typeanalysisfamilynanocoreconfidencehighcreated2026-08-14updated2026-08-14malware-familyratdotnetobfuscationc2persistence
SHA-256: b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11

nanocore: b0daeb6a — Dutch classical-music domain masquerade, builder v1.2.2.0

Executive Summary

Eighteenth confirmed sibling in the leaked NanoCore builder Feb 2015 batch. VB.NET WinForms client obfuscated with ConfuserEx, masquerading as the Dutch classical-music website schoenberg-ensemble.nl. Identical builder version 1.2.2.0 and timestamp to the rest of the batch; unique MyTemplate GUID and ~90 KB encrypted RCData payload. No hardcoded C2 recovered. Static-only — CAPE skipped (no Windows guest).

What It Is

  • SHA-256: b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11
  • File: schoenberg-ensemble.nl.exe — 207,872 bytes (203 KB) PE32 GUI .NET assembly ^[file.txt]
  • Build timestamp: Sun Feb 22 00:49:37 2015 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Linker: 6.0 (Visual Studio / .NET 2.0 era) ^[exiftool.json:18]
  • CLR: v2.0.50727 (.NET Framework 2.0) ^[strings.txt:51]
  • Builder version: 1.2.2.0 ^[strings.txt:1626]
  • MyTemplate GUID: 7e3c957d-3516-4313-add2-1d2b57e0ca5f ^[strings.txt:1624]
  • Internal name: NanoCore Client.exe / NanoCore Client ^[strings.txt:55-56]
  • Obfuscator: ConfuserEx — heavy #=q…== name mangling throughout metadata ^[strings.txt:278-330]
  • Signed: No Authenticode ^[rabin2-info.txt:27]
  • CAPE: Skipped — no Windows guest available ^[dynamic-analysis.md:3]

Family attribution is high-confidence based on the full NanoCore plugin-host interface surface, builder version stamp, and batch timestamp shared with seventeen prior siblings. See nanocore for cluster-wide analysis.

How It Works

Startup & Decryption

The entry point is a standard .NET WinForms application (ClientLoaderForm as startup form) ^[strings.txt:344]. At runtime the binary decrypts an encrypted payload stored in .rsrc (RT_RCDATA, 0x15F68 bytes, entropy 7.998) ^[pefile.txt:121-132]. The decryption pipeline uses RijndaelManaged + DeflateStream — both class names survive in the metadata strings ^[strings.txt:232,152]. This is the same pipeline observed across the entire Feb 2015 batch.

Plugin Architecture

NanoCore’s hallmark is its modular plugin system. The binary exposes the full host interface surface:

  • IClientApp, IClientData, IClientNetwork, IClientUIHost ^[strings.txt:86-95]
  • IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost ^[strings.txt:90-94]
  • NanoCore.ClientPluginHost ^[strings.txt:91]
  • IClientNameObjectCollection, IClientReadOnlyNameObjectCollection ^[strings.txt:96-97]

Commands are typed through BaseCommand, FileCommand, PluginCommand, CommandType, and DnsRecord enumerations ^[strings.txt:331,343-347]. Pipe-based IPC is used for plugin communication: CreatePipe, PipeCreated, PipeExists, ClosePipe, Disconnect, SendToServer ^[strings.txt:1112-1113,459,461,463,464].

C2 & Network

The client uses raw Berkeley sockets (not HTTP/HTTPS). Key socket classes present: Socket, SocketAsyncEventArgs, IPEndPoint, IPAddress, DnsRecord, LingerOption ^[strings.txt:172-181]. Host entries are managed dynamically via AddHostEntry and RebuildHostCache ^[strings.txt:468,470], allowing the server to push new C2 addresses at runtime. Keepalive framing uses KeepAlive and Transmission packet types ^[strings.txt:1116,1114]. DNS resolution is via DnsQuery_A ^[strings.txt:1399]. No hardcoded IP, domain, or port was recovered statically.

Persistence & Evasion

  • Registry: Full registry manipulation surface (RegOpenKeyEx, RegQueryValueEx, RegCloseKey, SetValue, GetValue, RemoveValue, EntryExists, GetEntries) ^[strings.txt:81-84,1390-1392,536-542]. capa flags T1112 (Modify Registry) ^[capa.txt:15].
  • File system: Copy, create, delete, enumerate files and directories ^[capa.txt:73-84].
  • Process: Create, terminate, suspend threads; enter debug mode ^[capa.txt:91-94,102,104]. capa flags T1620 (Reflective Code Loading) ^[capa.txt:16].
  • Anti-analysis: ConfuserEx control-flow flattening and constant encryption poison static analysis. SuppressIldasmAttribute is present ^[strings.txt:208].
  • Native API bridging: P/Invoke imports into kernel32.dll, psapi.dll, advapi32.dll, ntdll.dll, dnsapi.dll ^[strings.txt:63-67]. Notable APIs: SetThreadExecutionState, GetProcessImageFileName, NtSetInformationProcess, GetKernelObjectSecurity, SetKernelObjectSecurity, QueryDosDevice, AllocConsole, DeleteFile ^[strings.txt:1381-1398].

System Discovery

  • Account, file/directory, registry, system info, and user discovery ^[capa.txt:17-22].
  • GetDetails, HostDetails, HostData, Details methods suggest built-in victim fingerprinting ^[strings.txt:1372-1380].

Decompiled Behavior

Ghidra/decompiler output is not available for this sample — no Ghidra MCP server is reachable in this environment and the static tool chain did not produce decompiled artifacts. All behavioral claims above are inferred from metadata strings, capa static analysis, and PE structural inspection.

C2 Infrastructure

No hardcoded C2 recovered. The sample relies on runtime host-cache updates via AddHostEntry / RebuildHostCache ^[strings.txt:468,470]. The socket layer uses raw TCP (Socket, SocketAsyncEventArgs) with DNS resolution via Windows dnsapi.dll!DnsQuery_A ^[strings.txt:1399]. Dynamic analysis would be required to capture the initial C2 handshake.

Interesting Tidbits

  • Social-engineering pivot: Prior siblings in this batch used gaming masquerades (EMU.exe, Nemo.exe), blunt filenames (Backdoor.exe, nam.exe), or housing domains (aboddehousing.co.uk, coffeeandsuch.nl). This sample shifts to a Dutch classical-music ensemble (schoenberg-ensemble.nl) — a niche cultural target likely chosen to seem benign to European victims. ^[triage.json:5]
  • Version stamp anomaly: The binary carries 8.0.0.0 in version metadata ^[strings.txt:1614] — higher than the builder’s own 1.2.2.0. This may be the author’s custom version string or a WinForms template artifact.
  • No double-extension: Unlike many socially-engineered droppers, this uses a single .exe extension piggybacking on the domain name for credibility.
  • Floss failure: flare-floss was invoked with malformed arguments and produced no decoded strings ^[floss.txt:1-6]. All string evidence comes from standard strings extraction against the .NET metadata tables.

How To Mess With It (Homelab Replication)

Goal: Reproduce a NanoCore-like build fingerprint for detection testing.

  1. Toolchain: Visual Studio 2013+ or SharpDevelop, target .NET Framework 2.0, VB.NET WinForms project.
  2. Build a minimal RAT skeleton:
    • Create a WinForms app with a TcpClient connecting to a test server.
    • Add empty interface stubs named IClientApp, IClientNetwork, IClientUIHost.
    • Embed a dummy resource as RT_RCDATA.
  3. Obfuscate with ConfuserEx:
    <project outputDir=".\obfuscated" baseDir=".\bin\Debug"
             xmlns="http://confuser.codeplex.com">
      <module path="MyClient.exe">
        <rule preset="maximum" />
      </module>
    </project>
    
  4. Verify fingerprint:
    strings .\obfuscated\MyClient.exe | Select-String "#=q"
    capa .\obfuscated\MyClient.exe
    
    Expect: hundreds of #=q…== mangled names, mscoree.dll!_CorExeMain as sole import, high-entropy .rsrc, and capa hits for create TCP socket, hash data with MD5, query registry.
  5. What you learn: How ConfuserEx transforms a trivial .NET binary into something that statically resembles leaked-era NanoCore — useful for building YARA/Sigma detection baselines.

Deployable Signatures

YARA Rule — NanoCore Plugin-Host Fingerprint

rule nanocore_plugin_host_fingerprint
{
    meta:
        description = "NanoCore RAT client — plugin host interface surface"
        author = "PacketPursuit SOC"
        date = "2026-08-14"
        sha256 = "b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11"
    strings:
        $s1 = "NanoCore Client" ascii wide
        $s2 = "IClientApp" ascii wide
        $s3 = "IClientNetwork" ascii wide
        $s4 = "IClientUIHost" ascii wide
        $s5 = "IClientAppHost" ascii wide
        $s6 = "IClientDataHost" ascii wide
        $s7 = "IClientLoggingHost" ascii wide
        $s8 = "IClientNetworkHost" ascii wide
        $s9 = "NanoCore.ClientPluginHost" ascii wide
        $s10 = "AddHostEntry" ascii wide
        $s11 = "RebuildHostCache" ascii wide
        $s12 = "ClientLoaderForm" ascii wide
        $s13 = "BaseCommand" ascii wide
        $s14 = "FileCommand" ascii wide
        $s15 = "PluginCommand" ascii wide
        $s16 = "RijndaelManaged" ascii wide
        $s17 = "DeflateStream" ascii wide
        $c1 = "#=q" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        10 of ($s*) and
        #c1 > 50
}

Behavioral Hunt Query — EQL

process where
  process.pe.description : "*NanoCore*" or
  process.pe.original_file_name : "*NanoCore Client*" or
  process.pe.company : "*NanoCore*"
  or
  (
    process.name : "*.exe" and
    (
      registry set
        registry.path : "HKEY_USERS\\*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run*"
    ) and
    (
      network where destination.port in (4444, 5555, 1604, 1177, 995) or
      process.name : "*schoenberg*"
    )
  )

IOC List

Type Value Notes
SHA-256 b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11 Primary sample
MD5 23cca9cecd664dd58daa4f6cdb9cf57e ^[capa.txt:3]
SHA-1 98e170c496510e7099ad44578759a5f1f0ab4108 ^[capa.txt:4]
Filename schoenberg-ensemble.nl.exe Dutch masquerade
Builder version 1.2.2.0 Feb 2015 batch
MyTemplate GUID 7e3c957d-3516-4313-add2-1d2b57e0ca5f Unique to this sample
Internal name NanoCore Client.exe
Mutex pattern NanoCore* (inferred from family behavior) Not recovered statically
Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run Persistence vector (inferred)
C2 protocol Raw TCP + DNS No hardcoded addresses

Behavioral Fingerprint Statement

This binary is a .NET Framework 2.0 PE32 GUI executable with a single mscoree.dll import, ~90 KB of high-entropy RCData in .rsrc, and extensive ConfuserEx name mangling (#=q…==). At startup it decrypts its embedded resource via RijndaelManaged + DeflateStream, then initializes a WinForms loader that hosts modular plugins through a well-defined interface surface (IClientApp, IClientNetwork, IClientUIHost, etc.). It communicates over raw TCP sockets with dynamic host-cache updates (AddHostEntry / RebuildHostCache), performs registry queries for persistence, and enumerates files, users, and system information. The presence of SetThreadExecutionState, NtSetInformationProcess, and GetProcessImageFileName P/Invoke imports indicates process-manipulation capabilities.

Detection Signatures

ATT&CK Tactic Technique Evidence
DEFENSE EVASION T1112 Modify Registry capa registry set/delete value ^[capa.txt:15]
DEFENSE EVASION T1620 Reflective Code Loading capa load .NET assembly ^[capa.txt:16]
DISCOVERY T1087 Account Discovery capa ^[capa.txt:17]
DISCOVERY T1083 File and Directory Discovery capa ^[capa.txt:18]
DISCOVERY T1012 Query Registry capa ^[capa.txt:19]
DISCOVERY T1082 System Information Discovery capa ^[capa.txt:20]
DISCOVERY T1033 System Owner/User Discovery capa ^[capa.txt:21]

References

  • nanocore — cluster entity page with full sibling list and shared TTPs.
  • confuserex-obfuscation — technique page for the obfuscator fingerprint.
  • OpenCTI artifact: 1e6575b5-6648-485f-a6e2-f10698cdfd21 ^[triage.json:4]
  • MalwareBazaar source (abuse.ch)

Provenance

Analysis derived from static artifacts only. No dynamic execution was performed (CAPE skipped — no Windows guest). Tools: file (PE32 .NET), pefile (PE structure / resource layout), strings (metadata string extraction), capa v7 (ATT&CK capability mapping), rabin2 -I (binary header), exiftool (timestamp / linker version), binwalk (no significant embedded archives), floss (failed due to CLI argument error). All provenance markers use the canonical path raw/analyses/b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11/<file>.