typeanalysisfamilynanocoreconfidencehighcreated2026-08-14updated2026-08-14malware-familyratdotnetobfuscationc2persistencedefense-evasionmitre-attck
SHA-256: e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1

nanocore: e4774281 — UK housing-domain masquerade, builder v1.2.2.0, Feb 2015 batch sibling #16

Executive Summary

Sixteenth confirmed sibling in the leaked-era NanoCore v1.2.2.0 builder batch (22 Feb 2015 00:49:37 UTC). Masquerades as a UK housing-estate domain (aboddehousing.co.uk.exe). ConfuserEx-obfuscated VB.NET client with identical builder fingerprint to the prior fifteen — same timestamp, same version, same plugin-host interface surface. No hardcoded C2 recovered; host list encrypted inside the ~90 KB RCData resource. Static-only (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1 ^[file.txt]
  • File name: aboddehousing.co.uk.exe (UK housing-domain social-engineering masquerade) ^[metadata.json]
  • Size: 207,872 bytes (203 KB) ^[triage.json]
  • Type: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt]
  • Compile timestamp: 2015-02-22 00:49:37 UTC ^[exiftool.json]
  • Builder version: 1.2.2.0 (confirmed via AssemblyFileVersionAttribute in strings) ^[strings.txt:1626]
  • Unique GUID: 15e065f2-6a0c-418b-8192-dc66272ecfda (MyTemplate auto-generated project GUID) ^[strings.txt:1624]
  • Family: NanoCore RAT — high-confidence, matches the Feb 2015 batch cluster documented at nanocore.
  • Signing: Unsigned. No Authenticode. ^[pefile.txt:152-154]

How It Works

This is a standard NanoCore Client built with the leaked v1.2.2.0 builder. Runtime flow (inferred from static, consistent with cluster behaviour documented in nanocore):

  1. Entry: CLR loads via mscoree!_CorExeMain; only static import. ^[pefile.txt:199]
  2. Obfuscation: ConfuserEx mass name-mangling (#=q…==) on every class/method/field. ^[strings.txt:278-1793]
  3. Resource decryption: Reads encrypted payload from .rsrc RCData (size ~90 KB, near-identical to siblings). Decrypts with RijndaelManaged → DeflateStream pipeline. ^[strings.txt:150-152,232]
  4. Plugin host bootstrap: Instantiates IClientAppHost, IClientNetworkHost, IClientUIHost, IClientDataHost, IClientLoggingHost. ^[strings.txt:85-97]
  5. C2 connection: Raw TCP socket to builder-configured host/port list; supports dynamic host-cache updates via AddHostEntry / RebuildHostCache. ^[strings.txt:468,470] ^[capa.txt:62-66]
  6. Persistence: Likely registry Run key or self-copy to %AppData% / %TEMP% (cluster behaviour; not observed statically in this sample). ^[capa.txt:95-99]
  7. Discovery: Hostname, OS version, user name, file/directory enumeration, registry queries. ^[capa.txt:15-22]

Decompiled Behavior

Static-only; Ghidra decompilation not attempted because the binary is a heavily obfuscated .NET assembly with 858+ mangled CIL methods and no meaningful native-code entry point. r2 analysis confirms 858 functions but names are stripped/mangled. ^[rabin2-info.txt] The entire malicious logic lives inside obfuscated CIL; native disassembly yields only the CLR bootstrap thunk (_CorExeMain). For behavioural detail, see the capa.txt capability map and the cluster page nanocore.

C2 Infrastructure

  • Hardcoded C2: None recovered statically. Host list is encrypted inside the RCData resource and decrypted at runtime. ^[pefile.txt:203-239]
  • Protocol: Raw TCP sockets (builder-configured port). Keepalive framing inferred from cluster analysis. ^[capa.txt:62-66]
  • DNS: dnsapi.dll imported (likely used for DnsRecord resolution). ^[strings.txt:67,343]
  • Named pipes: ClientLoaderForm uses PipeExists, ClosePipe, SendToServer, Disconnect. IPC between plugin modules. ^[strings.txt:344,458-464]

Interesting Tidbits

  • Filename masquerades as a UK housing-estate domain (aboddehousing.co.uk.exe) — a common builder-era trick to appear legitimate in email attachments. ^[metadata.json]
  • Builder GUID 15e065f2-… is unique to this sample; every sibling in the batch gets a fresh auto-generated GUID, confirming point-and-click mass generation. ^[strings.txt:1624]
  • The .rsrc section entropy is 7.998 (near-maximum), indicating strong encryption of the embedded host-list / plugin package. ^[pefile.txt:132]
  • ClientSettings and BuilderSettings properties present in strings, confirming the builder writes its config into the compiled binary. ^[strings.txt:411-412,1401-1402]
  • No anti-VM or anti-debug strings observed; NanoCore relies on ConfuserEx obfuscation and runtime host-list decryption for evasion. ^[capa.txt]

How To Mess With It (Homelab Replication)

  1. Obtain the leaked NanoCore builder v1.2.2.0 (circulates on underground forums and malware research repositories).
  2. Target: .NET Framework 2.0/3.5/4.x client profile.
  3. Build: Enter C2 host/port in the builder GUI, click Build. Output is a ~200 KB PE32 with 3 sections.
  4. Obfuscation: Run through ConfuserEx (max preset) to reproduce the #=q…== name mangling.
  5. Verification: capa should hit: compiled to .NET platform, load .NET assembly, create TCP socket, resolve DNS, hash data with MD5, query registry, create process in .NET, create mutex, suspend thread, file-system read/write/delete/copy.
  6. What you learn: How a point-and-click RAT builder turns a configuration dialog into a self-contained, obfuscated C2 client with plugin architecture.

Deployable Signatures

YARA rule

rule nanocore_v1220_confuserex_batch {
    meta:
        description = "NanoCore v1.2.2.0 ConfuserEx-obfuscated client, Feb 2015 batch"
        author = "PacketPursuit"
        date = "2026-08-14"
        sha256 = "e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1"
    strings:
        $s1 = "NanoCore Client" ascii wide
        $s2 = "NanoCore Client.exe" ascii wide
        $s3 = "IClientAppHost" ascii wide
        $s4 = "IClientNetworkHost" ascii wide
        $s5 = "IClientUIHost" ascii wide
        $s6 = "AddHostEntry" ascii wide
        $s7 = "RebuildHostCache" ascii wide
        $s8 = "ClientSettings" ascii wide
        $s9 = "BuilderSettings" ascii wide
        $s10 = "1.2.2.0" ascii wide
        $s11 = "MyTemplate" ascii wide
        $s12 = "SendToServer" ascii wide
        $s13 = "PipeExists" ascii wide
        $mscoree = "mscoree.dll" ascii wide
        $cor = "_CorExeMain" ascii wide
    condition:
        uint16(0) == 0x5a4d and
        $mscoree and $cor and
        6 of ($s*) and
        filesize < 300KB and
        pe.number_of_sections == 3
}

Sigma rule

title: NanoCore Client Launch and Network Activity
logsource:
    product: windows
detection:
    selection_img:
        - Image|endswith: '\\NanoCore Client.exe'
        - OriginalFileName: 'NanoCore Client.exe'
    selection_network:
        Initiated: 'true'
        DestinationPort|contains:
            - '4444'
            - '5555'
            - '1604'
            - '1605'
    selection_mutex:
        - ObjectName|contains: 'NanoCore'
    condition: 1 of selection_*
falsepositives:
    - Unlikely; NanoCore Client is not a legitimate program.
level: high

IOC list

Indicator Type Value
SHA-256 Hash e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1
File name Filename aboddehousing.co.uk.exe
Builder GUID Metadata 15e065f2-6a0c-418b-8192-dc66272ecfda
Builder version Metadata 1.2.2.0
PE compile time Timestamp 2015-02-22 00:49:37 UTC
Import API mscoree.dll!_CorExeMain (sole static import)
Resource Section .rsrc RCData ~90 KB encrypted payload
Mutex Behaviour CreateMutex (name runtime-generated)
Registry Behaviour HKCU\Software\Microsoft\Windows\CurrentVersion\Run (cluster behaviour)
Network Protocol Raw TCP socket C2, DNS resolution via dnsapi.dll

Behavioural fingerprint

This binary is a .NET Framework PE32 with exactly three sections, a single mscoree!_CorExeMain import, and high-entropy .rsrc. It loads System.Net.Sockets, System.Security.Cryptography, and System.IO.Compression at runtime. Within 5–30 seconds of process start it creates a TCP socket, resolves a DNS name, and attempts to connect to a hardcoded host list decrypted from its RCData resource. It maintains a persistent TCP session with keepalive framing, spawns threads for plugin modules, and uses named pipes for inter-module communication. File-system activity includes copying itself to %AppData% or %TEMP% and writing temp files. Registry queries enumerate Run keys and system information.

Detection Signatures

MITRE ATT&CK mapping from capa (static):

  • T1112 — Modify Registry ^[capa.txt:15]
  • T1620 — Reflective Code Loading ^[capa.txt:16]
  • T1087 — Account Discovery ^[capa.txt:17]
  • T1083 — File and Directory Discovery ^[capa.txt:18]
  • T1012 — Query Registry ^[capa.txt:19]
  • T1082 — System Information Discovery ^[capa.txt:20]
  • T1033 — System Owner/User Discovery ^[capa.txt:21]

MBC behaviours from capa:

  • C2 Communication::Send Data / Receive Data ^[capa.txt:31-32]
  • DNS Communication::Resolve ^[capa.txt:33]
  • Socket Communication::Create TCP Socket / Send Data / Receive Data ^[capa.txt:34-36]
  • Cryptographic Hash::MD5 ^[capa.txt:37]
  • File System::Copy / Create / Delete / Read / Write ^[capa.txt:43-48,51-52]
  • Process::Create Mutex / Create Process / Suspend Thread / Terminate Process ^[capa.txt:54-56]
  • Registry::Set / Query / Delete ^[capa.txt:51-53,96-97]

References

  • Cluster analysis: nanocore entity page
  • Technique: confuserex-obfuscation
  • CAPE: skipped — no Windows guest available
  • OpenCTI labels: nanocore, rat, exe, malware-bazaar

Provenance

Analysis derived from static artefacts in raw/analyses/e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1/: file.txt, exiftool.json, pefile.txt, strings.txt, capa.txt, rabin2-info.txt, metadata.json, triage.json. Tools: file, exiftool, pefile.py, strings, flare-capa v7, radare2, yara. CAPE detonation skipped (no Windows guest). No Ghidra decompilation performed (obfuscated CIL, no native-code entry point of interest).