b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499nanocore: b5bbf49b — bare-filename sibling 'nega.exe', Feb 2015 builder batch
Executive Summary
The twentieth confirmed sibling in the Feb 22 2015 NanoCore builder batch. A 208 KB VB.NET PE32 client (nega.exe) carrying NanoCore RAT v1.2.2.0 under heavy ConfuserEx obfuscation. Unlike most siblings that masquerade as domain names, this sample uses a bare three-letter filename with no social-engineering veneer. Identical build timestamp, identical builder version, identical obfuscation fingerprint — only the MyTemplate GUID and encrypted RCData payload differ. No hardcoded C2 recovered; settings are runtime-decrypted from the 88 KB resource package. Static-only (CAPE skipped — no Windows guest).
What It Is
| Property | Value | Provenance |
|---|---|---|
| SHA-256 | b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499 |
metadata.json |
| File name | nega.exe |
metadata.json |
| Size | 207,872 bytes (203 KB) | metadata.json |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | file.txt |
| Timestamp | Sun Feb 22 00:49:37 2015 UTC (0x54E927A1) |
pefile.txt:34 |
| Linker | .NET Framework v2.0.50727 (CLR 2.0) | strings.txt:51 |
| Language | Visual Basic .NET (My.Application / MyTemplate) | strings.txt:1613, strings.txt:1626 |
| RAT version | NanoCore Client 1.2.2.0 | strings.txt:1626 |
| Obfuscator | ConfuserEx (#=q…== name mangling, ~1,050+ tokens) |
strings.txt:278+ |
| MyTemplate GUID | cce15acd-4387-46c9-8e17-643151fbfa1d |
strings.txt:1615 |
| Signed | No (stripped, unsigned) | pefile.txt:153-154 |
| RCData resource | 88,152 bytes (entropy 7.998), embedded ZIP archive | pefile.txt:238 |
Family ascription is high-confidence: every static marker — builder version 1.2.2.0, VB.NET MyTemplate GUID format, ConfuserEx name-mangling density, 3-section PE layout, .rsrc entropy ~8.0, and the shared Feb 22 2015 timestamp — aligns with the 19 prior confirmed siblings in this cluster. See nanocore entity page for the full cluster fingerprint. ^[nanocore entity]
How It Works
Per-Sample Deltas vs. Cluster Baseline
This sample differs from the sibling cluster in only three observable ways:
-
Filename:
nega.exe— a bare, meaningless three-letter name with no domain or utility masquerade. Most siblings in this batch use domain-masquerade filenames (okfun.exe,hotro.exe,mmdx2.ru.com.exe,cash-win.nl.exe, etc.). This is the first sibling in the batch with a non-descriptive name, suggesting either a test build or an intermediate stage before rebranding. ^[metadata.json] -
MyTemplate GUID:
cce15acd-4387-46c9-8e17-643151fbfa1d— unique to this sample. Every sibling carries a distinct GUID generated by the VB.NET compiler at build time. ^[strings.txt:1615] -
RCData payload hash: The 88,152-byte encrypted resource package in
.rsrchas a unique SHA-256 (1d39e76f...), as expected for a per-build config/plugin bundle. The size (88 KB) sits squarely in the sibling range (88–91 KB). ^[pefile.txt:133-135]
Cluster-Shared Behavior (see nanocore for full detail)
- Entry: CLR bootstrap →
ClientLoaderForm.Main(WinForms invisible wrapper) →IClientAppplugin host initialization. ^[strings.txt:344] - Obfuscation: ConfuserEx rewrites all identifiers to
#=q[A-Za-z0-9_$]{10,}==tokens, encrypts the.rsrcpayload, and flattens control flow. Static decompilation is impractical without automated deobfuscation. ^[strings.txt:278] - Persistence: Registry Run key manipulation inferred from
RegistryKey,get_StartupPath, andset_CurrentDirectoryreferences. ^[strings.txt:83, strings.txt:1456-1457] - C2: Raw TCP sockets (not HTTP/HTTPS).
System.Net.Sockets.Socket,SendToServer,get_Connected,get_Port,DnsRecord,AddHostEntry,RebuildHostCacheall present. ^[strings.txt:175-180, strings.txt:458, strings.txt:468-470] - Plugin architecture:
IClientApp,IClientNetwork,IClientUIHost,CommandType,BaseCommand,FileCommand,PluginCommand, plus pipe-based IPC (CreatePipe,PipeExists,PipeClosed). ^[strings.txt:86-97, strings.txt:331-348, strings.txt:459-463] - Crypto:
RijndaelManaged,DeflateStream,MD5CryptoServiceProviderpresent for resource decryption and packet integrity. ^[strings.txt:152, strings.txt:232, strings.txt:230]
Decompiled Behavior
Radare2 CIL analysis identifies 858 methods. The entry point lands in method.ClientLoaderForm.Main (0x40c480), which instantiates the invisible WinForms wrapper and delegates to the obfuscated Client constructor chain. ConfuserEx control-flow flattening and delegate trampolines dominate the IL; meaningful decompilation is blocked without dynamic tracing or automated deobfuscation tools (e.g., NoFusicator, de4dot replacement pipelines). ^[rabin2-info.txt]
The .rsrc section (offset 0x22058, size 0x15F58) is the ConfuserEx-encrypted payload package. Its entropy of 7.998 and the PK\x03\x04 ZIP signature deep inside the section confirm it carries a compressed/encrypted resource bundle — standard for ConfuserEx-protected NanoCore builds. ^[pefile.txt:131-137, binwalk.txt]
C2 Infrastructure
- Static C2: None extracted.
ClientSettings/BuilderSettingsobjects are encrypted inside the.rsrcZIP and decrypted at runtime via the ConfuserEx resource decryption stub. ^[strings.txt:1401-1402] - Protocol: Raw TCP sockets with keepalive framing. Inferred from
Socket,SendToServer,ReceiveAsync,KeepAlive(implied byConnectedand socket error handling patterns). ^[strings.txt:175-180] - DNS / host cache:
DnsRecord,GetHostEntry,AddHostEntry,RebuildHostCacheshow the client maintains a mutable host list, supporting server-driven redirection or DGA fallback. ^[strings.txt:343, strings.txt:468-470] - Named pipes:
CreatePipe,PipeExists,PipeCreated,PipeClosed— used for client ↔ plugin IPC, not C2 transport. ^[strings.txt:459-463]
Interesting Tidbits
- No social-engineering masquerade: Unlike siblings
okfun.exe,mmdx2.ru.com.exe,cash-win.nl.exe, etc., this sample uses the bare namenega.exe. This may indicate a test build, a pre-rebranding intermediate, or distribution via a channel where filename doesn't matter (e.g., bundled inside another dropper). ^[metadata.json] - Identical linker timestamp:
0x54E927A1(Sun Feb 22 00:49:37 2015 UTC) is shared across all 20 siblings, confirming a single batch-build event — likely one operator running the NanoCore builder repeatedly on the same machine in a short window. ^[pefile.txt:34] - SSDeep similarity: The ssdeep hash
6144:sLV6Bta6dtJmakIM5v6fA+eXcTTacsRy3Cj+M:sLV6BtpmkyuA+eXsaDCU/shares the same block-1 prefix (sLV6Bta6dtJmakIM5) as siblingfe81691f, confirming the same code base and ConfuserEx obfuscation layer. ^[ssdeep.txt] - VB.NET
MyTemplateartefact: The GUIDcce15acd-4387-46c9-8e17-643151fbfa1dis a compiler-generated template identifier. Its presence alongsideMy.MyProject.FormsandCreate__Instance__confirms VB.NET source, not C#. ^[strings.txt:1613-1620] - Single import: The PE imports only
mscoree.dll!_CorExeMain— standard for .NET assemblies, but also a triage shortcut: if you see a 200 KB PE with one import and a.rsrcentropy of ~8.0, think ConfuserEx .NET loader. ^[pefile.txt:199] - No Authenticode, no PDB, no debug directory: Clean stripped build. The Security and Debug directories are both zeroed, consistent with a builder-output binary intended for criminal distribution. ^[pefile.txt:153-163]
How To Mess With It (Homelab Replication)
Goal: Reproduce a ConfuserEx-obfuscated .NET RAT loader that matches this sample's static fingerprint.
- Toolchain: Visual Studio 2013/2015 Community + .NET Framework 2.0/3.5 targeting pack.
- Source: Write a trivial VB.NET WinForms app with a
Form1class, add a reference toSystem.Net.Sockets, and instantiate aTcpClientin theLoadevent. - Build: Compile as
Release, x86, .NET Framework 2.0. Output should be ~20–40 KB. - Obfuscate: Run through ConfuserEx v1.6.0 CLI with
preset="maximum". This applies name mangling, constant encryption, control-flow flattening, and resource compression. - Verify:
strings obfuscated.exe | Select-String "#=q" capa obfuscated.exe | findstr "dotnet" # Expect: hundreds of `#=q…==` tokens, `compiled to the .NET platform`, # `access .NET resource`, `create TCP socket`, etc. - What you'll learn: How ConfuserEx rewrites IL to defeat static analysis, and why
strings+caparemain the fastest triage tools for .NET malware even when decompilers fail.
Deployable Signatures
YARA Rule — NanoCore Feb 2015 ConfuserEx Builder Batch
rule nanocore_feb2015_confuserex_batch {
meta:
description = "NanoCore RAT v1.2.2.0 client, ConfuserEx-obfuscated, Feb 2015 builder batch"
author = "PacketPursuit"
date = "2026-08-26"
hash_sample = "b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499"
hash_sibling = "fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5"
strings:
$nano_name = "NanoCore Client" ascii wide
$nano_exe = "NanoCore Client.exe" ascii wide
$ver = "1.2.2.0" ascii wide
$conf1 = /#=q[A-Za-z0-9_$]{10,}==/
$mytmpl = "MyTemplate" ascii wide
$rsrc1 = "System.Resources.ResourceReader" ascii wide
$net1 = "System.Net.Sockets.Socket" ascii wide
$rijn = "RijndaelManaged" ascii wide
$defl = "DeflateStream" ascii wide
condition:
uint16(0) == 0x5A4D
and pe.number_of_sections == 3
and pe.timestamp == 0x54E927A1
and $nano_name
and $ver
and #conf1 > 50
and any of ($net1, $rijn, $defl)
and filesize < 300KB
}
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499 |
Hash |
| MD5 | d365a73d1b73fd74ddabb87c8ab135ed |
Hash |
| File name | nega.exe |
Filename |
| PE timestamp | 0x54E927A1 (Sun Feb 22 00:49:37 2015 UTC) |
Build artefact |
| Builder version | 1.2.2.0 |
Version string |
| MyTemplate GUID | cce15acd-4387-46c9-8e17-643151fbfa1d |
Compiler artefact |
| RCData size | 88,152 bytes (entropy ~7.998) | Resource metric |
| ConfuserEx tokens | #=q…== pattern, >1,000 instances |
Obfuscation fingerprint |
| Import table | mscoree.dll!_CorExeMain only |
Import anomaly |
Behavioral Fingerprint Statement
This binary is a .NET Framework 2.0 PE32 assembly that launches via an invisible WinForms wrapper (ClientLoaderForm), decrypts an 88 KB encrypted resource package from .rsrc using RijndaelManaged + DeflateStream, and then establishes raw TCP socket C2 communication with mutable host caching (AddHostEntry, RebuildHostCache). It creates mutexes for singleton enforcement, queries the registry for system discovery, and supports modular plugin loading via named pipes. Persistence is achieved through HKCU\Software\Microsoft\Windows\CurrentVersion\Run manipulation. The ConfuserEx obfuscation layer rewrites all type and method names to #=q…== tokens, producing >1,000 mangled identifiers.
Detection Signatures
capa → ATT&CK Mapping
| capa Capability | ATT&CK Technique | Namespace |
|---|---|---|
| set registry value | T1112 Modify Registry | host-interaction/registry/create |
| load .NET assembly | T1620 Reflective Code Loading | load-code/dotnet |
| query or enumerate registry key/value | T1012 Query Registry | host-interaction/registry |
| get session user name | T1033 System Owner/User Discovery | host-interaction/session |
| get OS version | T1082 System Information Discovery | host-interaction/os/version |
| enumerate files | T1083 File and Directory Discovery | host-interaction/file-system/files |
| create TCP socket | — (pre-ATT&CK) | communication/socket/tcp |
| resolve DNS | — (pre-ATT&CK) | communication/dns |
| create or open mutex | — (pre-ATT&CK) | host-interaction/mutex |
| hash data with MD5 | — (pre-ATT&CK) | data-manipulation/hashing/md5 |
| create process | — (pre-ATT&CK) | host-interaction/process/create |
| suspend thread | — (pre-ATT&CK) | host-interaction/thread/suspend |
Note: The create TCP socket and resolve DNS capabilities map to MBC behaviors C0001.011 and C0011.001 respectively, which sit below ATT&CK technique granularity. ^[capa.txt]
References
- NanoCore entity page: nanocore
- ConfuserEx obfuscation technique: confuserex-obfuscation
- Registry Run persistence procedure: registry-run-persistence
- MalwareBazaar entry:
https://bazaar.abuse.ch/sample/b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499/ - Cluster sibling analyses:
fe81691f,48c8e8a2,d065ebea,4121d69c,0eedf3a8,cb2aa275,e48f1c56,12deaec6,b6008cf6,f017a517,37509ef2,112d957b,e4ee45f1,930b692d,36115e96,e4774281,38cac999,b0daeb6a,96ddc506
Provenance
file.txt— file(1) v5.44pefile.txt— pefile (Python) v2023.2.7strings.txt— strings (GNU binutils) v2.42floss.txt— flare-floss v3.1.1 (errored on this sample; no decoded strings recovered)capa.txt— flare-capa v7.0.1rabin2-info.txt— radare2 v5.9.2binwalk.txt— binwalk v2.3.4ssdeep.txt— ssdeep v2.14.1exiftool.json— ExifTool v12.76dynamic-analysis.md— CAPE skipped (no Windows guest available)