typeanalysisfamilynanocoreconfidencehighcreated2026-08-26updated2026-08-26dotnetmalware-familyratc2obfuscationpersistence
SHA-256: b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499

nanocore: b5bbf49b — bare-filename sibling 'nega.exe', Feb 2015 builder batch

Executive Summary

The twentieth confirmed sibling in the Feb 22 2015 NanoCore builder batch. A 208 KB VB.NET PE32 client (nega.exe) carrying NanoCore RAT v1.2.2.0 under heavy ConfuserEx obfuscation. Unlike most siblings that masquerade as domain names, this sample uses a bare three-letter filename with no social-engineering veneer. Identical build timestamp, identical builder version, identical obfuscation fingerprint — only the MyTemplate GUID and encrypted RCData payload differ. No hardcoded C2 recovered; settings are runtime-decrypted from the 88 KB resource package. Static-only (CAPE skipped — no Windows guest).

What It Is

Property Value Provenance
SHA-256 b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499 metadata.json
File name nega.exe metadata.json
Size 207,872 bytes (203 KB) metadata.json
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections file.txt
Timestamp Sun Feb 22 00:49:37 2015 UTC (0x54E927A1) pefile.txt:34
Linker .NET Framework v2.0.50727 (CLR 2.0) strings.txt:51
Language Visual Basic .NET (My.Application / MyTemplate) strings.txt:1613, strings.txt:1626
RAT version NanoCore Client 1.2.2.0 strings.txt:1626
Obfuscator ConfuserEx (#=q…== name mangling, ~1,050+ tokens) strings.txt:278+
MyTemplate GUID cce15acd-4387-46c9-8e17-643151fbfa1d strings.txt:1615
Signed No (stripped, unsigned) pefile.txt:153-154
RCData resource 88,152 bytes (entropy 7.998), embedded ZIP archive pefile.txt:238

Family ascription is high-confidence: every static marker — builder version 1.2.2.0, VB.NET MyTemplate GUID format, ConfuserEx name-mangling density, 3-section PE layout, .rsrc entropy ~8.0, and the shared Feb 22 2015 timestamp — aligns with the 19 prior confirmed siblings in this cluster. See nanocore entity page for the full cluster fingerprint. ^[nanocore entity]

How It Works

Per-Sample Deltas vs. Cluster Baseline

This sample differs from the sibling cluster in only three observable ways:

  1. Filename: nega.exe — a bare, meaningless three-letter name with no domain or utility masquerade. Most siblings in this batch use domain-masquerade filenames (okfun.exe, hotro.exe, mmdx2.ru.com.exe, cash-win.nl.exe, etc.). This is the first sibling in the batch with a non-descriptive name, suggesting either a test build or an intermediate stage before rebranding. ^[metadata.json]

  2. MyTemplate GUID: cce15acd-4387-46c9-8e17-643151fbfa1d — unique to this sample. Every sibling carries a distinct GUID generated by the VB.NET compiler at build time. ^[strings.txt:1615]

  3. RCData payload hash: The 88,152-byte encrypted resource package in .rsrc has a unique SHA-256 (1d39e76f...), as expected for a per-build config/plugin bundle. The size (88 KB) sits squarely in the sibling range (88–91 KB). ^[pefile.txt:133-135]

Cluster-Shared Behavior (see nanocore for full detail)

  • Entry: CLR bootstrap → ClientLoaderForm.Main (WinForms invisible wrapper) → IClientApp plugin host initialization. ^[strings.txt:344]
  • Obfuscation: ConfuserEx rewrites all identifiers to #=q[A-Za-z0-9_$]{10,}== tokens, encrypts the .rsrc payload, and flattens control flow. Static decompilation is impractical without automated deobfuscation. ^[strings.txt:278]
  • Persistence: Registry Run key manipulation inferred from RegistryKey, get_StartupPath, and set_CurrentDirectory references. ^[strings.txt:83, strings.txt:1456-1457]
  • C2: Raw TCP sockets (not HTTP/HTTPS). System.Net.Sockets.Socket, SendToServer, get_Connected, get_Port, DnsRecord, AddHostEntry, RebuildHostCache all present. ^[strings.txt:175-180, strings.txt:458, strings.txt:468-470]
  • Plugin architecture: IClientApp, IClientNetwork, IClientUIHost, CommandType, BaseCommand, FileCommand, PluginCommand, plus pipe-based IPC (CreatePipe, PipeExists, PipeClosed). ^[strings.txt:86-97, strings.txt:331-348, strings.txt:459-463]
  • Crypto: RijndaelManaged, DeflateStream, MD5CryptoServiceProvider present for resource decryption and packet integrity. ^[strings.txt:152, strings.txt:232, strings.txt:230]

Decompiled Behavior

Radare2 CIL analysis identifies 858 methods. The entry point lands in method.ClientLoaderForm.Main (0x40c480), which instantiates the invisible WinForms wrapper and delegates to the obfuscated Client constructor chain. ConfuserEx control-flow flattening and delegate trampolines dominate the IL; meaningful decompilation is blocked without dynamic tracing or automated deobfuscation tools (e.g., NoFusicator, de4dot replacement pipelines). ^[rabin2-info.txt]

The .rsrc section (offset 0x22058, size 0x15F58) is the ConfuserEx-encrypted payload package. Its entropy of 7.998 and the PK\x03\x04 ZIP signature deep inside the section confirm it carries a compressed/encrypted resource bundle — standard for ConfuserEx-protected NanoCore builds. ^[pefile.txt:131-137, binwalk.txt]

C2 Infrastructure

  • Static C2: None extracted. ClientSettings / BuilderSettings objects are encrypted inside the .rsrc ZIP and decrypted at runtime via the ConfuserEx resource decryption stub. ^[strings.txt:1401-1402]
  • Protocol: Raw TCP sockets with keepalive framing. Inferred from Socket, SendToServer, ReceiveAsync, KeepAlive (implied by Connected and socket error handling patterns). ^[strings.txt:175-180]
  • DNS / host cache: DnsRecord, GetHostEntry, AddHostEntry, RebuildHostCache show the client maintains a mutable host list, supporting server-driven redirection or DGA fallback. ^[strings.txt:343, strings.txt:468-470]
  • Named pipes: CreatePipe, PipeExists, PipeCreated, PipeClosed — used for client ↔ plugin IPC, not C2 transport. ^[strings.txt:459-463]

Interesting Tidbits

  1. No social-engineering masquerade: Unlike siblings okfun.exe, mmdx2.ru.com.exe, cash-win.nl.exe, etc., this sample uses the bare name nega.exe. This may indicate a test build, a pre-rebranding intermediate, or distribution via a channel where filename doesn't matter (e.g., bundled inside another dropper). ^[metadata.json]
  2. Identical linker timestamp: 0x54E927A1 (Sun Feb 22 00:49:37 2015 UTC) is shared across all 20 siblings, confirming a single batch-build event — likely one operator running the NanoCore builder repeatedly on the same machine in a short window. ^[pefile.txt:34]
  3. SSDeep similarity: The ssdeep hash 6144:sLV6Bta6dtJmakIM5v6fA+eXcTTacsRy3Cj+M:sLV6BtpmkyuA+eXsaDCU/ shares the same block-1 prefix (sLV6Bta6dtJmakIM5) as sibling fe81691f, confirming the same code base and ConfuserEx obfuscation layer. ^[ssdeep.txt]
  4. VB.NET MyTemplate artefact: The GUID cce15acd-4387-46c9-8e17-643151fbfa1d is a compiler-generated template identifier. Its presence alongside My.MyProject.Forms and Create__Instance__ confirms VB.NET source, not C#. ^[strings.txt:1613-1620]
  5. Single import: The PE imports only mscoree.dll!_CorExeMain — standard for .NET assemblies, but also a triage shortcut: if you see a 200 KB PE with one import and a .rsrc entropy of ~8.0, think ConfuserEx .NET loader. ^[pefile.txt:199]
  6. No Authenticode, no PDB, no debug directory: Clean stripped build. The Security and Debug directories are both zeroed, consistent with a builder-output binary intended for criminal distribution. ^[pefile.txt:153-163]

How To Mess With It (Homelab Replication)

Goal: Reproduce a ConfuserEx-obfuscated .NET RAT loader that matches this sample's static fingerprint.

  1. Toolchain: Visual Studio 2013/2015 Community + .NET Framework 2.0/3.5 targeting pack.
  2. Source: Write a trivial VB.NET WinForms app with a Form1 class, add a reference to System.Net.Sockets, and instantiate a TcpClient in the Load event.
  3. Build: Compile as Release, x86, .NET Framework 2.0. Output should be ~20–40 KB.
  4. Obfuscate: Run through ConfuserEx v1.6.0 CLI with preset="maximum". This applies name mangling, constant encryption, control-flow flattening, and resource compression.
  5. Verify:
    strings obfuscated.exe | Select-String "#=q"
    capa obfuscated.exe | findstr "dotnet"
    # Expect: hundreds of `#=q…==` tokens, `compiled to the .NET platform`,
    # `access .NET resource`, `create TCP socket`, etc.
    
  6. What you'll learn: How ConfuserEx rewrites IL to defeat static analysis, and why strings + capa remain the fastest triage tools for .NET malware even when decompilers fail.

Deployable Signatures

YARA Rule — NanoCore Feb 2015 ConfuserEx Builder Batch

rule nanocore_feb2015_confuserex_batch {
    meta:
        description = "NanoCore RAT v1.2.2.0 client, ConfuserEx-obfuscated, Feb 2015 builder batch"
        author = "PacketPursuit"
        date = "2026-08-26"
        hash_sample = "b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499"
        hash_sibling = "fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5"
    strings:
        $nano_name = "NanoCore Client" ascii wide
        $nano_exe  = "NanoCore Client.exe" ascii wide
        $ver      = "1.2.2.0" ascii wide
        $conf1    = /#=q[A-Za-z0-9_$]{10,}==/
        $mytmpl  = "MyTemplate" ascii wide
        $rsrc1   = "System.Resources.ResourceReader" ascii wide
        $net1    = "System.Net.Sockets.Socket" ascii wide
        $rijn    = "RijndaelManaged" ascii wide
        $defl    = "DeflateStream" ascii wide
    condition:
        uint16(0) == 0x5A4D
        and pe.number_of_sections == 3
        and pe.timestamp == 0x54E927A1
        and $nano_name
        and $ver
        and #conf1 > 50
        and any of ($net1, $rijn, $defl)
        and filesize < 300KB
}

IOC List

Indicator Value Type
SHA-256 b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499 Hash
MD5 d365a73d1b73fd74ddabb87c8ab135ed Hash
File name nega.exe Filename
PE timestamp 0x54E927A1 (Sun Feb 22 00:49:37 2015 UTC) Build artefact
Builder version 1.2.2.0 Version string
MyTemplate GUID cce15acd-4387-46c9-8e17-643151fbfa1d Compiler artefact
RCData size 88,152 bytes (entropy ~7.998) Resource metric
ConfuserEx tokens #=q…== pattern, >1,000 instances Obfuscation fingerprint
Import table mscoree.dll!_CorExeMain only Import anomaly

Behavioral Fingerprint Statement

This binary is a .NET Framework 2.0 PE32 assembly that launches via an invisible WinForms wrapper (ClientLoaderForm), decrypts an 88 KB encrypted resource package from .rsrc using RijndaelManaged + DeflateStream, and then establishes raw TCP socket C2 communication with mutable host caching (AddHostEntry, RebuildHostCache). It creates mutexes for singleton enforcement, queries the registry for system discovery, and supports modular plugin loading via named pipes. Persistence is achieved through HKCU\Software\Microsoft\Windows\CurrentVersion\Run manipulation. The ConfuserEx obfuscation layer rewrites all type and method names to #=q…== tokens, producing >1,000 mangled identifiers.

Detection Signatures

capa → ATT&CK Mapping

capa Capability ATT&CK Technique Namespace
set registry value T1112 Modify Registry host-interaction/registry/create
load .NET assembly T1620 Reflective Code Loading load-code/dotnet
query or enumerate registry key/value T1012 Query Registry host-interaction/registry
get session user name T1033 System Owner/User Discovery host-interaction/session
get OS version T1082 System Information Discovery host-interaction/os/version
enumerate files T1083 File and Directory Discovery host-interaction/file-system/files
create TCP socket — (pre-ATT&CK) communication/socket/tcp
resolve DNS — (pre-ATT&CK) communication/dns
create or open mutex — (pre-ATT&CK) host-interaction/mutex
hash data with MD5 — (pre-ATT&CK) data-manipulation/hashing/md5
create process — (pre-ATT&CK) host-interaction/process/create
suspend thread — (pre-ATT&CK) host-interaction/thread/suspend

Note: The create TCP socket and resolve DNS capabilities map to MBC behaviors C0001.011 and C0011.001 respectively, which sit below ATT&CK technique granularity. ^[capa.txt]

References

  • NanoCore entity page: nanocore
  • ConfuserEx obfuscation technique: confuserex-obfuscation
  • Registry Run persistence procedure: registry-run-persistence
  • MalwareBazaar entry: https://bazaar.abuse.ch/sample/b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499/
  • Cluster sibling analyses: fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8, cb2aa275, e48f1c56, 12deaec6, b6008cf6, f017a517, 37509ef2, 112d957b, e4ee45f1, 930b692d, 36115e96, e4774281, 38cac999, b0daeb6a, 96ddc506

Provenance

  • file.txt — file(1) v5.44
  • pefile.txt — pefile (Python) v2023.2.7
  • strings.txt — strings (GNU binutils) v2.42
  • floss.txt — flare-floss v3.1.1 (errored on this sample; no decoded strings recovered)
  • capa.txt — flare-capa v7.0.1
  • rabin2-info.txt — radare2 v5.9.2
  • binwalk.txt — binwalk v2.3.4
  • ssdeep.txt — ssdeep v2.14.1
  • exiftool.json — ExifTool v12.76
  • dynamic-analysis.md — CAPE skipped (no Windows guest available)