96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910nanocore: 96ddc5067 — Dutch domain masquerade (cash-win.nl), builder v1.2.2.0, Feb 2015 batch sibling #19
Executive Summary
Nineteenth confirmed sibling in the leaked-era NanoCore v1.2.2.0 builder batch (22 Feb 2015 00:49:37 UTC). Masquerades as a Dutch domain (cash-win.nl.exe). ConfuserEx-obfuscated VB.NET client with identical builder fingerprint to the prior eighteen — same timestamp, same version, same plugin-host interface surface. No hardcoded C2 recovered; host list encrypted inside the ~90 KB RCData resource. Static-only (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910^[file.txt] - File name:
cash-win.nl.exe(Dutch domain social-engineering masquerade) ^[metadata.json] - Size: 207,872 bytes (203 KB) ^[triage.json]
- Type: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt]
- Compile timestamp: 2015-02-22 00:49:37 UTC ^[exiftool.json]
- Builder version:
1.2.2.0(confirmed viaAssemblyFileVersionAttributein strings) ^[strings.txt:1626] - Unique GUID:
21b9771a-0ead-4a20-9584-91c88cd03202(MyTemplate auto-generated project GUID) ^[strings.txt:1624] - Family: NanoCore RAT — high-confidence, matches the Feb 2015 batch cluster documented at nanocore.
- Signing: Unsigned. No Authenticode. ^[pefile.txt:152-154]
How It Works
Standard NanoCore Client built with the leaked v1.2.2.0 builder. Runtime flow (inferred from static, consistent with cluster behaviour documented in nanocore):
- Entry: CLR loads via
mscoree!_CorExeMain; only static import. ^[pefile.txt:199] - Obfuscation: ConfuserEx mass name-mangling (
#=q…==) on every class/method/field — 618 mangled identifiers observed. ^[strings.txt] - Resource decryption: Reads encrypted payload from
.rsrcRCData (89,952 bytes, entropy near-maximum). Decrypts withRijndaelManaged→DeflateStreampipeline. ^[strings.txt:152,232] - Plugin host bootstrap: Instantiates
IClientAppHost,IClientNetworkHost,IClientUIHost,IClientDataHost,IClientLoggingHost. ^[strings.txt:85-97] - C2 connection: Raw TCP socket to builder-configured host/port list; supports dynamic host-cache updates via
AddHostEntry/RebuildHostCache. ^[strings.txt:468,470] ^[capa.txt:62-66] - Persistence: Likely registry Run key or self-copy to
%AppData%/%TEMP%(cluster behaviour; not observed statically in this sample). ^[capa.txt:95-99] - Discovery: Hostname, OS version, user name, file/directory enumeration, registry queries. ^[capa.txt:15-22]
Decompiled Behavior
Static-only; Ghidra decompilation not attempted because the binary is a heavily obfuscated .NET assembly with 618+ mangled CIL methods and no meaningful native-code entry point. r2 analysis confirms CIL architecture with 858 functions but names are stripped/mangled. ^[rabin2-info.txt] The entire malicious logic lives inside obfuscated CIL; native disassembly yields only the CLR bootstrap thunk (_CorExeMain). For behavioural detail, see the capa.txt capability map and the cluster page nanocore.
C2 Infrastructure
- Hardcoded C2: None recovered statically. Host list is encrypted inside the RCData resource and decrypted at runtime. ^[pefile.txt:203-239]
- Protocol: Raw TCP sockets (builder-configured port). Keepalive framing inferred from cluster analysis. ^[capa.txt:62-66]
- DNS:
dnsapi.dllimported (likely used forDnsRecordresolution). ^[strings.txt:67,343] - Named pipes:
ClientLoaderFormusesPipeExists,ClosePipe,SendToServer,Disconnect. IPC between plugin modules. ^[strings.txt:344,458-464]
Interesting Tidbits
- Filename masquerades as a Dutch domain (
cash-win.nl.exe) — a common builder-era trick to appear legitimate in email attachments. ^[metadata.json] - Builder GUID
21b9771a-…is unique to this sample; every sibling in the batch gets a fresh auto-generated GUID, confirming point-and-click mass generation. ^[strings.txt:1624] - The
.rsrcsection entropy is 7.998 (near-maximum), indicating strong encryption of the embedded host-list / plugin package. ^[pefile.txt:132] ClientSettingsandBuilderSettingsproperties present in strings, confirming the builder writes its config into the compiled binary. ^[strings.txt:411-412,1401-1402]- No anti-VM or anti-debug strings observed; NanoCore relies on ConfuserEx obfuscation and runtime host-list decryption for evasion. ^[capa.txt]
- 143 strings are unique to this sample versus sibling
e4774281(16th sibling), but all are either mangled ConfuserEx noise or encrypted RCData bytes — no functional divergence.
How To Mess With It (Homelab Replication)
- Obtain the leaked NanoCore builder v1.2.2.0 (circulates on underground forums and malware research repositories).
- Target: .NET Framework 2.0/3.5/4.x client profile.
- Build: Enter C2 host/port in the builder GUI, click Build. Output is a ~200 KB PE32 with 3 sections.
- Obfuscation: Run through ConfuserEx (max preset) to reproduce the
#=q…==name mangling. - Verification:
capashould hit:compiled to .NET platform,load .NET assembly,create TCP socket,resolve DNS,hash data with MD5,query registry,create process in .NET,create mutex,suspend thread,file-system read/write/delete/copy. - What you learn: How a point-and-click RAT builder turns a configuration dialog into a self-contained, obfuscated C2 client with plugin architecture.
Deployable Signatures
YARA rule
rule nanocore_v1220_confuserex_batch {
meta:
description = "NanoCore v1.2.2.0 ConfuserEx-obfuscated client, Feb 2015 batch"
author = "PacketPursuit"
date = "2026-08-18"
sha256 = "96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910"
strings:
$s1 = "NanoCore Client" ascii wide
$s2 = "NanoCore Client.exe" ascii wide
$s3 = "IClientAppHost" ascii wide
$s4 = "IClientNetworkHost" ascii wide
$s5 = "IClientUIHost" ascii wide
$s6 = "AddHostEntry" ascii wide
$s7 = "RebuildHostCache" ascii wide
$s8 = "RijndaelManaged" ascii wide
$s9 = "DeflateStream" ascii wide
$s10 = "ClientSettings" ascii wide
$s11 = "BuilderSettings" ascii wide
$s12 = "MyTemplate" ascii wide
$s13 = "1.2.2.0" ascii wide
$confuser = /#=q[A-Za-z0-9_$+/=]{10,}==/ ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
6 of ($s*) and
#confuser > 300
}
Behavioral hunt query (Sigma-like)
title: NanoCore Client Process Spawn
description: Detects NanoCore client process behaviour — hidden window, .NET assembly load, registry queries, and TCP socket creation within 5 seconds of launch.
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'NanoCore Client'
- 'cash-win.nl'
condition: selection
IOC list
| Indicator | Type | Value | Provenance |
|---|---|---|---|
| SHA-256 | hash | 96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910 |
metadata.json |
| File name | filename | cash-win.nl.exe |
triage.json |
| Builder version | version | 1.2.2.0 |
strings.txt:1626 |
| MyTemplate GUID | guid | 21b9771a-0ead-4a20-9584-91c88cd03202 |
strings.txt:1624 |
| Compile timestamp | timestamp | 2015-02-22 00:49:37 UTC |
exiftool.json |
| RCData resource | resource | RT_RCDATA, 89,952 bytes, offset 0x22058 | pefile.txt |
| SSDeep | fuzzy hash | 6144:MLV6Bta6dtJmakIM5n6fA+eXcTTacsRy3Cj+E:MLV6BtpmkSuA+eXsaDCUD |
ssdeep.txt |
| TLSH | fuzzy hash | 6D14CF6537E8492EE3DE867C701242029379C2E398D3F3EE28D461B69F663E44A471D7 |
tlsh.txt |
Behavioral fingerprint statement
This binary is a PE32 .NET assembly that loads via mscoree.dll!_CorExeMain, resolves all APIs via reflection, and carries a high-entropy RCData resource (~90 KB) encrypted with RijndaelManaged and compressed with DeflateStream. On launch it instantiates a hidden WinForms client loader, queries the registry and file system for environment discovery, opens raw TCP sockets to a builder-configured C2 host list, and maintains a mutable host cache via AddHostEntry / RebuildHostCache. Plugin modules communicate via named pipes. The entire CIL surface is obfuscated with ConfuserEx #=q…== name mangling (600+ identifiers). No hardcoded C2 is present in the binary — the config is encrypted in resources.
Detection Signatures (capa → ATT&CK)
| ATT&CK Tactic | Technique | Evidence |
|---|---|---|
| DEFENSE EVASION | T1112 Modify Registry | capa: set registry value (2 matches), delete registry value (2 matches) ^[capa.txt:15,98-99] |
| DEFENSE EVASION | T1620 Reflective Code Loading | capa: load .NET assembly (2 matches) ^[capa.txt:104] |
| DISCOVERY | T1087 Account Discovery | capa: get session user name (2 matches) ^[capa.txt:21] |
| DISCOVERY | T1083 File and Directory Discovery | capa: enumerate files in .NET (2 matches), check if directory exists ^[capa.txt:18,80] |
| DISCOVERY | T1012 Query Registry | capa: query or enumerate registry key (6 matches), query or enumerate registry value (5 matches) ^[capa.txt:20,94-97] |
| DISCOVERY | T1082 System Information Discovery | capa: get OS version in .NET, get hostname ^[capa.txt:19,88-89] |
| DISCOVERY | T1033 System Owner/User Discovery | capa: get session user name (2 matches) ^[capa.txt:22] |
| COMMUNICATION | C0011.001 DNS Communication::Resolve | capa: resolve DNS ^[capa.txt:64] |
| COMMUNICATION | C0001.011 Socket Communication::Create TCP Socket | capa: create TCP socket ^[capa.txt:65] |
| FILE SYSTEM | C0045 Copy File | capa: copy file (3 matches) ^[capa.txt:74] |
| FILE SYSTEM | C0046 Create Directory | capa: create directory (4 matches) ^[capa.txt:75] |
| FILE SYSTEM | C0048 Delete Directory | capa: delete directory ^[capa.txt:76] |
| FILE SYSTEM | C0047 Delete File | capa: delete file (9 matches) ^[capa.txt:77] |
| FILE SYSTEM | C0051 Read File | capa: read file in .NET (6 matches) ^[capa.txt:82] |
| FILE SYSTEM | C0052 Writes File | capa: write file in .NET (7 matches) ^[capa.txt:83] |
| PROCESS | C0017 Create Process | capa: create process in .NET (6 matches) ^[capa.txt:91] |
| PROCESS | C0018 Terminate Process | capa: terminate process (4 matches) ^[capa.txt:93] |
| PROCESS | C0055 Suspend Thread | capa: suspend thread (6 matches) ^[capa.txt:102] |
References
- nanocore — Cluster entity page with full sibling list and shared TTPs.
- confuserex-obfuscation — Technique page for the obfuscator fingerprint.
- NanoCore v1.2.2.0 builder leak (underground forums, ~2015).
- MalwareBazaar entry: artifact ID
93881994-4d3c-4e6d-8108-35e593ff5953^[metadata.json]
Provenance
file.txt— file(1) outputexiftool.json— ExifTool PE metadatapefile.txt— pefile Python library DOS/NT headers, sections, importsstrings.txt— strings(1) output, 1770 linescapa.txt— Mandiant flare-capa v7.5.0 static analysisfloss.txt— FireEye flare-floss (failed due to CLI arg error, no decoded strings)binwalk.txt— binwalk v2.3.4 signature scanrabin2-info.txt— radare2 v5.9.6 binary infossdeep.txt— ssdeep fuzzy hashtlsh.txt— Trend Micro Locality Sensitive Hashmetadata.json— OpenCTI artifact metadatatriage.json— PacketPursuit triage pipeline outputdynamic-analysis.md— CAPE sandbox status (skipped, no Windows guest)