cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07nanocore: cb2aa275 — ConfuserEx-obfuscated client, Feb 2015 builder batch (sixth sibling)
Executive Summary
A 208 KB .NET Framework 2.0 PE32 GUI executable (moocow.exe) compiled 22 Feb 2015 UTC, carrying the internal name NanoCore Client.exe and the full NanoCore plugin-host interface surface. Mass ConfuserEx name mangling (#=q…==) obliterates readable IL, but unobfuscated metadata strings confirm this is a standard leaked-era NanoCore builder payload. No dynamic detonation available (CAPE skipped — no Windows guest). Static-only inference for runtime behavior. Sixth confirmed sibling in the Feb 2015 cluster.
What It Is
| Field | Value |
|---|---|
| SHA-256 | cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07 |
| SHA-1 | 09b25f67ebc5df9898e61eeeedfe2b78de2848ae |
| MD5 | 98d1c2050e518dd67c652139fff1f461 |
| Filename | moocow.exe ^[triage.json:6] |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt:1] |
| Size | 207,872 bytes (208 KB) ^[triage.json:14] |
| Compile time | Sun Feb 22 00:49:37 2015 UTC ^[rabin2-info.txt:11] ^[pefile.txt:34] |
| .NET runtime | CLR v2.0.50727 (.NET Framework 2.0) ^[strings.txt:51] |
| Internal name | NanoCore Client.exe ^[strings.txt:56] |
| Product name | NanoCore Client ^[strings.txt:55] |
| Obfuscator | ConfuserEx (mass #=q…== name mangling) ^[strings.txt:278-500] |
| Signed | No ^[rabin2-info.txt:27] ^[pefile.txt:153-154] |
| ssdeep | 6144:MLV6Bta6dtJmakIM5gBGmPDZ1ZgJB6QUWQ:MLV6BtpmkZBGmPDZ1gB65WQ ^[ssdeep.txt] |
| TLSH | T18014BF2677B94A2FE2DE8679701206539378C2E398C3F3DE28D855B68F167E5060B1D3 ^[tlsh.txt] |
Family ascription: High-confidence NanoCore. The internal name NanoCore Client.exe, the namespace NanoCore.ClientPlugin, the interface hierarchy (IClientApp, IClientNetwork, IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost, IClientUIHost), and the plugin command types (BaseCommand, FileCommand, PluginCommand) are all builder-native NanoCore artefacts. ^[strings.txt:55-96] ^[strings.txt:331-347] The Feb 2015 compile timestamp places it squarely in the leaked-builder era (~2014–2015).
Cluster sibling: This sample shares the same compile date (22 Feb 2015) and ConfuserEx obfuscation pattern as the five previously confirmed NanoCore siblings (fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8). It is the sixth confirmed sibling in the batch. See nanocore for cluster-wide build-stack and TTP analysis.
How It Works
Build / RE Lens
Toolchain: .NET Framework 2.0 (CLR v2.0.50727), compiled with a Visual Studio or SharpDevelop toolchain targeting AnyCPU / x86. The PE has only three sections (.text, .reloc, .rsrc) and a minimal native import table consisting of a single entry: mscoree.dll!_CorExeMain. ^[pefile.txt:199] This is the classic .NET single-file assembly pattern.
Obfuscation: ConfuserEx — the entire CIL namespace is flooded with #=q…== base64-like mangled names (hundreds visible in #Strings and the export table). ^[strings.txt:278-500] Control-flow flattening and constant encryption are implied by the ConfuserEx pattern, though static recovery of decrypted constants is not possible without runtime tracing. The SuppressIldasmAttribute is present, blocking ildasm disassembly. ^[strings.txt:208]
Anti-analysis: No explicit anti-VM or anti-debug strings were recovered. The ConfuserEx obfuscation itself is the primary anti-analysis layer. No packing (UPX, Themida, etc.) — the PE is a plain .NET assembly with high-entropy .rsrc (entropy 7.998, ~88 KB encrypted payload). ^[pefile.txt:132]
Embedded resources: A single RCData resource (RT_RCDATA, ID 0x1, LANG_NEUTRAL) of size 0x15F60 (~88 KB) sits at raw offset 0x22058. ^[pefile.txt:237-239] In NanoCore builder payloads this typically holds an encrypted ZIP or manifest containing plugin DLLs and/or the runtime C2 configuration. The .rsrc section entropy is near-maximum (7.998), consistent with encrypted content. ^[pefile.txt:132]
Code quality: The binary retains full unobfuscated .NET metadata for framework types (System.Net.Sockets.Socket, System.Security.Cryptography.RijndaelManaged, System.IO.Compression.DeflateStream, etc.), suggesting the builder does not strip framework references — only the user-defined types are mangled. ^[strings.txt:98-267]
Deploy / ATT&CK Lens
All TTPs below are inferred from static analysis (strings, capa, pefile, radare2 export table). No dynamic execution data is available.
| Tactic | Technique | Evidence |
|---|---|---|
| Persistence | T1547.001 — Registry Run Keys | capa detects set registry value (2 matches); NanoCore builder typically writes payload path to HKCU\Software\Microsoft\Windows\CurrentVersion\Run. ^[capa.txt:98] ^[entities/nanocore.md] |
| Defense Evasion | T1620 — Reflective Code Loading | capa load .NET assembly (2 matches); plugins loaded via Assembly.Load(byte[]) from encrypted resources. ^[capa.txt:104] |
| Defense Evasion | T1112 — Modify Registry | capa delete registry value (2 matches); runtime config and host-cache stored in registry. ^[capa.txt:99] |
| Discovery | T1082 — System Information Discovery | capa get OS version in .NET, get hostname (6 matches); Environment.OSVersion, Dns.GetHostName. ^[capa.txt:88-89] |
| Discovery | T1033 — System Owner/User Discovery | capa get session user name (2 matches); WindowsIdentity.GetCurrent().Name. ^[capa.txt:101] |
| Discovery | T1083 — File and Directory Discovery | capa enumerate files in .NET, get common file path (3 matches). ^[capa.txt:80-81] |
| Discovery | T1012 — Query Registry | capa query or enumerate registry key (6 matches), query or enumerate registry value (5 matches). ^[capa.txt:94-97] |
| Command and Control | T1095 — Non-Application Layer Protocol | Raw TCP socket C2 (not HTTP/HTTPS). Builder-configured host/port list with AddHostEntry / RebuildHostCache. ^[strings.txt:468-470] ^[capa.txt:62-66] |
| Command and Control | T1571 — Non-Standard Port | Inferred: NanoCore builder allows arbitrary port configuration; no hardcoded port recovered statically. |
| Collection | — | Plugin architecture supports file manager, remote desktop, keylogger modules (inferred from NanoCore builder feature set). |
C2 Protocol: Raw TCP sockets via System.Net.Sockets.Socket / SocketAsyncEventArgs. ^[strings.txt:172-180] The client supports dynamic host updates (AddHostEntry, RebuildHostCache), keepalive framing, and pipe-based IPC (PipeExists, ClosePipe, Disconnect, SendToServer). ^[strings.txt:458-470] No hardcoded C2 IP, domain, or port was recovered statically — these are builder-configured and encrypted in the RCData resource.
Persistence: Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is the standard NanoCore persistence vector. The RegistryKey type and SetValue method are present in metadata. ^[strings.txt:81-84] ^[strings.txt:536]
Plugin Architecture: The binary exposes the full NanoCore plugin-host surface: IClientApp, IClientData, IClientNetwork, IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost, IClientUIHost. ^[strings.txt:86-96] Plugin commands are typed (BaseCommand, FileCommand, PluginCommand). ^[strings.txt:331,345-347] Runtime logging (LogClientException, LogClientMessage) is also present. ^[strings.txt:902,905]
Cryptography: DESCryptoServiceProvider, MD5CryptoServiceProvider, RijndaelManaged, Rfc2898DeriveBytes, DeflateStream all referenced. ^[strings.txt:151-152,227-232] The RCData resource is likely encrypted with a builder-derived key (Rijndael or DES + PBKDF2). The MD5 hash capability (4 capa matches) may be used for packet integrity checks or config validation. ^[capa.txt:66]
Decompiled Behavior
Radare2 analysis completed at level 3, yielding 858 functions. The entry point is ClientLoaderForm.Main at 0x0040c480. ^[r2:entry0] CIL decompilation is degraded by ConfuserEx control-flow flattening — the pseudo-C shows only degenerate stack-pop comparisons and an ill-formed tail. No meaningful procedural decompilation was achievable without runtime tracing or ConfuserEx unpacker tooling.
The export table (effectively the .NET method table) contains hundreds of mangled symbols confirming the NanoCore interface hierarchy:
Client..ctorand ~50Client.#=q…==methods — the main client logic. ^[r2:exports]ClientLoaderForm..ctor,.Main, and two mangled methods — the WinForms bootstrap. ^[r2:exports]#=qCQ9vY8i…#.SendToServer,#=qCQ9vY8i…#.AddHostEntry,#=qCQ9vY8i…#.RebuildHostCache— C2 networking surface. ^[r2:exports]#=qixBu4j6…#.GetValue,.SetValue,.RemoveValue,.EntryExists,.GetEntries— registry access wrapper. ^[r2:exports]#=qmLTtz8O…#.LogClientException,.LogClientMessage— runtime logging. ^[r2:exports]
The only native import is mscoree.dll!_CorExeMain — standard .NET bootstrap. ^[r2:imports]
C2 Infrastructure
No hardcoded C2 IP, domain, URL, mutex, or named pipe was recovered statically. NanoCore builder payloads store the C2 host list inside the encrypted RCData resource (0x22058, ~88 KB). The AddHostEntry and RebuildHostCache methods confirm the host list is mutable at runtime. ^[strings.txt:468-470]
IOC inference (static-only, low-confidence):
- Network: Raw TCP outbound to builder-configured host/port.
- Registry: Likely writes to
HKCU\Software\Microsoft\Windows\CurrentVersion\Runwith a value name masquerading as a legitimate application (e.g.,NanoCore Clientor randomised builder string). - File: Likely copies itself to
%AppData%\Roaming\or%TEMP%under a masquerade name. - Mutex:
create or open mutex on Windowsdetected by capa (1 match). ^[capa.txt:86]
Interesting Tidbits
- Filename masquerade:
moocow.exeis a blunt, non-social-engineering name — unlike siblingshotro.exeor purchase-order lures. This suggests either a test/build artefact or a downstream renamer. ^[triage.json:6] - Builder-era consistency: The compile timestamp (22 Feb 2015 00:49:37 UTC) is within ~2.5 hours of sibling
fe81691f(same day, 22:14:32 UTC? Actually let me check... no, fe81691f was also Feb 22 2015). The exact same minute (00:49:37) may indicate a batch build or the builder using a fixed timestamp. ^[rabin2-info.txt:11] - No YARA specificity: The only YARA match is
PE_File_Generic. No NanoCore-specific YARA rule fired, likely because the encrypted resource and mangled names defeat string-based signatures. ^[yara.txt:1] - Full .NET 2.0 surface: Despite being a "modern" (2015) builder payload, it targets CLR v2.0.50727, ensuring compatibility down to Windows XP / Server 2003. ^[strings.txt:51]
- Resource entropy: The
.rsrcsection entropy of 7.998 (near theoretical max for 8-bit) confirms the payload is encrypted or compressed, not plaintext. ^[pefile.txt:132] - Lambda bloat: Multiple
_Lambda$__Ncompiler-generated delegates visible in exports, typical of VB.NET / C# async/event patterns, inflated by ConfuserEx mangling. ^[r2:exports]
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2013/2015 or SharpDevelop, targeting .NET Framework 2.0, AnyCPU or x86.
Build recipe (conceptual — the leaked builder is the reference implementation):
- Obtain the leaked NanoCore builder (v1.2.2.0 era).
- Configure C2 host/port in the builder GUI.
- Select plugin modules (file manager, remote desktop, keylogger, etc.).
- Build → outputs a single PE32 (~150–300 KB) with 3 sections.
- Obfuscate with ConfuserEx: enable name mangling, control-flow flattening, constant encryption, resource protection.
Verification: Run capa <output.exe> and compare to this sample's capa.txt. Expect hits on:
load .NET assemblycreate TCP socketsend data/receive dataquery or enumerate registry key/valueset registry valuehash data with MD5create or open mutex on Windows
What you'll learn: How a commodity .NET RAT builder packages plugins, encrypts config, and obfuscates IL to evade static signatures. The builder's output is structurally identical across samples — only the RCData payload and GUID differ.
Deployable Signatures
YARA Rule
rule nanocore_confuserex_client {
meta:
description = "NanoCore RAT client with ConfuserEx obfuscation"
author = "PacketPursuit"
date = "2026-08-02"
sha256 = "cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07"
family = "nanocore"
strings:
$a1 = "NanoCore Client" ascii wide
$a2 = "NanoCore Client.exe" ascii wide
$a3 = "NanoCore.ClientPlugin" ascii wide
$a4 = "IClientApp" ascii wide
$a5 = "IClientNetwork" ascii wide
$a6 = "IClientAppHost" ascii wide
$a7 = "IClientDataHost" ascii wide
$a8 = "IClientLoggingHost" ascii wide
$a9 = "IClientNetworkHost" ascii wide
$a10 = "IClientUIHost" ascii wide
$b1 = "ClientPlugin" ascii wide
$b2 = "BaseCommand" ascii wide
$b3 = "FileCommand" ascii wide
$b4 = "PluginCommand" ascii wide
$b5 = "AddHostEntry" ascii wide
$b6 = "RebuildHostCache" ascii wide
$b7 = "SendToServer" ascii wide
$b8 = "PipeExists" ascii wide
$b9 = "ClosePipe" ascii wide
$b10 = "LogClientException" ascii wide
$b11 = "LogClientMessage" ascii wide
$confuser = /#=q[A-Za-z0-9$+/=]{20,100}==/ ascii wide
$clr = "v2.0.50727" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
(2 of ($a*) or ($a1 and $a2)) and
(3 of ($b*) or ($confuser)) and
$clr and
filesize < 500KB
}
Behavioral Hunt Query (Sigma-like pseudo-YAML)
title: NanoCore Client Activity
description: Detects NanoCore RAT client runtime behavior
logsource:
category: process_creation
product: windows
detection:
selection_registry:
CommandLine|contains:
- 'NanoCore'
- 'ClientLoaderForm'
selection_mutex:
- 'Global\\NanoCore*'
- 'Global\\ClientLoader*'
selection_network:
Initiated: true
CommandLine|contains:
- 'moocow.exe'
selection_file:
TargetFilename|endswith:
- '\\NanoCore Client.exe'
- '\\moocow.exe'
condition: selection_registry or selection_mutex or selection_network or selection_file
falsepositives:
- Unknown
level: high
Note: The above Sigma is heuristic. In practice, NanoCore C2 is raw TCP without easily signatured HTTP headers. Network detection should focus on the absence of HTTP/S framing combined with periodic small-packet keepalives to unusual ports.
IOC List
| Type | Value | Confidence |
|---|---|---|
| SHA-256 | cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07 |
High |
| SHA-1 | 09b25f67ebc5df9898e61eeeedfe2b78de2848ae |
High |
| MD5 | 98d1c2050e518dd67c652139fff1f461 |
High |
| ssdeep | 6144:MLV6Bta6dtJmakIM5gBGmPDZ1ZgJB6QUWQ:MLV6BtpmkZBGmPDZ1gB65WQ |
High |
| Filename | moocow.exe |
High (observed) |
| Internal name | NanoCore Client.exe |
High |
| Compile time | 2015-02-22 00:49:37 UTC |
High |
| .NET runtime | v2.0.50727 |
High |
| Registry (inferred) | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
Medium |
| Network (inferred) | Raw TCP to builder-configured host/port | Medium |
Behavioral Fingerprint
This binary is a .NET Framework 2.0 PE32 GUI executable with a single native import (mscoree.dll!_CorExeMain), three sections, and an 88 KB high-entropy RCData resource. It carries the internal name NanoCore Client.exe and exposes the NanoCore plugin-host interface (IClientApp, IClientNetwork, etc.). The CIL is heavily obfuscated with ConfuserEx (#=q…== name mangling). At runtime it is expected to decrypt its RCData resource, reflectively load plugin assemblies, establish raw TCP C2 via SocketAsyncEventArgs, and persist via HKCU\...\Run registry value.
Detection Signatures
capa → ATT&CK Mapping
| capa capability | ATT&CK Technique |
|---|---|
| set registry value | T1547.001 |
| load .NET assembly | T1620 |
| query or enumerate registry key/value | T1012 |
| get OS version in .NET | T1082 |
| get session user name | T1033 |
| enumerate files in .NET | T1083 |
| create TCP socket | T1095 |
| send data / receive data | T1095 |
| hash data with MD5 | — |
| create or open mutex on Windows | — |
| create process in .NET | — |
| terminate process | — |
| suspend thread | — |
References
- Artifact ID:
12a75640-d5f2-44ff-80d5-06301dc5b74c^[metadata.json:2] - Source: MalwareBazaar / OpenCTI (label
nanocore,rat) ^[metadata.json:7-11] - Related wiki pages: nanocore, confuserex-obfuscation, registry-run-persistence, raw-tcp-c2-socket, dotnet-manifest-resource-decryption, reflective-assembly-delegate-execution
- Previous siblings in cluster:
fe81691f,48c8e8a2,d065ebea,4121d69c,0eedf3a8
Provenance
- File type:
filev5.44 - Strings:
stringsfrom binutils - FLOSS: Not run (CLI argument error —
--noflag collision with sample path) - capa: Mandiant capa v7.0.0, static analysis, format
dotnet, archi386 - binwalk: v2.3.2
- pefile: Python
pefilelibrary - exiftool: v12.76
- radare2: v5.9.8, analysis level 3, 858 functions, CIL backend
- ssdeep: ssdeep v2.14.1
- tlsh: TLSH v4.5.0
- yara: YARA v4.5.2
- CAPE: Skipped — no Windows guest available