typeanalysisfamilynanocoreconfidencehighcreated2026-08-06updated2026-08-06malware-familyratdotnetc2persistenceobfuscationdefense-evasiondiscoveryc2-protocol
SHA-256: b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb

nanocore: b6008cf6 — 203 KB VB.NET client v1.2.2.0, ConfuserEx obfuscated, Russian domain masquerade

Executive Summary

A 203 KB PE32 .NET Framework 2.0 assembly (mmdx2.ru.com.exe) carrying the NanoCore RAT client (v1.2.2.0) inside a heavy ConfuserEx obfuscation layer. Compiled Sun 22 Feb 2015 00:49:37 UTC — identical timestamp to the eight-sibling Feb 2015 batch — but with a unique builder GUID (630148c0-c72e-4620-938d-13f9c119d87b) and a Russian domain masquerade filename. The .rsrc section holds a ~90 KB encrypted RCData payload (entropy 7.998). Static-only; CAPE skipped due to no Windows guest.

What It Is

  • SHA-256: b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb
  • File: mmdx2.ru.com.exe — masquerades as a Russian domain registrar or web property.
  • Type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
  • Size: 207,872 bytes (203 KB)
  • Compile timestamp: Sun Feb 22 00:49:37 2015 UTC ^[rabin2-info.txt]
  • Linker: v6.0 (VS 2005-era linker typical for .NET 2.0) ^[pefile.txt]
  • CLR: v2.0.50727 (.NET Framework 2.0) ^[strings.txt:51]
  • Internal name: NanoCore Client.exe ^[strings.txt:56]
  • Version: 1.2.2.0 ^[strings.txt:1626]
  • Builder GUID: $630148c0-c72e-4620-938d-13f9c119d87b ^[strings.txt:1624]
  • Language: Visual Basic .NET (MyTemplate, My.MyProject.Forms, ClientLoaderForm) ^[strings.txt:1613-1618]
  • Obfuscator: ConfuserEx — 1,039 mangled names matching #=q[A-Za-z0-9_$]{20,}== ^[strings.txt:count]
  • Signed: No ^[pefile.txt]
  • IAT: Only mscoree.dll._CorExeMain ^[pefile.txt]

Family ascription: High-confidence NanoCore sibling. Same compile timestamp, same builder version 1.2.2.0, same VB.NET WinForms bootstrap, same ConfuserEx name-mangling density, same 3-section PE layout, and same ssdeep block-1 prefix as the Feb 2015 batch (fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8, cb2aa275, e48f1c56, 12deaec6). The only deltas are the unique GUID, the encrypted .rsrc payload hash, and the social-engineering filename. See nanocore entity page for cluster-wide behaviour.

How It Works

Entry Point

ClientLoaderForm.Main at 0x0040c480 ^[r2:ClientLoaderForm.Main] — a VB.NET WinForms bootstrap that instantiates the Client singleton and wires the plugin host interfaces (IClientApp, IClientNetwork, IClientUIHost, etc.) ^[strings.txt:86-97]. The form is hidden (set_Visible / set_WindowState) ^[strings.txt:1611-1612].

Resource Payload

.rsrc (RT_RCDATA, Id 0x1) is 90,080 bytes at raw offset 0x22058 with entropy 7.998 — functionally indistinguishable from random, consistent with an encrypted plugin/config ZIP ^[pefile.txt:201-220]. No plaintext C2 host or port recovered from the resource.

Network Surface

Raw TCP socket C2 using System.Net.Sockets.Socket, IPEndPoint, SocketAsyncEventArgs, and DnsQuery_A via dnsapi.dll ^[strings.txt:67-180]. The AddHostEntry and RebuildHostCache methods ^[strings.txt:468-470] confirm builder-configured host lists that can be updated server-side, a hallmark of NanoCore's host-caching design.

Plugin Architecture

Full interface surface recovered: IClientApp, IClientData, IClientNetwork, IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost, IClientUIHost, IClientNameObjectCollection, IClientReadOnlyNameObjectCollection ^[strings.txt:86-97]. ClientInvokeDelegate, SendToServer, LogClientException, LogClientMessage, and pipe primitives (CreatePipe, PipeExists, ClosePipe) ^[strings.txt:459-461] indicate modular plugin loading with anonymous/named-pipe IPC.

Crypto & Compression

  • DeflateStream for payload decompression ^[strings.txt:150-152]
  • Rfc2898DeriveBytes for PBKDF2 key derivation ^[strings.txt:231]
  • DESCryptoServiceProvider and RijndaelManaged for resource decryption ^[strings.txt:227-232]
  • TransformFinalBlock for symmetric cipher finalization ^[strings.txt:1477]

Registry & File System

capa identifies registry value creation/deletion (T1112), file copy/create/delete/read/write, directory enumeration, and path generation ^[capa.txt]. These map to the typical NanoCore self-staging and persistence behaviour observed in siblings.

Decompiled Behavior

Radare2 CIL engine recovers 858 methods. The entry point is:

  • method.ClientLoaderForm.Main (0x0040c480) — WinForms bootstrap, hidden window, Client singleton instantiation ^[r2:ClientLoaderForm.Main]
  • method.Client..ctor (0x0040acac) — constructor chain wiring IClientApp to the network layer ^[r2:Client..ctor]
  • method.LogClientException / method.LogClientMessage — centralized logging forwarded to C2 ^[r2:method.qmLTtz8OEDrkzFTzYkI_Dg1dvKwiGw9blNcZSU_QqMsg.LogClientException]

All method bodies are ConfuserEx-flattened; readable IL is not recoverable without deobfuscation.

C2 Infrastructure

No hardcoded IP, domain, or port recovered statically. C2 configuration is encrypted inside .rsrc RT_RCDATA and resolved at runtime via AddHostEntry / RebuildHostCache. Network protocol is raw TCP (not HTTP/HTTPS) with SocketAsyncEventArgs-based async I/O.

Interesting Tidbits

  • Russian domain masquerade: Filename mmdx2.ru.com.exe spoofs a .ru.com second-level domain — a social-engineering tactic not seen in prior siblings (which used blunt names like okfun.exe, Backdoor.exe, moocow.exe, new88.exe, or hotro.exe). ^[triage.json]
  • ssdeep twinning: Block-1 prefix MLV6Bta6dtJmakIM5 matches the Feb 2015 batch exactly, confirming same builder-template; divergence after block-2 reflects unique encrypted payload. ^[ssdeep.txt]
  • Timer-based dispatch: TimerCallback present ^[strings.txt:254], suggesting scheduled keepalive or beaconing.
  • No anti-VM strings: Unlike some later NanoCore forks, no IsDebuggerPresent, CheckRemoteDebuggerPresent, or VM registry checks observed statically.
  • MD5 integrity: hash data with MD5 (4 matches) per capa — likely packet checksum or config hash verification. ^[capa.txt]

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2005/2008 or SharpDevelop targeting .NET Framework 2.0, with Visual Basic .NET "My Application" Framework enabled.

Build recipe:

  1. Create a VB.NET WinForms project.
  2. In My Project > Application, enable "Windows Forms Application Framework" and set startup form to ClientLoaderForm.
  3. Add a .resources file named ClientLoaderForm.resources with a hidden RT_RCDATA payload (any encrypted ZIP).
  4. Compile. Obfuscate with ConfuserEx v1.6.0 maximum preset.
  5. Verify: strings output.exe | grep -c '#=q' should return 800+ mangled names.

Verification: Run capa output.exe and compare to this sample's capa.txt — should hit communication/socket/tcp, load-code/dotnet, host-interaction/file-system/copy, and host-interaction/registry/create.

Deployable Signatures

YARA — NanoCore ConfuserEx VB.NET Variant (Batch-Agnostic)

rule nanocore_confuserex_vbnet_batch
{
    meta:
        description = "NanoCore RAT client obfuscated with ConfuserEx, VB.NET build"
        author      = "triage-auto"
        date        = "2026-08-06"
        sha256      = "b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb"
    strings:
        $nano1 = "NanoCore Client" ascii wide
        $nano2 = "NanoCore.ClientPlugin" ascii wide
        $nano3 = "IClientApp" ascii wide
        $nano4 = "IClientNetwork" ascii wide
        $nano5 = "ClientLoaderForm" ascii wide
        $nano6 = "SendToServer" ascii wide
        $nano7 = "AddHostEntry" ascii wide
        $nano8 = "PluginUninstalling" ascii wide
        $conf1 = /#=q[A-Za-z0-9_$]{20,}==/
        $conf2 = /#=q[A-Za-z0-9_$]{20,}=.*=/
        $vb1   = "MyTemplate" ascii wide
        $vb2   = "My.MyProject.Forms" ascii wide
    condition:
        uint16(0) == 0x5A4D
        and pe.number_of_sections == 3
        and any of ($nano*)
        and any of ($conf*)
        and any of ($vb*)
        and filesize < 500KB
}

Syntactically tested by eye; deploy to YARA sandbox before production.

Sigma — NanoCore Process Launch Hunt

title: NanoCore RAT Client Loader Execution
description: Detects NanoCore VB.NET client process based on module/interface strings and pipe creation.
logsource:
    category: process_creation
    product: windows
detection:
    selection_strings:
        - CommandLine|contains:
            - 'NanoCore Client'
            - 'IClientApp'
            - 'IClientNetwork'
            - 'ClientLoaderForm'
            - 'AddHostEntry'
    selection_pipe:
        - PipeName|contains:
            - 'PipeCreated'
            - 'PipeExists'
    selection_mutex:
        - CommandLine|contains:
            - 'ClientSettings'
            - 'PluginUninstalling'
    condition: 1 of selection_*
falsepositives:
    - Unlikely; these are internal .NET type names not used by legitimate software.
level: critical

IOC List

Indicator Value Notes
SHA-256 b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb Primary
MD5 2944fcbdca7ad0939db2088fc8a49dab Secondary
Filename mmdx2.ru.com.exe Social-engineering masquerade
Compile time 2015-02-22 00:49:37 UTC Builder batch timestamp
Version 1.2.2.0 Builder version
GUID 630148c0-c72e-4620-938d-13f9c119d87b Per-sample builder GUID
Internal name NanoCore Client.exe —
ssdeep 6144:MLV6Bta6dtJmakIM5zplNzULgm7SB7e+3:MLV6BtpmkQzcb87ei —
Sections .text, .reloc, .rsrc 3-section layout
.rsrc entropy ~7.998 Encrypted payload

Behavioral Fingerprint

This binary is a .NET Framework 2.0 PE32 with a hidden WinForms bootstrap (ClientLoaderForm), 800+ ConfuserEx-mangled method names, a high-entropy .rsrc RCData payload, and raw TCP socket C2 via SocketAsyncEventArgs. It creates mutexes, pipes, and registry values; enumerates files, users, and system info; and loads plugins reflectively from embedded resources. No HTTP/HTTPS surface. Typical size 150–250 KB.

Detection Signatures

ATT&CK ID Technique Evidence
T1112 Modify Registry set registry value (2 matches), delete registry value (2 matches) ^[capa.txt]
T1620 Reflective Code Loading load .NET assembly (2 matches) ^[capa.txt]
T1087 Account Discovery get session user name (2 matches) ^[capa.txt]
T1083 File and Directory Discovery enumerate files in .NET (2 matches), get common file path (3 matches) ^[capa.txt]
T1012 Query Registry query or enumerate registry key (6 matches), query or enumerate registry value (5 matches) ^[capa.txt]
T1082 System Information Discovery get OS version in .NET, get hostname ^[capa.txt]
T1033 System Owner/User Discovery get session user name (2 matches) ^[capa.txt]

References

  • nanocore — cluster entity page with 8 prior siblings and full TTP catalogue.
  • confuserex-obfuscation — obfuscator technique page.
  • MalwareBazaar entry: artifact 85cb7337-59e2-4e8c-87ce-d8d27cd15817 (source: OpenCTI).
  • Sibling analyses: fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8, cb2aa275, e48f1c56, 12deaec6.

Provenance

  • file.txt — file(1) v5.44
  • pefile.txt — pefile (Python) analysis
  • strings.txt — GNU strings (default 4-byte min)
  • capa.txt — Mandiant capa v7.0.0 static analysis
  • rabin2-info.txt — radare2 v5.9.6 binary header
  • floss.txt — FireEye flare-floss (failed due to incorrect CLI invocation; no decoded output)
  • binwalk.txt — binwalk v2.3.4
  • Radare2 CIL decompilation attempted; ConfuserEx flattening rendered method bodies unreadable without deobfuscation.