typeanalysisfamilynanocoreconfidencehighcreated2026-08-02updated2026-08-02dotnetmalware-familyratc2obfuscationpersistence
SHA-256: e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556

nanocore: e48f1c56 — Confirmed twin of fe81691f, unique GUID f14daca4, Backdoor.exe masquerade

Executive Summary

A 203 KB PE32 .NET assembly (Backdoor.exe) that is a byte-identical twin of the previously analysed NanoCore RAT client fe81691f (okfun.exe), apart from the per-client encrypted .rsrc payload and the VB.NET MyTemplate GUID. Same Feb 22 2015 build timestamp, same ConfuserEx obfuscation layer (1,039 mangled #=q… identifiers), same builder version 1.2.2.0. Static-only analysis — no CAPE Windows guest available. The only material delta is the filename (Backdoor.exe, blunt honesty) and the individualized GUID (f14daca4-f2c5-4bf9-b197-8630941b582c). ^[file.txt] ^[strings.txt:1624]

What It Is

Property Value Provenance
SHA-256 e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556 metadata.json
File name Backdoor.exe metadata.json
Size 207,872 bytes (203 KB) metadata.json
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections file.txt
Timestamp Sun Feb 22 00:49:37 2015 UTC pefile.txt
Linker .NET Framework v2.0.50727 (CLR 2.0) strings.txt:51
Language Visual Basic .NET (My.Application framework) strings.txt:1613, strings.txt:1618
RAT version NanoCore Client 1.2.2.0 strings.txt:1626
Obfuscator ConfuserEx (1,039 #=q… mangled tokens) strings.txt:278+
Signed No (stripped, unsigned) pefile.txt:153-154
MyTemplate GUID f14daca4-f2c5-4bf9-b197-8630941b582c strings.txt:1624

This sample is a confirmed sibling in the NanoCore Feb 2015 batch. For shared build-stack, plugin architecture, C2 protocol, and persistence behaviour, see the cluster analysis at nanocore. ^[entities/nanocore.md]

How It Works

Cluster Relationship

diff against fe81691f reveals only two meaningful deltas:

  1. MyTemplate GUID (line 1624): f14daca4-… vs b4de0bbe-… — a per-client VB.NET auto-generated GUID used by the My Application Framework. ^[strings.txt:1624] ^[sample fe81691f/strings.txt:1624]
  2. Encrypted .rsrc payload: Entropy and section hashes differ (MD5 7c04ea8c… vs 534b0158…), confirming the ConfuserEx-encrypted resource / builder config is unique per client. ^[pefile.txt:92-96] ^[sample fe81691f/pefile.txt:92-96]

All other static artefacts — file size, capa fingerprint, import table (single mscoree.dll._CorExeMain), strings layout, section names, entry point — are identical. ^[pefile.txt:198-199] ^[capa.txt]

Distinguishing Trait

The filename Backdoor.exe is unusually blunt for this cluster; previous siblings used okfun.exe, hotro.exe, moocow.exe, or generic masquerade names. This suggests a builder user who did not bother with social-engineering renaming. ^[metadata.json] ^[sample fe81691f/metadata.json]

Decompiled Behavior

Identical to fe81691f. Radare2 CIL engine identifies the same method surface:

  • ClientLoaderForm.Main — WinForms bootstrap (hidden form, no taskbar). ^[r2:method.ClientLoaderForm.Main]
  • Client..ctor — singleton wiring IClientApp to network layer. ^[r2:sym.Client..ctor]
  • LogClientException / LogClientMessage — centralized logging forwarded to C2. ^[strings.txt:902-905]

ConfuserEx control-flow flattening and delegate trampolines dominate; manual decompilation is impractical without NoFusicator or de4dot pipelines. ^[capa.txt:15-22]

C2 Infrastructure

No static C2 recovered. The builder-generated ClientSettings blob is encrypted inside the .rsrc ZIP and decrypted at runtime. ^[strings.txt:1400-1402]

Protocol: raw TCP sockets (not HTTP/HTTPS), keepalive framing, mutable host cache via AddHostEntry / RebuildHostCache. ^[strings.txt:1105-1116] ^[capa.txt:62-66]

Interesting Tidbits

  1. Blunt filename: Backdoor.exe is the most honest name in this cluster; no social-engineering veneer. ^[metadata.json]
  2. Same builder batch: Identical timestamp (Feb 22 2015 00:49:37 UTC), same version 1.2.2.0, same 1,039 ConfuserEx mangled names. Confirms mass builder-era distribution. ^[strings.txt:1626] ^[rabin2-info.txt:11]
  3. Only YARA hit: PE_File_Generic — no open-source NanoCore rule triggered on this ConfuserEx layer. ^[yara.txt]
  4. .rsrc entropy 7.998: High-entropy encrypted payload confirms per-client resource individualization even when the rest of the binary is a template twin. ^[pefile.txt:132]
  5. No dynamic analysis: CAPE skipped (no Windows guest). All runtime/C2 claims are inferred from static imports and known NanoCore builder behaviour. ^[dynamic-analysis.md]

How To Mess With It (Homelab Replication)

See the full replication recipe in the nanocore cluster page and the fe81691f report. The delta here is trivial:

  1. Build the same VB.NET WinForms stub as fe81691f.
  2. Change the MyTemplate GUID in My Project > Assembly Information (or let Visual Studio auto-generate a new one).
  3. Run the NanoCore builder to generate a fresh ClientSettings blob with a new C2 host.
  4. Pass through ConfuserEx with identical settings (name obfuscation, constant encryption, control-flow flattening, resource encryption).
  5. Verify: capa fingerprint should match this sample exactly — same ATT&CK technique mapping, same capability namespace hits. ^[capa.txt]

What you learn: Even commodity RAT builders produce twins that differ only in GUID and encrypted payload. Static clustering must weight high-signal artefacts (GUID, payload hashes) over low-signal shared strings.

Deployable Signatures

YARA — NanoCore ConfuserEx Twin Detection

rule nanocore_confuserex_vbnet_twin
{
    meta:
        description = "NanoCore RAT client obfuscated with ConfuserEx, VB.NET build"
        author      = "triage-auto"
        date        = "2026-08-02"
        sha256      = "e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556"
    strings:
        $nano1 = "NanoCore Client" ascii wide
        $nano2 = "NanoCore.ClientPlugin" ascii wide
        $nano3 = "IClientApp" ascii wide
        $nano4 = "IClientNetwork" ascii wide
        $nano5 = "ClientLoaderForm" ascii wide
        $nano6 = "SendToServer" ascii wide
        $nano7 = "AddHostEntry" ascii wide
        $nano8 = "PluginUninstalling" ascii wide
        $conf1 = /#=q[A-Za-z0-9_$]{20,}==/      // ConfuserEx mangled name
        $conf2 = /#=q[A-Za-z0-9_$]{20,}=.*=/    // ConfuserEx extended form
        $vb1   = "MyTemplate" ascii wide
        $vb2   = "My.MyProject.Forms" ascii wide
        $ver   = "1.2.2.0" ascii wide
    condition:
        uint16(0) == 0x5A4D
        and pe.number_of_sections == 3
        and any of ($nano*)
        and any of ($conf*)
        and any of ($vb*)
        and $ver
        and filesize < 500KB
}

Syntactically tested by eye; deploy to sandbox before production.

Sigma — NanoCore Process Launch Hunt

title: NanoCore RAT Client Loader Execution
description: Detects NanoCore VB.NET client process based on module/interface strings and pipe creation.
logsource:
    category: process_creation
    product: windows
detection:
    selection_strings:
        CommandLine|contains|all:
            - 'NanoCore'
            - 'ClientLoaderForm'
    selection_pipes:
        CommandLine|contains:
            - 'PipeCreated'
            - 'PipeExists'
            - 'CreatePipe'
    selection_vb:
        ImageLoaded|contains:
            - 'Microsoft.VisualBasic'
            - 'MyTemplate'
    selection_mscoree:
        CommandLine|endswith:
            - '.exe'
    condition: 1 of selection_strings or (selection_pipes and selection_vb)
falsepositives:
    - Unknown
level: high
tags:
    - attack.execution
    - attack.t1059
    - attack.command_and_control
    - attack.t1071

IOC List

Category Indicator Context
Hash e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556 SHA-256
Hash 7fdd406f858259f82b9692d8858e9446 MD5
Hash 6a66d8b5a0138b0476b572f5f99827352cc38096 SHA-1
Filename Backdoor.exe Original name (blunt, no masquerade)
GUID f14daca4-f2c5-4bf9-b197-8630941b582c VB.NET MyTemplate GUID
Registry HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run Persistence inferred
File %TEMP%\\*.tmp, %APPDATA%\\* Staging inferred
Pipe \\.\\pipe\\* IPC bridge (CreatePipe, PipeExists)
Network Raw TCP outbound (no static IP) C2 host resolved via DNS / builder config
Mutex Unknown — runtime-generated —

Behavioral Fingerprint

This binary is a .NET PE32 GUI assembly with a single mscoree.dll import. At startup it instantiates a hidden VB.NET WinForms client loader, initializes TCP socket objects, and maintains an internal C2 host cache. It creates file-system directories and copies itself, interacts with the registry for persistence, and uses anonymous/named pipes for internal plugin IPC. Network traffic is raw TCP with keepalive framing. The ConfuserEx obfuscation (1,039 mangled #=q… identifiers) blocks naive string extraction and decompilation. This sample is a confirmed twin of fe81691f; only the MyTemplate GUID and encrypted .rsrc payload differ.

Detection Signatures (capa → ATT&CK)

capa static analysis mapped capabilities to ATT&CK: ^[capa.txt]

capa Capability ATT&CK Technique
modify registry T1112
reflective code loading T1620
account discovery T1087
file and directory discovery T1083
query registry T1012
system information discovery T1082
system owner/user discovery T1033
C2 communication (send/receive) T1071
DNS resolution T1071.004
create TCP socket T1071
MD5 hashing — (crypto utility)
generate random numbers — (utility)
copy file / create directory / delete file T1070
create process T1106
create mutex — (single instance)
enumerate registry T1012
get session integrity level T1033
suspend thread T1055

Dynamic execution would likely surface additional TTPs such as T1547.001 (Registry Run Keys) depending on builder configuration.

References

  • SHA-256: e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556
  • Wiki entity: nanocore
  • Wiki technique: confuserex-obfuscation
  • Wiki procedure: registry-run-persistence
  • Sibling analysis: /intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html
  • OpenCTI labels: nanocore, rat, malware-bazaar ^[metadata.json]
  • Sample source: abuse.ch / MalwareBazaar (via OpenCTI urlhaus-recent-payloads connector)

Provenance

  • Report built from static artefacts generated by the triage pipeline on 2026-05-26.
  • Tools: file, strings, floss (failed — invalid args), capa v5 (static, dotnet), binwalk, radare2 (CIL analysis), python3 (manual entropy + offset extraction), pefile.
  • No CAPE dynamic analysis: Windows guest unavailable at time of triage. All runtime/C2 claims are inferred from static imports, capa capability map, and known NanoCore builder behaviour.
  • Sibling confirmation via diff of strings.txt and pefile.txt against fe81691f; only GUID (line 1624) and .rsrc section hashes differ.