]
  4. Plugin host bootstrap: Instantiates IClientAppHost, IClientNetworkHost, IClientUIHost, IClientDataHost, IClientLoggingHost. ^[strings.txt:85-97]
  5. C2 connection: Raw TCP socket to builder-configured host/port list; supports dynamic host-cache updates via AddHostEntry / RebuildHostCache. ^[strings.txt:468,470] ^[capa.txt:62-66]
  6. Persistence: Likely registry Run key or self-copy to %AppData% / %TEMP% (cluster behaviour; not observed statically in this sample). ^[capa.txt:95-99]
  7. Discovery: Hostname, OS version, user name, file/directory enumeration, registry queries. ^[capa.txt:15-22]

Decompiled Behavior

Static-only; Ghidra decompilation not attempted because the binary is a heavily obfuscated .NET assembly with 618+ mangled CIL methods and no meaningful native-code entry point. r2 analysis confirms CIL architecture with 858 functions but names are stripped/mangled. ^[rabin2-info.txt] The entire malicious logic lives inside obfuscated CIL; native disassembly yields only the CLR bootstrap thunk (_CorExeMain). For behavioural detail, see the capa.txt capability map and the cluster page nanocore.

C2 Infrastructure

  • Hardcoded C2: None recovered statically. Host list is encrypted inside the RCData resource and decrypted at runtime. ^[pefile.txt:203-239]
  • Protocol: Raw TCP sockets (builder-configured port). Keepalive framing inferred from cluster analysis. ^[capa.txt:62-66]
  • DNS: dnsapi.dll imported (likely used for DnsRecord resolution). ^[strings.txt:67,343]
  • Named pipes: ClientLoaderForm uses PipeExists, ClosePipe, SendToServer, Disconnect. IPC between plugin modules. ^[strings.txt:344,458-464]

Interesting Tidbits

  • Filename masquerades as a Dutch domain (cash-win.nl.exe) — a common builder-era trick to appear legitimate in email attachments. ^[metadata.json]
  • Builder GUID 21b9771a-… is unique to this sample; every sibling in the batch gets a fresh auto-generated GUID, confirming point-and-click mass generation. ^[strings.txt:1624]
  • The .rsrc section entropy is 7.998 (near-maximum), indicating strong encryption of the embedded host-list / plugin package. ^[pefile.txt:132]
  • ClientSettings and BuilderSettings properties present in strings, confirming the builder writes its config into the compiled binary. ^[strings.txt:411-412,1401-1402]
  • No anti-VM or anti-debug strings observed; NanoCore relies on ConfuserEx obfuscation and runtime host-list decryption for evasion. ^[capa.txt]
  • 143 strings are unique to this sample versus sibling e4774281 (16th sibling), but all are either mangled ConfuserEx noise or encrypted RCData bytes — no functional divergence.

How To Mess With It (Homelab Replication)

  1. Obtain the leaked NanoCore builder v1.2.2.0 (circulates on underground forums and malware research repositories).
  2. Target: .NET Framework 2.0/3.5/4.x client profile.
  3. Build: Enter C2 host/port in the builder GUI, click Build. Output is a ~200 KB PE32 with 3 sections.
  4. Obfuscation: Run through ConfuserEx (max preset) to reproduce the #=q…== name mangling.
  5. Verification: capa should hit: compiled to .NET platform, load .NET assembly, create TCP socket, resolve DNS, hash data with MD5, query registry, create process in .NET, create mutex, suspend thread, file-system read/write/delete/copy.
  6. What you learn: How a point-and-click RAT builder turns a configuration dialog into a self-contained, obfuscated C2 client with plugin architecture.

Deployable Signatures

YARA rule

rule nanocore_v1220_confuserex_batch {
    meta:
        description = "NanoCore v1.2.2.0 ConfuserEx-obfuscated client, Feb 2015 batch"
        author = "PacketPursuit"
        date = "2026-08-18"
        sha256 = "96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910"
    strings:
        $s1 = "NanoCore Client" ascii wide
        $s2 = "NanoCore Client.exe" ascii wide
        $s3 = "IClientAppHost" ascii wide
        $s4 = "IClientNetworkHost" ascii wide
        $s5 = "IClientUIHost" ascii wide
        $s6 = "AddHostEntry" ascii wide
        $s7 = "RebuildHostCache" ascii wide
        $s8 = "RijndaelManaged" ascii wide
        $s9 = "DeflateStream" ascii wide
        $s10 = "ClientSettings" ascii wide
        $s11 = "BuilderSettings" ascii wide
        $s12 = "MyTemplate" ascii wide
        $s13 = "1.2.2.0" ascii wide
        $confuser = /#=q[A-Za-z0-9_$+/=]{10,}==/ ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        6 of ($s*) and
        #confuser > 300
}

Behavioral hunt query (Sigma-like)

title: NanoCore Client Process Spawn
description: Detects NanoCore client process behaviour — hidden window, .NET assembly load, registry queries, and TCP socket creation within 5 seconds of launch.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - 'NanoCore Client'
            - 'cash-win.nl'
    condition: selection

IOC list

Indicator Type Value Provenance
SHA-256 hash 96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910 metadata.json
File name filename cash-win.nl.exe triage.json
Builder version version 1.2.2.0 strings.txt:1626
MyTemplate GUID guid 21b9771a-0ead-4a20-9584-91c88cd03202 strings.txt:1624
Compile timestamp timestamp 2015-02-22 00:49:37 UTC exiftool.json
RCData resource resource RT_RCDATA, 89,952 bytes, offset 0x22058 pefile.txt
SSDeep fuzzy hash 6144:MLV6Bta6dtJmakIM5n6fA+eXcTTacsRy3Cj+E:MLV6BtpmkSuA+eXsaDCUD ssdeep.txt
TLSH fuzzy hash 6D14CF6537E8492EE3DE867C701242029379C2E398D3F3EE28D461B69F663E44A471D7 tlsh.txt

Behavioral fingerprint statement

This binary is a PE32 .NET assembly that loads via mscoree.dll!_CorExeMain, resolves all APIs via reflection, and carries a high-entropy RCData resource (~90 KB) encrypted with RijndaelManaged and compressed with DeflateStream. On launch it instantiates a hidden WinForms client loader, queries the registry and file system for environment discovery, opens raw TCP sockets to a builder-configured C2 host list, and maintains a mutable host cache via AddHostEntry / RebuildHostCache. Plugin modules communicate via named pipes. The entire CIL surface is obfuscated with ConfuserEx #=q…== name mangling (600+ identifiers). No hardcoded C2 is present in the binary — the config is encrypted in resources.

Detection Signatures (capa → ATT&CK)

ATT&CK Tactic Technique Evidence
DEFENSE EVASION T1112 Modify Registry capa: set registry value (2 matches), delete registry value (2 matches) ^[capa.txt:15,98-99]
DEFENSE EVASION T1620 Reflective Code Loading capa: load .NET assembly (2 matches) ^[capa.txt:104]
DISCOVERY T1087 Account Discovery capa: get session user name (2 matches) ^[capa.txt:21]
DISCOVERY T1083 File and Directory Discovery capa: enumerate files in .NET (2 matches), check if directory exists ^[capa.txt:18,80]
DISCOVERY T1012 Query Registry capa: query or enumerate registry key (6 matches), query or enumerate registry value (5 matches) ^[capa.txt:20,94-97]
DISCOVERY T1082 System Information Discovery capa: get OS version in .NET, get hostname ^[capa.txt:19,88-89]
DISCOVERY T1033 System Owner/User Discovery capa: get session user name (2 matches) ^[capa.txt:22]
COMMUNICATION C0011.001 DNS Communication::Resolve capa: resolve DNS ^[capa.txt:64]
COMMUNICATION C0001.011 Socket Communication::Create TCP Socket capa: create TCP socket ^[capa.txt:65]
FILE SYSTEM C0045 Copy File capa: copy file (3 matches) ^[capa.txt:74]
FILE SYSTEM C0046 Create Directory capa: create directory (4 matches) ^[capa.txt:75]
FILE SYSTEM C0048 Delete Directory capa: delete directory ^[capa.txt:76]
FILE SYSTEM C0047 Delete File capa: delete file (9 matches) ^[capa.txt:77]
FILE SYSTEM C0051 Read File capa: read file in .NET (6 matches) ^[capa.txt:82]
FILE SYSTEM C0052 Writes File capa: write file in .NET (7 matches) ^[capa.txt:83]
PROCESS C0017 Create Process capa: create process in .NET (6 matches) ^[capa.txt:91]
PROCESS C0018 Terminate Process capa: terminate process (4 matches) ^[capa.txt:93]
PROCESS C0055 Suspend Thread capa: suspend thread (6 matches) ^[capa.txt:102]

References

  • nanocore — Cluster entity page with full sibling list and shared TTPs.
  • confuserex-obfuscation — Technique page for the obfuscator fingerprint.
  • NanoCore v1.2.2.0 builder leak (underground forums, ~2015).
  • MalwareBazaar entry: artifact ID 93881994-4d3c-4e6d-8108-35e593ff5953 ^[metadata.json]

Provenance

  • file.txt — file(1) output
  • exiftool.json — ExifTool PE metadata
  • pefile.txt — pefile Python library DOS/NT headers, sections, imports
  • strings.txt — strings(1) output, 1770 lines
  • capa.txt — Mandiant flare-capa v7.5.0 static analysis
  • floss.txt — FireEye flare-floss (failed due to CLI arg error, no decoded strings)
  • binwalk.txt — binwalk v2.3.4 signature scan
  • rabin2-info.txt — radare2 v5.9.6 binary info
  • ssdeep.txt — ssdeep fuzzy hash
  • tlsh.txt — Trend Micro Locality Sensitive Hash
  • metadata.json — OpenCTI artifact metadata
  • triage.json — PacketPursuit triage pipeline output
  • dynamic-analysis.md — CAPE sandbox status (skipped, no Windows guest)