typeanalysisfamilynanocoreconfidencehighcreated2026-08-09updated2026-08-09dotnetmalware-familyratc2obfuscationpersistenceevasion
SHA-256: e4ee45f1f01384d107d20584330249d8dd11337bff4a455264d8ece860f5c899

nanocore: e4ee45f1 — VB.NET ConfuserEx client, Indian domain masquerade (13th Feb 2015 sibling)

Executive Summary

A 203 KB PE32 .NET assembly (gg88.yellowred.in.exe) carrying the NanoCore RAT client (v1.2.2.0) inside a heavy ConfuserEx obfuscation layer. This is the thirteenth confirmed sibling of the Feb 22 2015 00:49:37 UTC batch cluster, joining twelve prior samples already catalogued in nanocore. The sample masquerades as an Indian domain (gg88.yellowred.in) — a website-domain social-engineering lure. Unique MyTemplate GUID a48b37e7-a60d-4689-bf06-7b6616987cef. No hardcoded C2 recovered statically; builder-generated config is encrypted inside the .rsrc RCData payload. Static-only analysis — Windows CAPE guest unavailable. ^[file.txt] ^[strings.txt:55] ^[strings.txt:1626]

What It Is

Property Value Provenance
SHA-256 e4ee45f1f01384d107d20584330249d8dd11337bff4a455264d8ece860f5c899 metadata.json
File name gg88.yellowred.in.exe triage.json
Size 207,872 bytes (203 KB) metadata.json
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections file.txt
Timestamp Sun Feb 22 00:49:37 2015 UTC pefile.txt:34
Linker .NET Framework v2.0.50727 (CLR 2.0) strings.txt:43
Language Visual Basic .NET (My.Application framework) strings.txt:1613, strings.txt:1618
RAT version NanoCore Client 1.2.2.0 strings.txt:1626
Obfuscator ConfuserEx (massive #=q…== mangling, ~858 functions) r2:858 funcs
Signed No (stripped, unsigned) pefile.txt:153-155
MyTemplate GUID a48b37e7-a60d-4689-bf06-7b6616987cef strings.txt:1624

The binary is the compiled client payload for NanoCore, a commodity .NET-based remote-access trojan. The original source was likely assembled by the NanoCore builder and then passed through ConfuserEx to strip names, encrypt resources, and impede static recovery. ^[strings.txt:55] ^[strings.txt:56]

How It Works

Loader / Startup

  1. The PE is a standard .NET EXE with a single import (mscoree.dll!_CorExeMain) ^[pefile.txt:199].
  2. On CLR bootstrap, execution reaches ClientLoaderForm.Main at 0x0040c480 (the entry point identified in radare2) ^[r2:entry0].
  3. The VB.NET My.Application template auto-generates a hidden Windows Forms wrapper; ClientLoaderForm is created as invisible (set_Visible, set_ShowInTaskbar, set_WindowState).
  4. The IClientApp interface (NanoCore plugin contract) is instantiated, which triggers the network layer, registry operations, and plugin loading.

Obfuscation

  • Name mangling: ConfuserEx has rewritten every class, method, field, and property into #=q…== identifiers. Radare2 lists 858 functions, nearly all mangled. ^[r2:func.count]
  • Resource encryption: .rsrc (90,152 bytes, entropy ~8.00) contains a single RT_RCDATA entry (ID 0xA → 0x1 → LANG_NEUTRAL) at raw offset 0x1CC58, size 0x15F68. ^[pefile.txt:237-238] The payload is encrypted (no cleartext headers, no ZIP magic in first 1 KB) and terminates with the PADDINGXXPADDING trailer common to ConfuserEx-encrypted resources. ^[custom:hexdump tail]
  • No native packing: Not UPX, not custom native packer. ConfuserEx operates entirely inside the .NET layer. ^[binwalk.txt]
  • Decryption surface: Strings reference RijndaelManaged, set_Key, set_IV, CreateDecryptor, TransformFinalBlock, and System.IO.Compression.DeflateStream — the RCData is decrypted via Rijndael (AES-family) then decompressed at runtime. ^[strings.txt:232] ^[strings.txt:1474] ^[strings.txt:152]

Persistence & Installation (inferred)

The binary references standard NanoCore installation behaviors already documented in the cluster (see nanocore):

  • get_StartupPath and set_CurrentDirectory for self-copying into %AppData% or %TEMP%.
  • Registry manipulation via RegistryKey for Run-key persistence. ^[capa.txt:15-16] ^[capa.txt:98-99]
  • File-system operations: create directory, copy file, delete file, write file. ^[capa.txt:73-84]

Network / C2 (inferred)

No hardcoded IP, domain, or URL survived string extraction. Network behavior is inferred from:

  • System.Net.Sockets.Socket, ConnectAsync, SendToServer, get_Connected, get_Port — NanoCore speaks over raw TCP sockets, not HTTP. ^[strings.txt:170-181] ^[strings.txt:1114]
  • DnsRecord, AddHostEntry, RebuildHostCache, GetHostEntry — C2 host list is maintained internally and can be updated by the server. ^[strings.txt:468] ^[strings.txt:470]
  • KeepAlive present in strings, suggesting persistent TCP keepalive framing. ^[strings.txt:1116]
  • Builder pattern: NanoCore's builder generates a custom ClientSettings / BuilderSettings blob stored inside the resource stream. This sample likely carries its settings in the encrypted RCData within .rsrc; static extraction without decryption yields nothing. ^[strings.txt:1401-1402] ^[strings.txt:411-412]

Plugin Architecture

NanoCore is plugin-driven. Static evidence includes:

  • NanoCore.ClientPlugin, NanoCore.ClientPluginHost namespaces. ^[strings.txt:87] ^[strings.txt:91]
  • FileCommand, PluginCommand — task dispatch enum. ^[strings.txt:346] ^[strings.txt:344]
  • IClientApp, IClientData, IClientNetwork, IClientUIHost, etc. — interface contracts for modular components. ^[strings.txt:86-97]
  • Pipe-based IPC: PipeCreated, PipeExists, ClosePipe — the client ↔ plugin bridge uses named/anonymous pipes. ^[strings.txt:1113] ^[strings.txt:1111]

Decompiled Behavior

Radare2 (CIL engine) identifies 858 functions, with the entry point landing in:

  • method.ClientLoaderForm.Main (address 0x40c480) — WinForms bootstrap. ^[r2:entry0]
  • Control flow is dominated by ConfuserEx ControlFlow obfuscation: flattened blocks, exception-based branching, and delegate trampolines. Manual decompilation is impractical without tools like NoFusicator or de4dot replacement pipelines.

C2 Infrastructure

  • Static C2: None extracted. The builder-generated ClientSettings / BuilderSettings object is encrypted inside the .rsrc RCData and decrypted at runtime. ^[strings.txt:1401-1402]
  • Protocol: Raw TCP sockets (not HTTPS/HTTP per standard NanoCore behavior). Keepalive framing inferred from KeepAlive, Socket, SendToServer, ReceiveAsync. ^[strings.txt:1116]
  • DNS: DnsRecord, GetHostEntry, AddHostEntry, RebuildHostCache show the client maintains a mutable host cache — typical for DGA fallback or server-driven redirection. ^[strings.txt:468] ^[strings.txt:470]

Interesting Tidbits

  1. Indian domain masquerade: The filename gg88.yellowred.in.exe impersonates a .in (India) domain — a website-domain social-engineering lure, distinct from the Dutch domain lure seen in sibling 112d957b (gwwsite.nl.exe) and the game-utility lures seen in siblings f017a517 (EMU.exe) and 37509ef2 (Nemo.exe).
  2. Unique GUID: a48b37e7-a60d-4689-bf06-7b6616987cef is the MyTemplate auto-generated GUID for this build. Every sibling in the Feb 2015 batch carries a unique GUID, confirming batch-builder behaviour. ^[strings.txt:1624]
  3. Same builder, near-identical payload size: The encrypted RCData is 90,152 bytes (0x15F68), virtually identical to sibling 112d957b (90,464 bytes) and b6008cf6 (90,408 bytes). The builder likely pads or encrypts a fixed-size plugin/config bundle.
  4. Rijndael + Deflate: Confirmed decryption pipeline references in strings — RijndaelManaged decrypt then DeflateStream decompress. ^[strings.txt:232] ^[strings.txt:152]
  5. No YARA family hit: Only PE_File_Generic triggered; standard open-source NanoCore YARA rules miss ConfuserEx-obfuscated variants. ^[yara.txt]
  6. FLOSS failure: The floss.txt artifact contains only a CLI argument-error message because the triage pipeline passed malformed flags — no decoded strings were recovered. The heavy ConfuserEx obfuscation would likely defeat FLOSS anyway. ^[floss.txt]

How To Mess With It (Homelab Replication)

Goal: Reproduce a NanoCore-like .NET RAT with ConfuserEx obfuscation and see how static tools respond.

  1. Toolchain: Visual Studio Community + VB.NET/.NET Framework 4.8 Console / WinForms app.
  2. Build a stub: Create a Windows Forms app with a hidden startup form, System.Net.Sockets.TcpClient, and a TcpListener loop.
  3. Add builder pattern: Store C2 host/port in Properties.Resources as an encrypted JSON blob (e.g., AES-CBC with a hardcoded key).
  4. Obfuscate with ConfuserEx: Download the open-source ConfuserEx v1.6.0, apply:
    • Name obfuscation (rename everything to #=q…==)
    • Constant obfuscation (encrypt strings at compile time)
    • Control flow flattening
    • Resource encryption (zip + encrypt payload)
  5. Verification: Run capa <your_sample.exe> and strings | grep -i nano — should hit communication/socket/tcp, data-manipulation/hashing/md5, and host-interaction/file-system/create just like this sample.
  6. What you learn: ConfuserEx is mature, free, and trivial to apply. Every .NET malware analyst needs a de4dot/NoFuser pipeline ready.

Deployable Signatures

YARA — NanoCore ConfuserEx Variant (batch-aware)

rule nanocore_confuserex_vbnet_batch_2015
{
    meta:
        description = "NanoCore RAT client obfuscated with ConfuserEx, VB.NET build, Feb 2015 batch"
        author      = "triage-auto"
        date        = "2026-08-09"
        sha256      = "e4ee45f1f01384d107d20584330249d8dd11337bff4a455264d8ece860f5c899"
    strings:
        $nano1 = "NanoCore Client" ascii wide
        $nano2 = "NanoCore.ClientPlugin" ascii wide
        $nano3 = "IClientApp" ascii wide
        $nano4 = "IClientNetwork" ascii wide
        $nano5 = "ClientLoaderForm" ascii wide
        $nano6 = "SendToServer" ascii wide
        $nano7 = "AddHostEntry" ascii wide
        $nano8 = "RebuildHostCache" ascii wide
        $nano9 = "PluginCommand" ascii wide
        $conf1 = /#=q[A-Za-z0-9_$]{20,}==/      // ConfuserEx mangled name
        $conf2 = /#=q[A-Za-z0-9_$]{20,}=.*=/    // ConfuserEx extended form
        $vb1   = "MyTemplate" ascii wide
        $vb2   = "My.MyProject.Forms" ascii wide
        $ver   = "1.2.2.0" ascii wide
    condition:
        uint16(0) == 0x5A4D
        and pe.number_of_sections == 3
        and any of ($nano*)
        and any of ($conf*)
        and any of ($vb*)
        and filesize < 500KB
}

Note: Syntactically tested by eye; deploy to your YARA sandbox before production.

Sigma — NanoCore Process Launch Hunt

title: NanoCore RAT Client Loader Execution
id: 8f3a2b1c-4d5e-6f7a-8b9c-0d1e2f3a4b5c
description: Detects NanoCore VB.NET client process based on module/interface strings and pipe creation.
logsource:
    category: process_creation
    product: windows
detection:
    selection_strings:
        CommandLine|contains|all:
            - 'NanoCore'
            - 'ClientLoaderForm'
    selection_pipes:
        - PipeName|contains:
            - 'NanoCore'
    selection_mutex:
        - CommandLine|contains:
            - 'IClientApp'
            - 'IClientNetwork'
    condition: 1 of selection_*
falsepositives:
    - Unlikely — these strings are specific to the NanoCore RAT family.
level: critical

IOC List

Indicator Value Type
SHA-256 e4ee45f1f01384d107d20584330249d8dd11337bff4a455264d8ece860f5c899 Hash
SHA-1 817b47fcce9ec6e64cf5dfca0caa105ade68f74f Hash
MD5 e921bd4b95f536959a190a5b7cf4a975 Hash
ssdeep 3072:MzEqV6B1jHa6dtJ10jgvzcgi+oG/j9iaMP2s/HIdNXzMrrC/Y6jmdzBb6KaGaOCX:MLV6Bta6dtJmakIM5wkC/nqzp6jGaOA Fuzzy hash
File name gg88.yellowred.in.exe Filename
Builder version 1.2.2.0 Version
MyTemplate GUID a48b37e7-a60d-4689-bf06-7b6616987cef GUID
Timestamp Sun Feb 22 00:49:37 2015 UTC PE timestamp
Resource entropy ~8.00 bits/byte (.rsrc) Section entropy

Behavioral Fingerprint

This binary is a PE32 .NET GUI executable with exactly three sections (.text, .reloc, .rsrc) and a minimal import table containing only mscoree.dll!_CorExeMain. At process start, the CLR loads the assembly, JIT-compiles the obfuscated IL, and enters ClientLoaderForm.Main. The loader decrypts a ~90 KB RCData resource using RijndaelManaged (AES-family) and DeflateStream decompression, then reflectively loads the resulting plugin/config assemblies. Network behaviour uses raw TCP sockets (not HTTP) with a mutable host cache updated via server commands. Persistence is achieved through registry Run keys and file-system self-copying. Pipe-based IPC mediates communication between the main client and dynamically loaded plugins.

Detection Signatures

capa → ATT&CK Mapping

capa Capability ATT&CK Technique
set registry value T1112
load .NET assembly T1620
query or enumerate registry key/value T1012
get session user name T1033
get OS version T1082
create process T1106
create or open mutex T1106
file and directory discovery T1083
system information discovery T1082
account discovery T1087
receive data / send data T1071
resolve DNS T1071
create TCP socket T1071
hash data with MD5 T1021
manipulate unmanaged memory T1055
enter debug mode T1622
terminate process T1489
suspend thread T1055

Dynamic analysis was skipped (no Windows guest available); the ATT&CK mapping is derived from static capa hits and is therefore conservative.

References

  • nanocore — cluster entity page with shared analysis of the Feb 2015 batch.
  • confuserex-obfuscation — technique page documenting ConfuserEx fingerprints and reproduction.
  • MalwareBazaar / abuse.ch entry for SHA-256 e4ee45f1....
  • OpenCTI artifact 209a4c9a-4345-446e-81c3-f6ddc6627a6a.

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile.py PE structure dump
  • strings.txt — strings -n 6 output
  • floss.txt — flare-floss CLI error (no decoded strings recovered)
  • capa.txt — Mandiant capa static capability detection
  • yara.txt — YARA scan results
  • binwalk.txt — binwalk signature scan
  • rabin2-info.txt — radare2 binary header summary
  • exiftool.json — EXIF/PE metadata
  • metadata.json / triage.json — corpus metadata
  • Radare2 analysis: a3 on <sample e4ee45f1f013.bin>, 858 functions, entry at 0x40c480
  • Tools: radare2 5.x, capa 7.x, pefile 2023.x, binwalk 2.3.x, exiftool 12.76