b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eebnanocore: b6008cf6 — 203 KB VB.NET client v1.2.2.0, ConfuserEx obfuscated, Russian domain masquerade
Executive Summary
A 203 KB PE32 .NET Framework 2.0 assembly (mmdx2.ru.com.exe) carrying the NanoCore RAT client (v1.2.2.0) inside a heavy ConfuserEx obfuscation layer. Compiled Sun 22 Feb 2015 00:49:37 UTC — identical timestamp to the eight-sibling Feb 2015 batch — but with a unique builder GUID (630148c0-c72e-4620-938d-13f9c119d87b) and a Russian domain masquerade filename. The .rsrc section holds a ~90 KB encrypted RCData payload (entropy 7.998). Static-only; CAPE skipped due to no Windows guest.
What It Is
- SHA-256:
b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb - File:
mmdx2.ru.com.exe— masquerades as a Russian domain registrar or web property. - Type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
- Size: 207,872 bytes (203 KB)
- Compile timestamp: Sun Feb 22 00:49:37 2015 UTC ^[rabin2-info.txt]
- Linker: v6.0 (VS 2005-era linker typical for .NET 2.0) ^[pefile.txt]
- CLR: v2.0.50727 (.NET Framework 2.0) ^[strings.txt:51]
- Internal name:
NanoCore Client.exe^[strings.txt:56] - Version:
1.2.2.0^[strings.txt:1626] - Builder GUID:
$630148c0-c72e-4620-938d-13f9c119d87b^[strings.txt:1624] - Language: Visual Basic .NET (MyTemplate, My.MyProject.Forms, ClientLoaderForm) ^[strings.txt:1613-1618]
- Obfuscator: ConfuserEx — 1,039 mangled names matching
#=q[A-Za-z0-9_$]{20,}==^[strings.txt:count] - Signed: No ^[pefile.txt]
- IAT: Only
mscoree.dll._CorExeMain^[pefile.txt]
Family ascription: High-confidence NanoCore sibling. Same compile timestamp, same builder version 1.2.2.0, same VB.NET WinForms bootstrap, same ConfuserEx name-mangling density, same 3-section PE layout, and same ssdeep block-1 prefix as the Feb 2015 batch (fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8, cb2aa275, e48f1c56, 12deaec6). The only deltas are the unique GUID, the encrypted .rsrc payload hash, and the social-engineering filename. See nanocore entity page for cluster-wide behaviour.
How It Works
Entry Point
ClientLoaderForm.Main at 0x0040c480 ^[r2:ClientLoaderForm.Main] — a VB.NET WinForms bootstrap that instantiates the Client singleton and wires the plugin host interfaces (IClientApp, IClientNetwork, IClientUIHost, etc.) ^[strings.txt:86-97]. The form is hidden (set_Visible / set_WindowState) ^[strings.txt:1611-1612].
Resource Payload
.rsrc (RT_RCDATA, Id 0x1) is 90,080 bytes at raw offset 0x22058 with entropy 7.998 — functionally indistinguishable from random, consistent with an encrypted plugin/config ZIP ^[pefile.txt:201-220]. No plaintext C2 host or port recovered from the resource.
Network Surface
Raw TCP socket C2 using System.Net.Sockets.Socket, IPEndPoint, SocketAsyncEventArgs, and DnsQuery_A via dnsapi.dll ^[strings.txt:67-180]. The AddHostEntry and RebuildHostCache methods ^[strings.txt:468-470] confirm builder-configured host lists that can be updated server-side, a hallmark of NanoCore's host-caching design.
Plugin Architecture
Full interface surface recovered: IClientApp, IClientData, IClientNetwork, IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost, IClientUIHost, IClientNameObjectCollection, IClientReadOnlyNameObjectCollection ^[strings.txt:86-97]. ClientInvokeDelegate, SendToServer, LogClientException, LogClientMessage, and pipe primitives (CreatePipe, PipeExists, ClosePipe) ^[strings.txt:459-461] indicate modular plugin loading with anonymous/named-pipe IPC.
Crypto & Compression
DeflateStreamfor payload decompression ^[strings.txt:150-152]Rfc2898DeriveBytesfor PBKDF2 key derivation ^[strings.txt:231]DESCryptoServiceProviderandRijndaelManagedfor resource decryption ^[strings.txt:227-232]TransformFinalBlockfor symmetric cipher finalization ^[strings.txt:1477]
Registry & File System
capa identifies registry value creation/deletion (T1112), file copy/create/delete/read/write, directory enumeration, and path generation ^[capa.txt]. These map to the typical NanoCore self-staging and persistence behaviour observed in siblings.
Decompiled Behavior
Radare2 CIL engine recovers 858 methods. The entry point is:
method.ClientLoaderForm.Main(0x0040c480) — WinForms bootstrap, hidden window,Clientsingleton instantiation ^[r2:ClientLoaderForm.Main]method.Client..ctor(0x0040acac) — constructor chain wiringIClientAppto the network layer ^[r2:Client..ctor]method.LogClientException/method.LogClientMessage— centralized logging forwarded to C2 ^[r2:method.qmLTtz8OEDrkzFTzYkI_Dg1dvKwiGw9blNcZSU_QqMsg.LogClientException]
All method bodies are ConfuserEx-flattened; readable IL is not recoverable without deobfuscation.
C2 Infrastructure
No hardcoded IP, domain, or port recovered statically. C2 configuration is encrypted inside .rsrc RT_RCDATA and resolved at runtime via AddHostEntry / RebuildHostCache. Network protocol is raw TCP (not HTTP/HTTPS) with SocketAsyncEventArgs-based async I/O.
Interesting Tidbits
- Russian domain masquerade: Filename
mmdx2.ru.com.exespoofs a.ru.comsecond-level domain — a social-engineering tactic not seen in prior siblings (which used blunt names likeokfun.exe,Backdoor.exe,moocow.exe,new88.exe, orhotro.exe). ^[triage.json] - ssdeep twinning: Block-1 prefix
MLV6Bta6dtJmakIM5matches the Feb 2015 batch exactly, confirming same builder-template; divergence after block-2 reflects unique encrypted payload. ^[ssdeep.txt] - Timer-based dispatch:
TimerCallbackpresent ^[strings.txt:254], suggesting scheduled keepalive or beaconing. - No anti-VM strings: Unlike some later NanoCore forks, no
IsDebuggerPresent,CheckRemoteDebuggerPresent, or VM registry checks observed statically. - MD5 integrity:
hash data with MD5(4 matches) per capa — likely packet checksum or config hash verification. ^[capa.txt]
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2005/2008 or SharpDevelop targeting .NET Framework 2.0, with Visual Basic .NET "My Application" Framework enabled.
Build recipe:
- Create a VB.NET WinForms project.
- In
My Project > Application, enable "Windows Forms Application Framework" and set startup form toClientLoaderForm. - Add a
.resourcesfile namedClientLoaderForm.resourceswith a hiddenRT_RCDATApayload (any encrypted ZIP). - Compile. Obfuscate with ConfuserEx v1.6.0 maximum preset.
- Verify:
strings output.exe | grep -c '#=q'should return 800+ mangled names.
Verification: Run capa output.exe and compare to this sample's capa.txt — should hit communication/socket/tcp, load-code/dotnet, host-interaction/file-system/copy, and host-interaction/registry/create.
Deployable Signatures
YARA — NanoCore ConfuserEx VB.NET Variant (Batch-Agnostic)
rule nanocore_confuserex_vbnet_batch
{
meta:
description = "NanoCore RAT client obfuscated with ConfuserEx, VB.NET build"
author = "triage-auto"
date = "2026-08-06"
sha256 = "b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb"
strings:
$nano1 = "NanoCore Client" ascii wide
$nano2 = "NanoCore.ClientPlugin" ascii wide
$nano3 = "IClientApp" ascii wide
$nano4 = "IClientNetwork" ascii wide
$nano5 = "ClientLoaderForm" ascii wide
$nano6 = "SendToServer" ascii wide
$nano7 = "AddHostEntry" ascii wide
$nano8 = "PluginUninstalling" ascii wide
$conf1 = /#=q[A-Za-z0-9_$]{20,}==/
$conf2 = /#=q[A-Za-z0-9_$]{20,}=.*=/
$vb1 = "MyTemplate" ascii wide
$vb2 = "My.MyProject.Forms" ascii wide
condition:
uint16(0) == 0x5A4D
and pe.number_of_sections == 3
and any of ($nano*)
and any of ($conf*)
and any of ($vb*)
and filesize < 500KB
}
Syntactically tested by eye; deploy to YARA sandbox before production.
Sigma — NanoCore Process Launch Hunt
title: NanoCore RAT Client Loader Execution
description: Detects NanoCore VB.NET client process based on module/interface strings and pipe creation.
logsource:
category: process_creation
product: windows
detection:
selection_strings:
- CommandLine|contains:
- 'NanoCore Client'
- 'IClientApp'
- 'IClientNetwork'
- 'ClientLoaderForm'
- 'AddHostEntry'
selection_pipe:
- PipeName|contains:
- 'PipeCreated'
- 'PipeExists'
selection_mutex:
- CommandLine|contains:
- 'ClientSettings'
- 'PluginUninstalling'
condition: 1 of selection_*
falsepositives:
- Unlikely; these are internal .NET type names not used by legitimate software.
level: critical
IOC List
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb |
Primary |
| MD5 | 2944fcbdca7ad0939db2088fc8a49dab |
Secondary |
| Filename | mmdx2.ru.com.exe |
Social-engineering masquerade |
| Compile time | 2015-02-22 00:49:37 UTC |
Builder batch timestamp |
| Version | 1.2.2.0 |
Builder version |
| GUID | 630148c0-c72e-4620-938d-13f9c119d87b |
Per-sample builder GUID |
| Internal name | NanoCore Client.exe |
— |
| ssdeep | 6144:MLV6Bta6dtJmakIM5zplNzULgm7SB7e+3:MLV6BtpmkQzcb87ei |
— |
| Sections | .text, .reloc, .rsrc |
3-section layout |
| .rsrc entropy | ~7.998 | Encrypted payload |
Behavioral Fingerprint
This binary is a .NET Framework 2.0 PE32 with a hidden WinForms bootstrap (ClientLoaderForm), 800+ ConfuserEx-mangled method names, a high-entropy .rsrc RCData payload, and raw TCP socket C2 via SocketAsyncEventArgs. It creates mutexes, pipes, and registry values; enumerates files, users, and system info; and loads plugins reflectively from embedded resources. No HTTP/HTTPS surface. Typical size 150–250 KB.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1112 | Modify Registry | set registry value (2 matches), delete registry value (2 matches) ^[capa.txt] |
| T1620 | Reflective Code Loading | load .NET assembly (2 matches) ^[capa.txt] |
| T1087 | Account Discovery | get session user name (2 matches) ^[capa.txt] |
| T1083 | File and Directory Discovery | enumerate files in .NET (2 matches), get common file path (3 matches) ^[capa.txt] |
| T1012 | Query Registry | query or enumerate registry key (6 matches), query or enumerate registry value (5 matches) ^[capa.txt] |
| T1082 | System Information Discovery | get OS version in .NET, get hostname ^[capa.txt] |
| T1033 | System Owner/User Discovery | get session user name (2 matches) ^[capa.txt] |
References
- nanocore — cluster entity page with 8 prior siblings and full TTP catalogue.
- confuserex-obfuscation — obfuscator technique page.
- MalwareBazaar entry: artifact
85cb7337-59e2-4e8c-87ce-d8d27cd15817(source: OpenCTI). - Sibling analyses:
fe81691f,48c8e8a2,d065ebea,4121d69c,0eedf3a8,cb2aa275,e48f1c56,12deaec6.
Provenance
file.txt— file(1) v5.44pefile.txt— pefile (Python) analysisstrings.txt— GNU strings (default 4-byte min)capa.txt— Mandiant capa v7.0.0 static analysisrabin2-info.txt— radare2 v5.9.6 binary headerfloss.txt— FireEye flare-floss (failed due to incorrect CLI invocation; no decoded output)binwalk.txt— binwalk v2.3.4- Radare2 CIL decompilation attempted; ConfuserEx flattening rendered method bodies unreadable without deobfuscation.