e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1nanocore: e4774281 — UK housing-domain masquerade, builder v1.2.2.0, Feb 2015 batch sibling #16
Executive Summary
Sixteenth confirmed sibling in the leaked-era NanoCore v1.2.2.0 builder batch (22 Feb 2015 00:49:37 UTC). Masquerades as a UK housing-estate domain (aboddehousing.co.uk.exe). ConfuserEx-obfuscated VB.NET client with identical builder fingerprint to the prior fifteen — same timestamp, same version, same plugin-host interface surface. No hardcoded C2 recovered; host list encrypted inside the ~90 KB RCData resource. Static-only (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1^[file.txt] - File name:
aboddehousing.co.uk.exe(UK housing-domain social-engineering masquerade) ^[metadata.json] - Size: 207,872 bytes (203 KB) ^[triage.json]
- Type: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt]
- Compile timestamp: 2015-02-22 00:49:37 UTC ^[exiftool.json]
- Builder version:
1.2.2.0(confirmed viaAssemblyFileVersionAttributein strings) ^[strings.txt:1626] - Unique GUID:
15e065f2-6a0c-418b-8192-dc66272ecfda(MyTemplate auto-generated project GUID) ^[strings.txt:1624] - Family: NanoCore RAT — high-confidence, matches the Feb 2015 batch cluster documented at nanocore.
- Signing: Unsigned. No Authenticode. ^[pefile.txt:152-154]
How It Works
This is a standard NanoCore Client built with the leaked v1.2.2.0 builder. Runtime flow (inferred from static, consistent with cluster behaviour documented in nanocore):
- Entry: CLR loads via
mscoree!_CorExeMain; only static import. ^[pefile.txt:199] - Obfuscation: ConfuserEx mass name-mangling (
#=q…==) on every class/method/field. ^[strings.txt:278-1793] - Resource decryption: Reads encrypted payload from
.rsrcRCData (size ~90 KB, near-identical to siblings). Decrypts withRijndaelManaged→DeflateStreampipeline. ^[strings.txt:150-152,232] - Plugin host bootstrap: Instantiates
IClientAppHost,IClientNetworkHost,IClientUIHost,IClientDataHost,IClientLoggingHost. ^[strings.txt:85-97] - C2 connection: Raw TCP socket to builder-configured host/port list; supports dynamic host-cache updates via
AddHostEntry/RebuildHostCache. ^[strings.txt:468,470] ^[capa.txt:62-66] - Persistence: Likely registry Run key or self-copy to
%AppData%/%TEMP%(cluster behaviour; not observed statically in this sample). ^[capa.txt:95-99] - Discovery: Hostname, OS version, user name, file/directory enumeration, registry queries. ^[capa.txt:15-22]
Decompiled Behavior
Static-only; Ghidra decompilation not attempted because the binary is a heavily obfuscated .NET assembly with 858+ mangled CIL methods and no meaningful native-code entry point. r2 analysis confirms 858 functions but names are stripped/mangled. ^[rabin2-info.txt] The entire malicious logic lives inside obfuscated CIL; native disassembly yields only the CLR bootstrap thunk (_CorExeMain). For behavioural detail, see the capa.txt capability map and the cluster page nanocore.
C2 Infrastructure
- Hardcoded C2: None recovered statically. Host list is encrypted inside the RCData resource and decrypted at runtime. ^[pefile.txt:203-239]
- Protocol: Raw TCP sockets (builder-configured port). Keepalive framing inferred from cluster analysis. ^[capa.txt:62-66]
- DNS:
dnsapi.dllimported (likely used forDnsRecordresolution). ^[strings.txt:67,343] - Named pipes:
ClientLoaderFormusesPipeExists,ClosePipe,SendToServer,Disconnect. IPC between plugin modules. ^[strings.txt:344,458-464]
Interesting Tidbits
- Filename masquerades as a UK housing-estate domain (
aboddehousing.co.uk.exe) — a common builder-era trick to appear legitimate in email attachments. ^[metadata.json] - Builder GUID
15e065f2-…is unique to this sample; every sibling in the batch gets a fresh auto-generated GUID, confirming point-and-click mass generation. ^[strings.txt:1624] - The
.rsrcsection entropy is 7.998 (near-maximum), indicating strong encryption of the embedded host-list / plugin package. ^[pefile.txt:132] ClientSettingsandBuilderSettingsproperties present in strings, confirming the builder writes its config into the compiled binary. ^[strings.txt:411-412,1401-1402]- No anti-VM or anti-debug strings observed; NanoCore relies on ConfuserEx obfuscation and runtime host-list decryption for evasion. ^[capa.txt]
How To Mess With It (Homelab Replication)
- Obtain the leaked NanoCore builder v1.2.2.0 (circulates on underground forums and malware research repositories).
- Target: .NET Framework 2.0/3.5/4.x client profile.
- Build: Enter C2 host/port in the builder GUI, click Build. Output is a ~200 KB PE32 with 3 sections.
- Obfuscation: Run through ConfuserEx (max preset) to reproduce the
#=q…==name mangling. - Verification:
capashould hit:compiled to .NET platform,load .NET assembly,create TCP socket,resolve DNS,hash data with MD5,query registry,create process in .NET,create mutex,suspend thread,file-system read/write/delete/copy. - What you learn: How a point-and-click RAT builder turns a configuration dialog into a self-contained, obfuscated C2 client with plugin architecture.
Deployable Signatures
YARA rule
rule nanocore_v1220_confuserex_batch {
meta:
description = "NanoCore v1.2.2.0 ConfuserEx-obfuscated client, Feb 2015 batch"
author = "PacketPursuit"
date = "2026-08-14"
sha256 = "e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1"
strings:
$s1 = "NanoCore Client" ascii wide
$s2 = "NanoCore Client.exe" ascii wide
$s3 = "IClientAppHost" ascii wide
$s4 = "IClientNetworkHost" ascii wide
$s5 = "IClientUIHost" ascii wide
$s6 = "AddHostEntry" ascii wide
$s7 = "RebuildHostCache" ascii wide
$s8 = "ClientSettings" ascii wide
$s9 = "BuilderSettings" ascii wide
$s10 = "1.2.2.0" ascii wide
$s11 = "MyTemplate" ascii wide
$s12 = "SendToServer" ascii wide
$s13 = "PipeExists" ascii wide
$mscoree = "mscoree.dll" ascii wide
$cor = "_CorExeMain" ascii wide
condition:
uint16(0) == 0x5a4d and
$mscoree and $cor and
6 of ($s*) and
filesize < 300KB and
pe.number_of_sections == 3
}
Sigma rule
title: NanoCore Client Launch and Network Activity
logsource:
product: windows
detection:
selection_img:
- Image|endswith: '\\NanoCore Client.exe'
- OriginalFileName: 'NanoCore Client.exe'
selection_network:
Initiated: 'true'
DestinationPort|contains:
- '4444'
- '5555'
- '1604'
- '1605'
selection_mutex:
- ObjectName|contains: 'NanoCore'
condition: 1 of selection_*
falsepositives:
- Unlikely; NanoCore Client is not a legitimate program.
level: high
IOC list
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | Hash | e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1 |
| File name | Filename | aboddehousing.co.uk.exe |
| Builder GUID | Metadata | 15e065f2-6a0c-418b-8192-dc66272ecfda |
| Builder version | Metadata | 1.2.2.0 |
| PE compile time | Timestamp | 2015-02-22 00:49:37 UTC |
| Import | API | mscoree.dll!_CorExeMain (sole static import) |
| Resource | Section | .rsrc RCData ~90 KB encrypted payload |
| Mutex | Behaviour | CreateMutex (name runtime-generated) |
| Registry | Behaviour | HKCU\Software\Microsoft\Windows\CurrentVersion\Run (cluster behaviour) |
| Network | Protocol | Raw TCP socket C2, DNS resolution via dnsapi.dll |
Behavioural fingerprint
This binary is a .NET Framework PE32 with exactly three sections, a single mscoree!_CorExeMain import, and high-entropy .rsrc. It loads System.Net.Sockets, System.Security.Cryptography, and System.IO.Compression at runtime. Within 5–30 seconds of process start it creates a TCP socket, resolves a DNS name, and attempts to connect to a hardcoded host list decrypted from its RCData resource. It maintains a persistent TCP session with keepalive framing, spawns threads for plugin modules, and uses named pipes for inter-module communication. File-system activity includes copying itself to %AppData% or %TEMP% and writing temp files. Registry queries enumerate Run keys and system information.
Detection Signatures
MITRE ATT&CK mapping from capa (static):
- T1112 — Modify Registry ^[capa.txt:15]
- T1620 — Reflective Code Loading ^[capa.txt:16]
- T1087 — Account Discovery ^[capa.txt:17]
- T1083 — File and Directory Discovery ^[capa.txt:18]
- T1012 — Query Registry ^[capa.txt:19]
- T1082 — System Information Discovery ^[capa.txt:20]
- T1033 — System Owner/User Discovery ^[capa.txt:21]
MBC behaviours from capa:
- C2 Communication::Send Data / Receive Data ^[capa.txt:31-32]
- DNS Communication::Resolve ^[capa.txt:33]
- Socket Communication::Create TCP Socket / Send Data / Receive Data ^[capa.txt:34-36]
- Cryptographic Hash::MD5 ^[capa.txt:37]
- File System::Copy / Create / Delete / Read / Write ^[capa.txt:43-48,51-52]
- Process::Create Mutex / Create Process / Suspend Thread / Terminate Process ^[capa.txt:54-56]
- Registry::Set / Query / Delete ^[capa.txt:51-53,96-97]
References
- Cluster analysis: nanocore entity page
- Technique: confuserex-obfuscation
- CAPE: skipped — no Windows guest available
- OpenCTI labels:
nanocore,rat,exe,malware-bazaar
Provenance
Analysis derived from static artefacts in raw/analyses/e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1/: file.txt, exiftool.json, pefile.txt, strings.txt, capa.txt, rabin2-info.txt, metadata.json, triage.json. Tools: file, exiftool, pefile.py, strings, flare-capa v7, radare2, yara. CAPE detonation skipped (no Windows guest). No Ghidra decompilation performed (obfuscated CIL, no native-code entry point of interest).