f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6fnanocore: f017a517 — EMU.exe emulator masquerade, 1.2.2.0 builder, 90 KB encrypted RCData
Executive Summary
Tenth confirmed sibling of the leaked-era NanoCore RAT builder batch (22 Feb 2015 00:49:37 UTC). Identical ConfuserEx-obfuscated VB.NET client v1.2.2.0 to the nine prior siblings, but distributed under the filename EMU.exe — an emulator/game-utility social-engineering lure rather than the blunt Backdoor.exe or new88.exe names seen in the rest of the cluster. 90 KB encrypted RCData payload in .rsrc; no hardcoded C2 recovered statically. Static-only (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f |
| Filename | EMU.exe ^[metadata.json] |
| Size | 207,872 bytes (203 KB) |
| Compile | Sun Feb 22 00:49:37 2015 UTC — identical timestamp to the full Feb 2015 batch. ^[pefile.txt:34] |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| CLR | .NET Framework 2.0 (v2.0.50727) ^[strings.txt:51] |
| Builder | NanoCore Client v1.2.2.0 ^[strings.txt:1626] |
| Internal name | NanoCore Client / NanoCore Client.exe ^[strings.txt:55-56] |
| Obfuscator | ConfuserEx — mass #=q…== name mangling across 858 r2-discovered functions. ^[strings.txt:278-948] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Imports | Single entry: mscoree.dll._CorExeMain ^[pefile.txt:199] |
| Resource | .rsrc RT_RCDATA id=1, 89,960 bytes, entropy ~7.998 — encrypted plugin package. |
How It Works
The binary is a standard NanoCore client from the leaked builder era. For the shared build-stack, plugin architecture, C2 protocol, and persistence patterns, see the nanocore entity page — this sample is a cluster sibling and does not introduce new technical divergence.
Per-sample deltas:
- Filename masquerade:
EMU.exe(emulator / game utility) instead of the bluntBackdoor.exe,new88.exe,moocow.exe, or geographic lures (hotro.exe,mmdx2.ru.com.exe) seen in prior siblings. This represents a different social-engineering angle targeting gamers or retro-computing enthusiasts. - Payload size: 89,960-byte encrypted RCData — larger than the ~88 KB seen in
cb2aa275, suggesting a fuller plugin bundle or different builder configuration. - GUID: Not recovered statically (ConfuserEx strips
MyTemplateGUID visibility without de-obfuscation).
Entry point is ClientLoaderForm.Main at 0x0040c480 — the standard WinForms bootstrap that decrypts the .rsrc payload, reflects the plugin assembly into memory, and initiates the TCP C2 loop. ^[r2:entry0]
Decompiled Behavior
Ghidra CIL decompilation was not attempted (radare2 CIL analysis completed successfully with 858 functions). Key observations from radare2:
- Entry point
0x0040c480labeledClientLoaderForm.Main— WinForms loader form. ^[r2:entry0] - Heavy ConfuserEx obfuscation: all type and method names replaced with
#=q<Base64>==patterns, hindering decompiler readability. ^[strings.txt:278-948] - No observable anti-VM or anti-debug checks beyond the obfuscation layer.
- The
.rsrcsection (entropy 7.998) contains the encrypted plugin package; decryption key is runtime-derived, not present in strings.
C2 Infrastructure
No hardcoded C2 hostnames, IPs, or ports recovered statically. The NanoCore builder stores C2 configuration inside the encrypted RCData resource; runtime decryption is required. ^[nanocore]
Interesting Tidbits
EMU.exemasquerade is a departure from the builder's typical blunt-filename distribution pattern. Indicates either a reseller/customer re-packaging or a builder UI that allows custom output filenames.- The
.rsrcpayload is ~2 KB larger than thecb2aa275sibling, suggesting a plugin configuration with more modules enabled (keylogger, remote desktop, file manager) or a different build profile. - Version string
1.2.2.0at line 1626 of strings.txt is consistent with the leaked builder era — no evidence of a later fork or modified build. - capa static analysis triggers the same .NET Framework false-positive family (Debug-build attribute detection) seen across other ConfuserEx samples; the
enter debug mode in .NEThit is benign. ^[capa.txt:92]
How To Mess With It (Homelab Replication)
Not recommended for live replication — NanoCore is a known malicious RAT and its builder is leaked warez. For defensive research:
- Toolchain: VB.NET or C# in Visual Studio / SharpDevelop, targeting .NET Framework 2.0.
- Obfuscation: Apply ConfuserEx (open-source) with name mangling + resource encryption.
- Verification:
capaon the output should hit.NET platform,create TCP socket,resolve DNS,create process,query registry,set registry value,load .NET assembly. - Network: A raw TCP listener on the configured port will receive the initial handshake once the RCData is decrypted and the client executes.
Deployable Signatures
YARA rule
rule nanocore_confuserex_feb2015_batch {
meta:
description = "NanoCore RAT leaked-builder batch sibling (Feb 2015, ConfuserEx, v1.2.2.0)"
author = "triage-pipeline"
date = "2026-08-07"
sha256 = "f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f"
strings:
$a = "NanoCore Client" ascii wide
$b = "NanoCore Client.exe" ascii wide
$c = "NanoCore" ascii wide
$d = "IClientApp" ascii wide
$e = "IClientNetwork" ascii wide
$f = "IClientUIHost" ascii wide
$g = "ClientLoaderForm" ascii wide
$h = "1.2.2.0" ascii wide
$i = "#=q" ascii wide
$confuser = "ConfuserEx" ascii wide
condition:
uint16(0) == 0x5A4D and
($a or $b) and
($c and $d and $e) and
($g or $h) and
#i > 50 and
filesize < 500KB
}
Sigma rule (process creation)
title: NanoCore Client Execution Detection
logsource:
category: process_creation
product: windows
detection:
selection_strings:
CommandLine|contains:
- 'NanoCore'
- 'ClientLoaderForm'
selection_mutex:
- '?*NanoCore*'
condition: selection_strings or selection_mutex
falsepositives:
- Unlikely; these strings are specific to the NanoCore malware family.
level: high
IOC list
| Type | Value | Note |
|---|---|---|
| SHA-256 | f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f |
This sample |
| Filename | EMU.exe |
Social-engineering lure |
| Compile time | 2015-02-22 00:49:37 UTC |
Batch fingerprint |
| Version | 1.2.2.0 |
Builder version |
| Internal name | NanoCore Client.exe |
Immutable builder artefact |
| Resource | RT_RCDATA id=1, ~90 KB | Encrypted plugin package |
| Mutex | Unknown | Builder-configured, runtime-resolved |
| C2 | Unknown | Stored in encrypted resource |
Behavioral fingerprint
This PE32 .NET executable loads via mscoree.dll._CorExeMain, decrypts an ~90 KB RCData resource at runtime using a ConfuserEx-derived key, reflectively loads the decrypted assembly into the current AppDomain, and opens a raw TCP socket to a builder-configured host within seconds of process start. File-system operations (create directory, copy file, write file) and registry queries follow shortly after. Persistence is typically via HKCU\Software\Microsoft\Windows\CurrentVersion\Run.
Detection Signatures
| ATT&CK Tactic | Technique | Source |
|---|---|---|
| Defense Evasion | T1112 Modify Registry | ^[capa.txt:15] |
| Defense Evasion | T1620 Reflective Code Loading | ^[capa.txt:16] |
| Discovery | T1087 Account Discovery | ^[capa.txt:17] |
| Discovery | T1083 File and Directory Discovery | ^[capa.txt:18] |
| Discovery | T1012 Query Registry | ^[capa.txt:19] |
| Discovery | T1082 System Information Discovery | ^[capa.txt:20] |
| Discovery | T1033 System Owner/User Discovery | ^[capa.txt:21] |
| Command and Control | B0030.001 Send Data / B0030.002 Receive Data | ^[capa.txt:31-32] |
| Communication | C0011.001 DNS Resolve / C0001.011 TCP Socket | ^[capa.txt:33-36] |
References
- Artifact ID:
22092f78-62f9-4dfe-aa83-fe4b03f60135^[metadata.json] - Source: OpenCTI / MalwareBazaar
- Family page: nanocore
- Technique: confuserex-obfuscation
- Concept: raw-tcp-c2-socket
- Batch siblings:
fe81691f,48c8e8a2,d065ebea,4121d69c,0eedf3a8,cb2aa275,e48f1c56,12deaec6,b6008cf6
Provenance
Analysis derived from static artefacts only — no CAPE detonation available (no Windows guest). Tools: file (PE32 .NET), pefile (3 sections, .rsrc 89,960 bytes), radare2 rabin2 (CIL, unsigned, entry0=ClientLoaderForm.Main), capa v7 (ATT&CK + MBC mapping), strings (NanoCore Client 1.2.2.0, ConfuserEx mangling), custom Python resource extraction (pefile RT_RCDATA enumeration). FLOSS failed on argument order and was not re-run successfully. Report written 2026-08-07.