typeanalysisfamilynanocoreconfidencehighcreated2026-08-02updated2026-08-02malware-familyratdotnetc2persistenceobfuscationconfuserex
SHA-256: cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07

nanocore: cb2aa275 — ConfuserEx-obfuscated client, Feb 2015 builder batch (sixth sibling)

Executive Summary

A 208 KB .NET Framework 2.0 PE32 GUI executable (moocow.exe) compiled 22 Feb 2015 UTC, carrying the internal name NanoCore Client.exe and the full NanoCore plugin-host interface surface. Mass ConfuserEx name mangling (#=q…==) obliterates readable IL, but unobfuscated metadata strings confirm this is a standard leaked-era NanoCore builder payload. No dynamic detonation available (CAPE skipped — no Windows guest). Static-only inference for runtime behavior. Sixth confirmed sibling in the Feb 2015 cluster.

What It Is

Field Value
SHA-256 cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07
SHA-1 09b25f67ebc5df9898e61eeeedfe2b78de2848ae
MD5 98d1c2050e518dd67c652139fff1f461
Filename moocow.exe ^[triage.json:6]
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt:1]
Size 207,872 bytes (208 KB) ^[triage.json:14]
Compile time Sun Feb 22 00:49:37 2015 UTC ^[rabin2-info.txt:11] ^[pefile.txt:34]
.NET runtime CLR v2.0.50727 (.NET Framework 2.0) ^[strings.txt:51]
Internal name NanoCore Client.exe ^[strings.txt:56]
Product name NanoCore Client ^[strings.txt:55]
Obfuscator ConfuserEx (mass #=q…== name mangling) ^[strings.txt:278-500]
Signed No ^[rabin2-info.txt:27] ^[pefile.txt:153-154]
ssdeep 6144:MLV6Bta6dtJmakIM5gBGmPDZ1ZgJB6QUWQ:MLV6BtpmkZBGmPDZ1gB65WQ ^[ssdeep.txt]
TLSH T18014BF2677B94A2FE2DE8679701206539378C2E398C3F3DE28D855B68F167E5060B1D3 ^[tlsh.txt]

Family ascription: High-confidence NanoCore. The internal name NanoCore Client.exe, the namespace NanoCore.ClientPlugin, the interface hierarchy (IClientApp, IClientNetwork, IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost, IClientUIHost), and the plugin command types (BaseCommand, FileCommand, PluginCommand) are all builder-native NanoCore artefacts. ^[strings.txt:55-96] ^[strings.txt:331-347] The Feb 2015 compile timestamp places it squarely in the leaked-builder era (~2014–2015).

Cluster sibling: This sample shares the same compile date (22 Feb 2015) and ConfuserEx obfuscation pattern as the five previously confirmed NanoCore siblings (fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8). It is the sixth confirmed sibling in the batch. See nanocore for cluster-wide build-stack and TTP analysis.

How It Works

Build / RE Lens

Toolchain: .NET Framework 2.0 (CLR v2.0.50727), compiled with a Visual Studio or SharpDevelop toolchain targeting AnyCPU / x86. The PE has only three sections (.text, .reloc, .rsrc) and a minimal native import table consisting of a single entry: mscoree.dll!_CorExeMain. ^[pefile.txt:199] This is the classic .NET single-file assembly pattern.

Obfuscation: ConfuserEx — the entire CIL namespace is flooded with #=q…== base64-like mangled names (hundreds visible in #Strings and the export table). ^[strings.txt:278-500] Control-flow flattening and constant encryption are implied by the ConfuserEx pattern, though static recovery of decrypted constants is not possible without runtime tracing. The SuppressIldasmAttribute is present, blocking ildasm disassembly. ^[strings.txt:208]

Anti-analysis: No explicit anti-VM or anti-debug strings were recovered. The ConfuserEx obfuscation itself is the primary anti-analysis layer. No packing (UPX, Themida, etc.) — the PE is a plain .NET assembly with high-entropy .rsrc (entropy 7.998, ~88 KB encrypted payload). ^[pefile.txt:132]

Embedded resources: A single RCData resource (RT_RCDATA, ID 0x1, LANG_NEUTRAL) of size 0x15F60 (~88 KB) sits at raw offset 0x22058. ^[pefile.txt:237-239] In NanoCore builder payloads this typically holds an encrypted ZIP or manifest containing plugin DLLs and/or the runtime C2 configuration. The .rsrc section entropy is near-maximum (7.998), consistent with encrypted content. ^[pefile.txt:132]

Code quality: The binary retains full unobfuscated .NET metadata for framework types (System.Net.Sockets.Socket, System.Security.Cryptography.RijndaelManaged, System.IO.Compression.DeflateStream, etc.), suggesting the builder does not strip framework references — only the user-defined types are mangled. ^[strings.txt:98-267]

Deploy / ATT&CK Lens

All TTPs below are inferred from static analysis (strings, capa, pefile, radare2 export table). No dynamic execution data is available.

Tactic Technique Evidence
Persistence T1547.001 — Registry Run Keys capa detects set registry value (2 matches); NanoCore builder typically writes payload path to HKCU\Software\Microsoft\Windows\CurrentVersion\Run. ^[capa.txt:98] ^[entities/nanocore.md]
Defense Evasion T1620 — Reflective Code Loading capa load .NET assembly (2 matches); plugins loaded via Assembly.Load(byte[]) from encrypted resources. ^[capa.txt:104]
Defense Evasion T1112 — Modify Registry capa delete registry value (2 matches); runtime config and host-cache stored in registry. ^[capa.txt:99]
Discovery T1082 — System Information Discovery capa get OS version in .NET, get hostname (6 matches); Environment.OSVersion, Dns.GetHostName. ^[capa.txt:88-89]
Discovery T1033 — System Owner/User Discovery capa get session user name (2 matches); WindowsIdentity.GetCurrent().Name. ^[capa.txt:101]
Discovery T1083 — File and Directory Discovery capa enumerate files in .NET, get common file path (3 matches). ^[capa.txt:80-81]
Discovery T1012 — Query Registry capa query or enumerate registry key (6 matches), query or enumerate registry value (5 matches). ^[capa.txt:94-97]
Command and Control T1095 — Non-Application Layer Protocol Raw TCP socket C2 (not HTTP/HTTPS). Builder-configured host/port list with AddHostEntry / RebuildHostCache. ^[strings.txt:468-470] ^[capa.txt:62-66]
Command and Control T1571 — Non-Standard Port Inferred: NanoCore builder allows arbitrary port configuration; no hardcoded port recovered statically.
Collection — Plugin architecture supports file manager, remote desktop, keylogger modules (inferred from NanoCore builder feature set).

C2 Protocol: Raw TCP sockets via System.Net.Sockets.Socket / SocketAsyncEventArgs. ^[strings.txt:172-180] The client supports dynamic host updates (AddHostEntry, RebuildHostCache), keepalive framing, and pipe-based IPC (PipeExists, ClosePipe, Disconnect, SendToServer). ^[strings.txt:458-470] No hardcoded C2 IP, domain, or port was recovered statically — these are builder-configured and encrypted in the RCData resource.

Persistence: Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is the standard NanoCore persistence vector. The RegistryKey type and SetValue method are present in metadata. ^[strings.txt:81-84] ^[strings.txt:536]

Plugin Architecture: The binary exposes the full NanoCore plugin-host surface: IClientApp, IClientData, IClientNetwork, IClientAppHost, IClientDataHost, IClientLoggingHost, IClientNetworkHost, IClientUIHost. ^[strings.txt:86-96] Plugin commands are typed (BaseCommand, FileCommand, PluginCommand). ^[strings.txt:331,345-347] Runtime logging (LogClientException, LogClientMessage) is also present. ^[strings.txt:902,905]

Cryptography: DESCryptoServiceProvider, MD5CryptoServiceProvider, RijndaelManaged, Rfc2898DeriveBytes, DeflateStream all referenced. ^[strings.txt:151-152,227-232] The RCData resource is likely encrypted with a builder-derived key (Rijndael or DES + PBKDF2). The MD5 hash capability (4 capa matches) may be used for packet integrity checks or config validation. ^[capa.txt:66]

Decompiled Behavior

Radare2 analysis completed at level 3, yielding 858 functions. The entry point is ClientLoaderForm.Main at 0x0040c480. ^[r2:entry0] CIL decompilation is degraded by ConfuserEx control-flow flattening — the pseudo-C shows only degenerate stack-pop comparisons and an ill-formed tail. No meaningful procedural decompilation was achievable without runtime tracing or ConfuserEx unpacker tooling.

The export table (effectively the .NET method table) contains hundreds of mangled symbols confirming the NanoCore interface hierarchy:

  • Client..ctor and ~50 Client.#=q…== methods — the main client logic. ^[r2:exports]
  • ClientLoaderForm..ctor, .Main, and two mangled methods — the WinForms bootstrap. ^[r2:exports]
  • #=qCQ9vY8i…#.SendToServer, #=qCQ9vY8i…#.AddHostEntry, #=qCQ9vY8i…#.RebuildHostCache — C2 networking surface. ^[r2:exports]
  • #=qixBu4j6…#.GetValue, .SetValue, .RemoveValue, .EntryExists, .GetEntries — registry access wrapper. ^[r2:exports]
  • #=qmLTtz8O…#.LogClientException, .LogClientMessage — runtime logging. ^[r2:exports]

The only native import is mscoree.dll!_CorExeMain — standard .NET bootstrap. ^[r2:imports]

C2 Infrastructure

No hardcoded C2 IP, domain, URL, mutex, or named pipe was recovered statically. NanoCore builder payloads store the C2 host list inside the encrypted RCData resource (0x22058, ~88 KB). The AddHostEntry and RebuildHostCache methods confirm the host list is mutable at runtime. ^[strings.txt:468-470]

IOC inference (static-only, low-confidence):

  • Network: Raw TCP outbound to builder-configured host/port.
  • Registry: Likely writes to HKCU\Software\Microsoft\Windows\CurrentVersion\Run with a value name masquerading as a legitimate application (e.g., NanoCore Client or randomised builder string).
  • File: Likely copies itself to %AppData%\Roaming\ or %TEMP% under a masquerade name.
  • Mutex: create or open mutex on Windows detected by capa (1 match). ^[capa.txt:86]

Interesting Tidbits

  1. Filename masquerade: moocow.exe is a blunt, non-social-engineering name — unlike siblings hotro.exe or purchase-order lures. This suggests either a test/build artefact or a downstream renamer. ^[triage.json:6]
  2. Builder-era consistency: The compile timestamp (22 Feb 2015 00:49:37 UTC) is within ~2.5 hours of sibling fe81691f (same day, 22:14:32 UTC? Actually let me check... no, fe81691f was also Feb 22 2015). The exact same minute (00:49:37) may indicate a batch build or the builder using a fixed timestamp. ^[rabin2-info.txt:11]
  3. No YARA specificity: The only YARA match is PE_File_Generic. No NanoCore-specific YARA rule fired, likely because the encrypted resource and mangled names defeat string-based signatures. ^[yara.txt:1]
  4. Full .NET 2.0 surface: Despite being a "modern" (2015) builder payload, it targets CLR v2.0.50727, ensuring compatibility down to Windows XP / Server 2003. ^[strings.txt:51]
  5. Resource entropy: The .rsrc section entropy of 7.998 (near theoretical max for 8-bit) confirms the payload is encrypted or compressed, not plaintext. ^[pefile.txt:132]
  6. Lambda bloat: Multiple _Lambda$__N compiler-generated delegates visible in exports, typical of VB.NET / C# async/event patterns, inflated by ConfuserEx mangling. ^[r2:exports]

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2013/2015 or SharpDevelop, targeting .NET Framework 2.0, AnyCPU or x86.

Build recipe (conceptual — the leaked builder is the reference implementation):

  1. Obtain the leaked NanoCore builder (v1.2.2.0 era).
  2. Configure C2 host/port in the builder GUI.
  3. Select plugin modules (file manager, remote desktop, keylogger, etc.).
  4. Build → outputs a single PE32 (~150–300 KB) with 3 sections.
  5. Obfuscate with ConfuserEx: enable name mangling, control-flow flattening, constant encryption, resource protection.

Verification: Run capa <output.exe> and compare to this sample's capa.txt. Expect hits on:

  • load .NET assembly
  • create TCP socket
  • send data / receive data
  • query or enumerate registry key/value
  • set registry value
  • hash data with MD5
  • create or open mutex on Windows

What you'll learn: How a commodity .NET RAT builder packages plugins, encrypts config, and obfuscates IL to evade static signatures. The builder's output is structurally identical across samples — only the RCData payload and GUID differ.

Deployable Signatures

YARA Rule

rule nanocore_confuserex_client {
    meta:
        description = "NanoCore RAT client with ConfuserEx obfuscation"
        author = "PacketPursuit"
        date = "2026-08-02"
        sha256 = "cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07"
        family = "nanocore"
    strings:
        $a1 = "NanoCore Client" ascii wide
        $a2 = "NanoCore Client.exe" ascii wide
        $a3 = "NanoCore.ClientPlugin" ascii wide
        $a4 = "IClientApp" ascii wide
        $a5 = "IClientNetwork" ascii wide
        $a6 = "IClientAppHost" ascii wide
        $a7 = "IClientDataHost" ascii wide
        $a8 = "IClientLoggingHost" ascii wide
        $a9 = "IClientNetworkHost" ascii wide
        $a10 = "IClientUIHost" ascii wide
        $b1 = "ClientPlugin" ascii wide
        $b2 = "BaseCommand" ascii wide
        $b3 = "FileCommand" ascii wide
        $b4 = "PluginCommand" ascii wide
        $b5 = "AddHostEntry" ascii wide
        $b6 = "RebuildHostCache" ascii wide
        $b7 = "SendToServer" ascii wide
        $b8 = "PipeExists" ascii wide
        $b9 = "ClosePipe" ascii wide
        $b10 = "LogClientException" ascii wide
        $b11 = "LogClientMessage" ascii wide
        $confuser = /#=q[A-Za-z0-9$+/=]{20,100}==/ ascii wide
        $clr = "v2.0.50727" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        (2 of ($a*) or ($a1 and $a2)) and
        (3 of ($b*) or ($confuser)) and
        $clr and
        filesize < 500KB
}

Behavioral Hunt Query (Sigma-like pseudo-YAML)

title: NanoCore Client Activity
description: Detects NanoCore RAT client runtime behavior
logsource:
  category: process_creation
  product: windows
detection:
  selection_registry:
    CommandLine|contains:
      - 'NanoCore'
      - 'ClientLoaderForm'
  selection_mutex:
    - 'Global\\NanoCore*'
    - 'Global\\ClientLoader*'
  selection_network:
    Initiated: true
    CommandLine|contains:
      - 'moocow.exe'
  selection_file:
    TargetFilename|endswith:
      - '\\NanoCore Client.exe'
      - '\\moocow.exe'
  condition: selection_registry or selection_mutex or selection_network or selection_file
falsepositives:
  - Unknown
level: high

Note: The above Sigma is heuristic. In practice, NanoCore C2 is raw TCP without easily signatured HTTP headers. Network detection should focus on the absence of HTTP/S framing combined with periodic small-packet keepalives to unusual ports.

IOC List

Type Value Confidence
SHA-256 cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07 High
SHA-1 09b25f67ebc5df9898e61eeeedfe2b78de2848ae High
MD5 98d1c2050e518dd67c652139fff1f461 High
ssdeep 6144:MLV6Bta6dtJmakIM5gBGmPDZ1ZgJB6QUWQ:MLV6BtpmkZBGmPDZ1gB65WQ High
Filename moocow.exe High (observed)
Internal name NanoCore Client.exe High
Compile time 2015-02-22 00:49:37 UTC High
.NET runtime v2.0.50727 High
Registry (inferred) HKCU\Software\Microsoft\Windows\CurrentVersion\Run Medium
Network (inferred) Raw TCP to builder-configured host/port Medium

Behavioral Fingerprint

This binary is a .NET Framework 2.0 PE32 GUI executable with a single native import (mscoree.dll!_CorExeMain), three sections, and an 88 KB high-entropy RCData resource. It carries the internal name NanoCore Client.exe and exposes the NanoCore plugin-host interface (IClientApp, IClientNetwork, etc.). The CIL is heavily obfuscated with ConfuserEx (#=q…== name mangling). At runtime it is expected to decrypt its RCData resource, reflectively load plugin assemblies, establish raw TCP C2 via SocketAsyncEventArgs, and persist via HKCU\...\Run registry value.

Detection Signatures

capa → ATT&CK Mapping

capa capability ATT&CK Technique
set registry value T1547.001
load .NET assembly T1620
query or enumerate registry key/value T1012
get OS version in .NET T1082
get session user name T1033
enumerate files in .NET T1083
create TCP socket T1095
send data / receive data T1095
hash data with MD5 —
create or open mutex on Windows —
create process in .NET —
terminate process —
suspend thread —

References

Provenance

  • File type: file v5.44
  • Strings: strings from binutils
  • FLOSS: Not run (CLI argument error — --no flag collision with sample path)
  • capa: Mandiant capa v7.0.0, static analysis, format dotnet, arch i386
  • binwalk: v2.3.2
  • pefile: Python pefile library
  • exiftool: v12.76
  • radare2: v5.9.8, analysis level 3, 858 functions, CIL backend
  • ssdeep: ssdeep v2.14.1
  • tlsh: TLSH v4.5.0
  • yara: YARA v4.5.2
  • CAPE: Skipped — no Windows guest available