typeanalysisfamilynanocoreconfidencehighmalware-familyratdotnetobfuscationc2persistencedefense-evasion
SHA-256: f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f

nanocore: f017a517 — EMU.exe emulator masquerade, 1.2.2.0 builder, 90 KB encrypted RCData

Executive Summary

Tenth confirmed sibling of the leaked-era NanoCore RAT builder batch (22 Feb 2015 00:49:37 UTC). Identical ConfuserEx-obfuscated VB.NET client v1.2.2.0 to the nine prior siblings, but distributed under the filename EMU.exe — an emulator/game-utility social-engineering lure rather than the blunt Backdoor.exe or new88.exe names seen in the rest of the cluster. 90 KB encrypted RCData payload in .rsrc; no hardcoded C2 recovered statically. Static-only (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f
Filename EMU.exe ^[metadata.json]
Size 207,872 bytes (203 KB)
Compile Sun Feb 22 00:49:37 2015 UTC — identical timestamp to the full Feb 2015 batch. ^[pefile.txt:34]
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
CLR .NET Framework 2.0 (v2.0.50727) ^[strings.txt:51]
Builder NanoCore Client v1.2.2.0 ^[strings.txt:1626]
Internal name NanoCore Client / NanoCore Client.exe ^[strings.txt:55-56]
Obfuscator ConfuserEx — mass #=q…== name mangling across 858 r2-discovered functions. ^[strings.txt:278-948]
Signed Unsigned ^[rabin2-info.txt:27]
Imports Single entry: mscoree.dll._CorExeMain ^[pefile.txt:199]
Resource .rsrc RT_RCDATA id=1, 89,960 bytes, entropy ~7.998 — encrypted plugin package.

How It Works

The binary is a standard NanoCore client from the leaked builder era. For the shared build-stack, plugin architecture, C2 protocol, and persistence patterns, see the nanocore entity page — this sample is a cluster sibling and does not introduce new technical divergence.

Per-sample deltas:

  • Filename masquerade: EMU.exe (emulator / game utility) instead of the blunt Backdoor.exe, new88.exe, moocow.exe, or geographic lures (hotro.exe, mmdx2.ru.com.exe) seen in prior siblings. This represents a different social-engineering angle targeting gamers or retro-computing enthusiasts.
  • Payload size: 89,960-byte encrypted RCData — larger than the ~88 KB seen in cb2aa275, suggesting a fuller plugin bundle or different builder configuration.
  • GUID: Not recovered statically (ConfuserEx strips MyTemplate GUID visibility without de-obfuscation).

Entry point is ClientLoaderForm.Main at 0x0040c480 — the standard WinForms bootstrap that decrypts the .rsrc payload, reflects the plugin assembly into memory, and initiates the TCP C2 loop. ^[r2:entry0]

Decompiled Behavior

Ghidra CIL decompilation was not attempted (radare2 CIL analysis completed successfully with 858 functions). Key observations from radare2:

  • Entry point 0x0040c480 labeled ClientLoaderForm.Main — WinForms loader form. ^[r2:entry0]
  • Heavy ConfuserEx obfuscation: all type and method names replaced with #=q<Base64>== patterns, hindering decompiler readability. ^[strings.txt:278-948]
  • No observable anti-VM or anti-debug checks beyond the obfuscation layer.
  • The .rsrc section (entropy 7.998) contains the encrypted plugin package; decryption key is runtime-derived, not present in strings.

C2 Infrastructure

No hardcoded C2 hostnames, IPs, or ports recovered statically. The NanoCore builder stores C2 configuration inside the encrypted RCData resource; runtime decryption is required. ^[nanocore]

Interesting Tidbits

  • EMU.exe masquerade is a departure from the builder's typical blunt-filename distribution pattern. Indicates either a reseller/customer re-packaging or a builder UI that allows custom output filenames.
  • The .rsrc payload is ~2 KB larger than the cb2aa275 sibling, suggesting a plugin configuration with more modules enabled (keylogger, remote desktop, file manager) or a different build profile.
  • Version string 1.2.2.0 at line 1626 of strings.txt is consistent with the leaked builder era — no evidence of a later fork or modified build.
  • capa static analysis triggers the same .NET Framework false-positive family (Debug-build attribute detection) seen across other ConfuserEx samples; the enter debug mode in .NET hit is benign. ^[capa.txt:92]

How To Mess With It (Homelab Replication)

Not recommended for live replication — NanoCore is a known malicious RAT and its builder is leaked warez. For defensive research:

  1. Toolchain: VB.NET or C# in Visual Studio / SharpDevelop, targeting .NET Framework 2.0.
  2. Obfuscation: Apply ConfuserEx (open-source) with name mangling + resource encryption.
  3. Verification: capa on the output should hit .NET platform, create TCP socket, resolve DNS, create process, query registry, set registry value, load .NET assembly.
  4. Network: A raw TCP listener on the configured port will receive the initial handshake once the RCData is decrypted and the client executes.

Deployable Signatures

YARA rule

rule nanocore_confuserex_feb2015_batch {
    meta:
        description = "NanoCore RAT leaked-builder batch sibling (Feb 2015, ConfuserEx, v1.2.2.0)"
        author = "triage-pipeline"
        date = "2026-08-07"
        sha256 = "f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f"
    strings:
        $a = "NanoCore Client" ascii wide
        $b = "NanoCore Client.exe" ascii wide
        $c = "NanoCore" ascii wide
        $d = "IClientApp" ascii wide
        $e = "IClientNetwork" ascii wide
        $f = "IClientUIHost" ascii wide
        $g = "ClientLoaderForm" ascii wide
        $h = "1.2.2.0" ascii wide
        $i = "#=q" ascii wide
        $confuser = "ConfuserEx" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        ($a or $b) and
        ($c and $d and $e) and
        ($g or $h) and
        #i > 50 and
        filesize < 500KB
}

Sigma rule (process creation)

title: NanoCore Client Execution Detection
logsource:
    category: process_creation
    product: windows
detection:
    selection_strings:
        CommandLine|contains:
            - 'NanoCore'
            - 'ClientLoaderForm'
    selection_mutex:
        - '?*NanoCore*'
    condition: selection_strings or selection_mutex
falsepositives:
    - Unlikely; these strings are specific to the NanoCore malware family.
level: high

IOC list

Type Value Note
SHA-256 f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f This sample
Filename EMU.exe Social-engineering lure
Compile time 2015-02-22 00:49:37 UTC Batch fingerprint
Version 1.2.2.0 Builder version
Internal name NanoCore Client.exe Immutable builder artefact
Resource RT_RCDATA id=1, ~90 KB Encrypted plugin package
Mutex Unknown Builder-configured, runtime-resolved
C2 Unknown Stored in encrypted resource

Behavioral fingerprint

This PE32 .NET executable loads via mscoree.dll._CorExeMain, decrypts an ~90 KB RCData resource at runtime using a ConfuserEx-derived key, reflectively loads the decrypted assembly into the current AppDomain, and opens a raw TCP socket to a builder-configured host within seconds of process start. File-system operations (create directory, copy file, write file) and registry queries follow shortly after. Persistence is typically via HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

Detection Signatures

ATT&CK Tactic Technique Source
Defense Evasion T1112 Modify Registry ^[capa.txt:15]
Defense Evasion T1620 Reflective Code Loading ^[capa.txt:16]
Discovery T1087 Account Discovery ^[capa.txt:17]
Discovery T1083 File and Directory Discovery ^[capa.txt:18]
Discovery T1012 Query Registry ^[capa.txt:19]
Discovery T1082 System Information Discovery ^[capa.txt:20]
Discovery T1033 System Owner/User Discovery ^[capa.txt:21]
Command and Control B0030.001 Send Data / B0030.002 Receive Data ^[capa.txt:31-32]
Communication C0011.001 DNS Resolve / C0001.011 TCP Socket ^[capa.txt:33-36]

References

  • Artifact ID: 22092f78-62f9-4dfe-aa83-fe4b03f60135 ^[metadata.json]
  • Source: OpenCTI / MalwareBazaar
  • Family page: nanocore
  • Technique: confuserex-obfuscation
  • Concept: raw-tcp-c2-socket
  • Batch siblings: fe81691f, 48c8e8a2, d065ebea, 4121d69c, 0eedf3a8, cb2aa275, e48f1c56, 12deaec6, b6008cf6

Provenance

Analysis derived from static artefacts only — no CAPE detonation available (no Windows guest). Tools: file (PE32 .NET), pefile (3 sections, .rsrc 89,960 bytes), radare2 rabin2 (CIL, unsigned, entry0=ClientLoaderForm.Main), capa v7 (ATT&CK + MBC mapping), strings (NanoCore Client 1.2.2.0, ConfuserEx mangling), custom Python resource extraction (pefile RT_RCDATA enumeration). FLOSS failed on argument order and was not re-run successfully. Report written 2026-08-07.