b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11nanocore: b0daeb6a — Dutch classical-music domain masquerade, builder v1.2.2.0
Executive Summary
Eighteenth confirmed sibling in the leaked NanoCore builder Feb 2015 batch. VB.NET WinForms client obfuscated with ConfuserEx, masquerading as the Dutch classical-music website schoenberg-ensemble.nl. Identical builder version 1.2.2.0 and timestamp to the rest of the batch; unique MyTemplate GUID and ~90 KB encrypted RCData payload. No hardcoded C2 recovered. Static-only — CAPE skipped (no Windows guest).
What It Is
- SHA-256:
b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11 - File:
schoenberg-ensemble.nl.exe— 207,872 bytes (203 KB) PE32 GUI .NET assembly ^[file.txt] - Build timestamp: Sun Feb 22 00:49:37 2015 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Linker: 6.0 (Visual Studio / .NET 2.0 era) ^[exiftool.json:18]
- CLR: v2.0.50727 (.NET Framework 2.0) ^[strings.txt:51]
- Builder version:
1.2.2.0^[strings.txt:1626] - MyTemplate GUID:
7e3c957d-3516-4313-add2-1d2b57e0ca5f^[strings.txt:1624] - Internal name:
NanoCore Client.exe/NanoCore Client^[strings.txt:55-56] - Obfuscator: ConfuserEx — heavy
#=q…==name mangling throughout metadata ^[strings.txt:278-330] - Signed: No Authenticode ^[rabin2-info.txt:27]
- CAPE: Skipped — no Windows guest available ^[dynamic-analysis.md:3]
Family attribution is high-confidence based on the full NanoCore plugin-host interface surface, builder version stamp, and batch timestamp shared with seventeen prior siblings. See nanocore for cluster-wide analysis.
How It Works
Startup & Decryption
The entry point is a standard .NET WinForms application (ClientLoaderForm as startup form) ^[strings.txt:344]. At runtime the binary decrypts an encrypted payload stored in .rsrc (RT_RCDATA, 0x15F68 bytes, entropy 7.998) ^[pefile.txt:121-132]. The decryption pipeline uses RijndaelManaged + DeflateStream — both class names survive in the metadata strings ^[strings.txt:232,152]. This is the same pipeline observed across the entire Feb 2015 batch.
Plugin Architecture
NanoCore’s hallmark is its modular plugin system. The binary exposes the full host interface surface:
IClientApp,IClientData,IClientNetwork,IClientUIHost^[strings.txt:86-95]IClientAppHost,IClientDataHost,IClientLoggingHost,IClientNetworkHost^[strings.txt:90-94]NanoCore.ClientPluginHost^[strings.txt:91]IClientNameObjectCollection,IClientReadOnlyNameObjectCollection^[strings.txt:96-97]
Commands are typed through BaseCommand, FileCommand, PluginCommand, CommandType, and DnsRecord enumerations ^[strings.txt:331,343-347]. Pipe-based IPC is used for plugin communication: CreatePipe, PipeCreated, PipeExists, ClosePipe, Disconnect, SendToServer ^[strings.txt:1112-1113,459,461,463,464].
C2 & Network
The client uses raw Berkeley sockets (not HTTP/HTTPS). Key socket classes present: Socket, SocketAsyncEventArgs, IPEndPoint, IPAddress, DnsRecord, LingerOption ^[strings.txt:172-181]. Host entries are managed dynamically via AddHostEntry and RebuildHostCache ^[strings.txt:468,470], allowing the server to push new C2 addresses at runtime. Keepalive framing uses KeepAlive and Transmission packet types ^[strings.txt:1116,1114]. DNS resolution is via DnsQuery_A ^[strings.txt:1399]. No hardcoded IP, domain, or port was recovered statically.
Persistence & Evasion
- Registry: Full registry manipulation surface (
RegOpenKeyEx,RegQueryValueEx,RegCloseKey,SetValue,GetValue,RemoveValue,EntryExists,GetEntries) ^[strings.txt:81-84,1390-1392,536-542]. capa flags T1112 (Modify Registry) ^[capa.txt:15]. - File system: Copy, create, delete, enumerate files and directories ^[capa.txt:73-84].
- Process: Create, terminate, suspend threads; enter debug mode ^[capa.txt:91-94,102,104]. capa flags T1620 (Reflective Code Loading) ^[capa.txt:16].
- Anti-analysis: ConfuserEx control-flow flattening and constant encryption poison static analysis.
SuppressIldasmAttributeis present ^[strings.txt:208]. - Native API bridging: P/Invoke imports into
kernel32.dll,psapi.dll,advapi32.dll,ntdll.dll,dnsapi.dll^[strings.txt:63-67]. Notable APIs:SetThreadExecutionState,GetProcessImageFileName,NtSetInformationProcess,GetKernelObjectSecurity,SetKernelObjectSecurity,QueryDosDevice,AllocConsole,DeleteFile^[strings.txt:1381-1398].
System Discovery
- Account, file/directory, registry, system info, and user discovery ^[capa.txt:17-22].
GetDetails,HostDetails,HostData,Detailsmethods suggest built-in victim fingerprinting ^[strings.txt:1372-1380].
Decompiled Behavior
Ghidra/decompiler output is not available for this sample — no Ghidra MCP server is reachable in this environment and the static tool chain did not produce decompiled artifacts. All behavioral claims above are inferred from metadata strings, capa static analysis, and PE structural inspection.
C2 Infrastructure
No hardcoded C2 recovered. The sample relies on runtime host-cache updates via AddHostEntry / RebuildHostCache ^[strings.txt:468,470]. The socket layer uses raw TCP (Socket, SocketAsyncEventArgs) with DNS resolution via Windows dnsapi.dll!DnsQuery_A ^[strings.txt:1399]. Dynamic analysis would be required to capture the initial C2 handshake.
Interesting Tidbits
- Social-engineering pivot: Prior siblings in this batch used gaming masquerades (
EMU.exe,Nemo.exe), blunt filenames (Backdoor.exe,nam.exe), or housing domains (aboddehousing.co.uk,coffeeandsuch.nl). This sample shifts to a Dutch classical-music ensemble (schoenberg-ensemble.nl) — a niche cultural target likely chosen to seem benign to European victims. ^[triage.json:5] - Version stamp anomaly: The binary carries
8.0.0.0in version metadata ^[strings.txt:1614] — higher than the builder’s own1.2.2.0. This may be the author’s custom version string or a WinForms template artifact. - No double-extension: Unlike many socially-engineered droppers, this uses a single
.exeextension piggybacking on the domain name for credibility. - Floss failure: flare-floss was invoked with malformed arguments and produced no decoded strings ^[floss.txt:1-6]. All string evidence comes from standard
stringsextraction against the .NET metadata tables.
How To Mess With It (Homelab Replication)
Goal: Reproduce a NanoCore-like build fingerprint for detection testing.
- Toolchain: Visual Studio 2013+ or SharpDevelop, target .NET Framework 2.0, VB.NET WinForms project.
- Build a minimal RAT skeleton:
- Create a WinForms app with a
TcpClientconnecting to a test server. - Add empty interface stubs named
IClientApp,IClientNetwork,IClientUIHost. - Embed a dummy resource as
RT_RCDATA.
- Create a WinForms app with a
- Obfuscate with ConfuserEx:
<project outputDir=".\obfuscated" baseDir=".\bin\Debug" xmlns="http://confuser.codeplex.com"> <module path="MyClient.exe"> <rule preset="maximum" /> </module> </project> - Verify fingerprint:
Expect: hundreds ofstrings .\obfuscated\MyClient.exe | Select-String "#=q" capa .\obfuscated\MyClient.exe#=q…==mangled names,mscoree.dll!_CorExeMainas sole import, high-entropy.rsrc, and capa hits forcreate TCP socket,hash data with MD5,query registry. - What you learn: How ConfuserEx transforms a trivial .NET binary into something that statically resembles leaked-era NanoCore — useful for building YARA/Sigma detection baselines.
Deployable Signatures
YARA Rule — NanoCore Plugin-Host Fingerprint
rule nanocore_plugin_host_fingerprint
{
meta:
description = "NanoCore RAT client — plugin host interface surface"
author = "PacketPursuit SOC"
date = "2026-08-14"
sha256 = "b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11"
strings:
$s1 = "NanoCore Client" ascii wide
$s2 = "IClientApp" ascii wide
$s3 = "IClientNetwork" ascii wide
$s4 = "IClientUIHost" ascii wide
$s5 = "IClientAppHost" ascii wide
$s6 = "IClientDataHost" ascii wide
$s7 = "IClientLoggingHost" ascii wide
$s8 = "IClientNetworkHost" ascii wide
$s9 = "NanoCore.ClientPluginHost" ascii wide
$s10 = "AddHostEntry" ascii wide
$s11 = "RebuildHostCache" ascii wide
$s12 = "ClientLoaderForm" ascii wide
$s13 = "BaseCommand" ascii wide
$s14 = "FileCommand" ascii wide
$s15 = "PluginCommand" ascii wide
$s16 = "RijndaelManaged" ascii wide
$s17 = "DeflateStream" ascii wide
$c1 = "#=q" ascii wide
condition:
uint16(0) == 0x5A4D and
10 of ($s*) and
#c1 > 50
}
Behavioral Hunt Query — EQL
process where
process.pe.description : "*NanoCore*" or
process.pe.original_file_name : "*NanoCore Client*" or
process.pe.company : "*NanoCore*"
or
(
process.name : "*.exe" and
(
registry set
registry.path : "HKEY_USERS\\*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run*"
) and
(
network where destination.port in (4444, 5555, 1604, 1177, 995) or
process.name : "*schoenberg*"
)
)
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11 |
Primary sample |
| MD5 | 23cca9cecd664dd58daa4f6cdb9cf57e |
^[capa.txt:3] |
| SHA-1 | 98e170c496510e7099ad44578759a5f1f0ab4108 |
^[capa.txt:4] |
| Filename | schoenberg-ensemble.nl.exe |
Dutch masquerade |
| Builder version | 1.2.2.0 |
Feb 2015 batch |
| MyTemplate GUID | 7e3c957d-3516-4313-add2-1d2b57e0ca5f |
Unique to this sample |
| Internal name | NanoCore Client.exe |
|
| Mutex pattern | NanoCore* (inferred from family behavior) |
Not recovered statically |
| Registry | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
Persistence vector (inferred) |
| C2 protocol | Raw TCP + DNS | No hardcoded addresses |
Behavioral Fingerprint Statement
This binary is a .NET Framework 2.0 PE32 GUI executable with a single mscoree.dll import, ~90 KB of high-entropy RCData in .rsrc, and extensive ConfuserEx name mangling (#=q…==). At startup it decrypts its embedded resource via RijndaelManaged + DeflateStream, then initializes a WinForms loader that hosts modular plugins through a well-defined interface surface (IClientApp, IClientNetwork, IClientUIHost, etc.). It communicates over raw TCP sockets with dynamic host-cache updates (AddHostEntry / RebuildHostCache), performs registry queries for persistence, and enumerates files, users, and system information. The presence of SetThreadExecutionState, NtSetInformationProcess, and GetProcessImageFileName P/Invoke imports indicates process-manipulation capabilities.
Detection Signatures
| ATT&CK Tactic | Technique | Evidence |
|---|---|---|
| DEFENSE EVASION | T1112 Modify Registry | capa registry set/delete value ^[capa.txt:15] |
| DEFENSE EVASION | T1620 Reflective Code Loading | capa load .NET assembly ^[capa.txt:16] |
| DISCOVERY | T1087 Account Discovery | capa ^[capa.txt:17] |
| DISCOVERY | T1083 File and Directory Discovery | capa ^[capa.txt:18] |
| DISCOVERY | T1012 Query Registry | capa ^[capa.txt:19] |
| DISCOVERY | T1082 System Information Discovery | capa ^[capa.txt:20] |
| DISCOVERY | T1033 System Owner/User Discovery | capa ^[capa.txt:21] |
References
- nanocore — cluster entity page with full sibling list and shared TTPs.
- confuserex-obfuscation — technique page for the obfuscator fingerprint.
- OpenCTI artifact:
1e6575b5-6648-485f-a6e2-f10698cdfd21^[triage.json:4] - MalwareBazaar source (abuse.ch)
Provenance
Analysis derived from static artifacts only. No dynamic execution was performed (CAPE skipped — no Windows guest). Tools: file (PE32 .NET), pefile (PE structure / resource layout), strings (metadata string extraction), capa v7 (ATT&CK capability mapping), rabin2 -I (binary header), exiftool (timestamp / linker version), binwalk (no significant embedded archives), floss (failed due to CLI argument error). All provenance markers use the canonical path raw/analyses/b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11/<file>.