e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556nanocore: e48f1c56 — Confirmed twin of fe81691f, unique GUID f14daca4, Backdoor.exe masquerade
Executive Summary
A 203 KB PE32 .NET assembly (Backdoor.exe) that is a byte-identical twin of the previously analysed NanoCore RAT client fe81691f (okfun.exe), apart from the per-client encrypted .rsrc payload and the VB.NET MyTemplate GUID. Same Feb 22 2015 build timestamp, same ConfuserEx obfuscation layer (1,039 mangled #=q… identifiers), same builder version 1.2.2.0. Static-only analysis — no CAPE Windows guest available. The only material delta is the filename (Backdoor.exe, blunt honesty) and the individualized GUID (f14daca4-f2c5-4bf9-b197-8630941b582c). ^[file.txt] ^[strings.txt:1624]
What It Is
| Property | Value | Provenance |
|---|---|---|
| SHA-256 | e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556 |
metadata.json |
| File name | Backdoor.exe |
metadata.json |
| Size | 207,872 bytes (203 KB) | metadata.json |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | file.txt |
| Timestamp | Sun Feb 22 00:49:37 2015 UTC | pefile.txt |
| Linker | .NET Framework v2.0.50727 (CLR 2.0) | strings.txt:51 |
| Language | Visual Basic .NET (My.Application framework) | strings.txt:1613, strings.txt:1618 |
| RAT version | NanoCore Client 1.2.2.0 | strings.txt:1626 |
| Obfuscator | ConfuserEx (1,039 #=q… mangled tokens) |
strings.txt:278+ |
| Signed | No (stripped, unsigned) | pefile.txt:153-154 |
| MyTemplate GUID | f14daca4-f2c5-4bf9-b197-8630941b582c |
strings.txt:1624 |
This sample is a confirmed sibling in the NanoCore Feb 2015 batch. For shared build-stack, plugin architecture, C2 protocol, and persistence behaviour, see the cluster analysis at nanocore. ^[entities/nanocore.md]
How It Works
Cluster Relationship
diff against fe81691f reveals only two meaningful deltas:
- MyTemplate GUID (line 1624):
f14daca4-…vsb4de0bbe-…— a per-client VB.NET auto-generated GUID used by the My Application Framework. ^[strings.txt:1624] ^[sample fe81691f/strings.txt:1624] - Encrypted
.rsrcpayload: Entropy and section hashes differ (MD57c04ea8c…vs534b0158…), confirming the ConfuserEx-encrypted resource / builder config is unique per client. ^[pefile.txt:92-96] ^[sample fe81691f/pefile.txt:92-96]
All other static artefacts — file size, capa fingerprint, import table (single mscoree.dll._CorExeMain), strings layout, section names, entry point — are identical. ^[pefile.txt:198-199] ^[capa.txt]
Distinguishing Trait
The filename Backdoor.exe is unusually blunt for this cluster; previous siblings used okfun.exe, hotro.exe, moocow.exe, or generic masquerade names. This suggests a builder user who did not bother with social-engineering renaming. ^[metadata.json] ^[sample fe81691f/metadata.json]
Decompiled Behavior
Identical to fe81691f. Radare2 CIL engine identifies the same method surface:
ClientLoaderForm.Main— WinForms bootstrap (hidden form, no taskbar). ^[r2:method.ClientLoaderForm.Main]Client..ctor— singleton wiringIClientAppto network layer. ^[r2:sym.Client..ctor]LogClientException/LogClientMessage— centralized logging forwarded to C2. ^[strings.txt:902-905]
ConfuserEx control-flow flattening and delegate trampolines dominate; manual decompilation is impractical without NoFusicator or de4dot pipelines. ^[capa.txt:15-22]
C2 Infrastructure
No static C2 recovered. The builder-generated ClientSettings blob is encrypted inside the .rsrc ZIP and decrypted at runtime. ^[strings.txt:1400-1402]
Protocol: raw TCP sockets (not HTTP/HTTPS), keepalive framing, mutable host cache via AddHostEntry / RebuildHostCache. ^[strings.txt:1105-1116] ^[capa.txt:62-66]
Interesting Tidbits
- Blunt filename:
Backdoor.exeis the most honest name in this cluster; no social-engineering veneer. ^[metadata.json] - Same builder batch: Identical timestamp (Feb 22 2015 00:49:37 UTC), same version
1.2.2.0, same 1,039 ConfuserEx mangled names. Confirms mass builder-era distribution. ^[strings.txt:1626] ^[rabin2-info.txt:11] - Only YARA hit:
PE_File_Generic— no open-source NanoCore rule triggered on this ConfuserEx layer. ^[yara.txt] - .rsrc entropy 7.998: High-entropy encrypted payload confirms per-client resource individualization even when the rest of the binary is a template twin. ^[pefile.txt:132]
- No dynamic analysis: CAPE skipped (no Windows guest). All runtime/C2 claims are inferred from static imports and known NanoCore builder behaviour. ^[dynamic-analysis.md]
How To Mess With It (Homelab Replication)
See the full replication recipe in the nanocore cluster page and the fe81691f report. The delta here is trivial:
- Build the same VB.NET WinForms stub as
fe81691f. - Change the
MyTemplateGUID inMy Project > Assembly Information(or let Visual Studio auto-generate a new one). - Run the NanoCore builder to generate a fresh
ClientSettingsblob with a new C2 host. - Pass through ConfuserEx with identical settings (name obfuscation, constant encryption, control-flow flattening, resource encryption).
- Verify:
capafingerprint should match this sample exactly — same ATT&CK technique mapping, same capability namespace hits. ^[capa.txt]
What you learn: Even commodity RAT builders produce twins that differ only in GUID and encrypted payload. Static clustering must weight high-signal artefacts (GUID, payload hashes) over low-signal shared strings.
Deployable Signatures
YARA — NanoCore ConfuserEx Twin Detection
rule nanocore_confuserex_vbnet_twin
{
meta:
description = "NanoCore RAT client obfuscated with ConfuserEx, VB.NET build"
author = "triage-auto"
date = "2026-08-02"
sha256 = "e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556"
strings:
$nano1 = "NanoCore Client" ascii wide
$nano2 = "NanoCore.ClientPlugin" ascii wide
$nano3 = "IClientApp" ascii wide
$nano4 = "IClientNetwork" ascii wide
$nano5 = "ClientLoaderForm" ascii wide
$nano6 = "SendToServer" ascii wide
$nano7 = "AddHostEntry" ascii wide
$nano8 = "PluginUninstalling" ascii wide
$conf1 = /#=q[A-Za-z0-9_$]{20,}==/ // ConfuserEx mangled name
$conf2 = /#=q[A-Za-z0-9_$]{20,}=.*=/ // ConfuserEx extended form
$vb1 = "MyTemplate" ascii wide
$vb2 = "My.MyProject.Forms" ascii wide
$ver = "1.2.2.0" ascii wide
condition:
uint16(0) == 0x5A4D
and pe.number_of_sections == 3
and any of ($nano*)
and any of ($conf*)
and any of ($vb*)
and $ver
and filesize < 500KB
}
Syntactically tested by eye; deploy to sandbox before production.
Sigma — NanoCore Process Launch Hunt
title: NanoCore RAT Client Loader Execution
description: Detects NanoCore VB.NET client process based on module/interface strings and pipe creation.
logsource:
category: process_creation
product: windows
detection:
selection_strings:
CommandLine|contains|all:
- 'NanoCore'
- 'ClientLoaderForm'
selection_pipes:
CommandLine|contains:
- 'PipeCreated'
- 'PipeExists'
- 'CreatePipe'
selection_vb:
ImageLoaded|contains:
- 'Microsoft.VisualBasic'
- 'MyTemplate'
selection_mscoree:
CommandLine|endswith:
- '.exe'
condition: 1 of selection_strings or (selection_pipes and selection_vb)
falsepositives:
- Unknown
level: high
tags:
- attack.execution
- attack.t1059
- attack.command_and_control
- attack.t1071
IOC List
| Category | Indicator | Context |
|---|---|---|
| Hash | e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556 |
SHA-256 |
| Hash | 7fdd406f858259f82b9692d8858e9446 |
MD5 |
| Hash | 6a66d8b5a0138b0476b572f5f99827352cc38096 |
SHA-1 |
| Filename | Backdoor.exe |
Original name (blunt, no masquerade) |
| GUID | f14daca4-f2c5-4bf9-b197-8630941b582c |
VB.NET MyTemplate GUID |
| Registry | HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run |
Persistence inferred |
| File | %TEMP%\\*.tmp, %APPDATA%\\* |
Staging inferred |
| Pipe | \\.\\pipe\\* |
IPC bridge (CreatePipe, PipeExists) |
| Network | Raw TCP outbound (no static IP) | C2 host resolved via DNS / builder config |
| Mutex | Unknown — runtime-generated | — |
Behavioral Fingerprint
This binary is a .NET PE32 GUI assembly with a single mscoree.dll import. At startup it instantiates a hidden VB.NET WinForms client loader, initializes TCP socket objects, and maintains an internal C2 host cache. It creates file-system directories and copies itself, interacts with the registry for persistence, and uses anonymous/named pipes for internal plugin IPC. Network traffic is raw TCP with keepalive framing. The ConfuserEx obfuscation (1,039 mangled #=q… identifiers) blocks naive string extraction and decompilation. This sample is a confirmed twin of fe81691f; only the MyTemplate GUID and encrypted .rsrc payload differ.
Detection Signatures (capa → ATT&CK)
capa static analysis mapped capabilities to ATT&CK: ^[capa.txt]
| capa Capability | ATT&CK Technique |
|---|---|
| modify registry | T1112 |
| reflective code loading | T1620 |
| account discovery | T1087 |
| file and directory discovery | T1083 |
| query registry | T1012 |
| system information discovery | T1082 |
| system owner/user discovery | T1033 |
| C2 communication (send/receive) | T1071 |
| DNS resolution | T1071.004 |
| create TCP socket | T1071 |
| MD5 hashing | — (crypto utility) |
| generate random numbers | — (utility) |
| copy file / create directory / delete file | T1070 |
| create process | T1106 |
| create mutex | — (single instance) |
| enumerate registry | T1012 |
| get session integrity level | T1033 |
| suspend thread | T1055 |
Dynamic execution would likely surface additional TTPs such as T1547.001 (Registry Run Keys) depending on builder configuration.
References
- SHA-256:
e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556 - Wiki entity: nanocore
- Wiki technique: confuserex-obfuscation
- Wiki procedure: registry-run-persistence
- Sibling analysis: /intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html
- OpenCTI labels:
nanocore,rat,malware-bazaar^[metadata.json] - Sample source: abuse.ch / MalwareBazaar (via OpenCTI
urlhaus-recent-payloadsconnector)
Provenance
- Report built from static artefacts generated by the triage pipeline on 2026-05-26.
- Tools:
file,strings,floss(failed — invalid args),capav5 (static, dotnet),binwalk,radare2(CIL analysis),python3(manual entropy + offset extraction),pefile. - No CAPE dynamic analysis: Windows guest unavailable at time of triage. All runtime/C2 claims are inferred from static imports, capa capability map, and known NanoCore builder behaviour.
- Sibling confirmation via
diffofstrings.txtandpefile.txtagainstfe81691f; only GUID (line 1624) and.rsrcsection hashes differ.