NanoCore
Overview
NanoCore is a commodity .NET-based remote-access trojan (RAT) whose builder leaked around 2014–2015. It remains actively distributed via spam, cracked software bundles, and phishing lures. The client is highly configurable through a point-and-click builder that generates a small (~150–300 KB) obfuscated EXE targeting .NET Framework 2.0–4.x.
Build-Stack Typically Observed
- Language: C# or VB.NET (Visual Studio / SharpDevelop).
- Framework: .NET Framework 2.0 (CLR v2.0.50727) or .NET 4.x.
- Builder: NanoCore Builder (version stamps like
1.2.2.0seen in leaked-era builds). - Obfuscator: Frequently confuserex-obfuscation — mass name mangling (
#=q…==), resource encryption, control-flow flattening. Also observed with Eazfuscator, Dotfuscator, and SmartAssembly. - Package: Single PE32 with 3 sections (
.text,.reloc,.rsrc)..rsrcoften contains an encrypted ZIP or manifest payload. - Signing: Usually unsigned; Authenticode stripped. ^[sample fe81691f/pefile.txt]
Deploy / TTPs Typically Observed
- Persistence: Registry Run key (
HKCU\Software\Microsoft\Windows\CurrentVersion\Run) or copied to%AppData%/%TEMP%. ^[sample fe81691f/capa.txt:95-99] - C2 Protocol: Raw TCP sockets (not HTTP/HTTPS). Builder-configured host/port list; client caches entries and supports server-driven host updates via
AddHostEntry/RebuildHostCache. Keepalive framing. ^[sample fe81691f/capa.txt:62-66] - Plugin Architecture: Modular design —
IClientApp,IClientNetwork,IClientUIHost, etc. Plugins loaded reflectively from encrypted resource packages. IPC via named/anonymous pipes. ^[sample fe81691f/strings.txt:86-97] - File System: Creates directories, copies itself, deletes files, writes temp files. ^[sample fe81691f/capa.txt:73-84]
- Discovery: System information, user name, OS version, hostname, file/directory enumeration, registry queries. ^[sample fe81691f/capa.txt:15-22]
- Defense Evasion: Heavily obfuscated with ConfuserEx; reflective code loading of plugins; minimal static IAT (only
mscoree.dll._CorExeMain). ^[sample fe81691f/pefile.txt:199] - MD5 Hashing: Observed in network packet integrity / config checks. ^[sample fe81691f/capa.txt:66]
Variants / Aliases
- NanoCore RAT — the umbrella label.
- NanoCore Client — the builder-generated payload EXE.
- NanoCore Plugin — individual modules (file manager, remote desktop, keylogger, etc.) delivered as encrypted plugin packages.
- Builder versions:
1.1.x,1.2.x(leaked era), plus later forks sold in underground markets.
Notable Analyses
-
fe81691f— VB.NET ConfuserEx obfuscated client v1.2.2.0, raw static deep-dive. ^[/intel/analyses/fe81691f199873bd5470c7beff9a52fdd6c1e03b80484e40b15ce040cde851b5.html] -
48c8e8a2— ConfuserEx sibling build (same timestamp, same builder version, different GUID and encrypted resource). Confirms batch-build behaviour. ^[/intel/analyses/48c8e8a2f28318ae10000d4997784cd12703e182bd50db5da32b930034a0bc4c.html] -
d065ebea— Third sibling (hotro.exe) in the same Feb 2015 batch, Vietnamese-language filename masquerade. ^[/intel/analyses/d065ebea634c65f1bc3e1b770d09f0364b87a74a631deca80f84f20561533898.html] -
4121d69c— Fourth sibling (Backdoor.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client with identical builder version1.2.2.0. Confirms mass builder-era distribution. ^[/intel/analyses/4121d69c165b16754eb62f1b87930e7c66a69e4c4a5e6526c10e1c4fea547b2f.html] |-0eedf3a8— Fifth sibling (Backdoor.exe), same Feb 2015 batch, identical builder version1.2.2.0, unique GUIDee24ebfc-5674-4134-8aa8-c2651cc2f5d4. Blunt-filename lure; no social-engineering rename. ^[/intel/analyses/0eedf3a80df9b816949c1ac066553d40b5bb0113edec7dedd1b19ab7228ec5a3.html] |-cb2aa275— Sixth sibling (moocow.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated .NET Framework 2.0 client with internal nameNanoCore Client.exe. Full plugin-host interface surface (IClientApp,IClientNetwork, etc.). 88 KB encrypted RCData resource, no hardcoded C2 recovered. Static-only (CAPE skipped). ^[/intel/analyses/cb2aa2757374dcf03c6dec4079e6b4f6eaf68fdd61731e7e922eba679ee6fe07.html] |-e48f1c56— Seventh confirmed sibling (Backdoor.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Confirmed twin offe81691f— only delta is theMyTemplateGUID (f14daca4-…vsb4de0bbe-…) and encrypted.rsrcpayload hashes. Blunt filename; no social-engineering masquerade. Static-only (CAPE skipped). ^[/intel/analyses/e48f1c56d011b1cb99607a39092d27abd11cf544b80bf7e539406ca34fab2556.html] |-12deaec6— Eighth confirmed sibling (new88.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. UniqueMyTemplateGUID2601925a-2b07-4fb7-aeb0-80126437ed67. Blunt filename; no social-engineering masquerade. Static-only (CAPE skipped). ^[/intel/analyses/12deaec6ed13bc99dc670d7f01739d008c7c76c690fc164148c9dd38516287ac.html] |-b6008cf6— Ninth confirmed sibling (mmdx2.ru.com.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. UniqueMyTemplateGUID630148c0-c72e-4620-938d-13f9c119d87b. Russian domain masquerade filename; ~90 KB encrypted RCData in.rsrc. Static-only (CAPE skipped). ^[/intel/analyses/b6008cf64e5ec8d7756cd1fc8e0e76b7e420529d41e83b66022b76ebb26b1eeb.html] ||-f017a517— Tenth confirmed sibling (EMU.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Emulator/game-utility social-engineering masquerade; 89,960-byte encrypted RCData in.rsrc. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/f017a517cca5e63ad557dc9541ab6284a23ecfb7e6ccbc0d24bf42981af81d6f.html] -
37509ef2— Eleventh confirmed sibling (Nemo.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Disney/Finding Nemo social-engineering masquerade; 88,928-byte encrypted RCData in.rsrc. Unique GUID6d10e433-cda2-420f-9bab-c964ccf1d3ca. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/37509ef29401d29e69288a7975f57e3787c5cb4122b95ae159078a396037f242.html] |||-112d957b— Twelfth confirmed sibling (gwwsite.nl.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade; 90,464-byte encrypted RCData in.rsrc. Unique GUIDead3cb61-5c13-4ced-8ae6-88a547e425c9. RijndaelManaged + DeflateStream decryption pipeline confirmed in strings. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/112d957b56a0ccec1e06defc317c8b7b169b6e74514d1a6f7bee8c2b32b080ae.html] |-96ddc5067— Nineteenth confirmed sibling (cash-win.nl.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade (cash-win.nl); 89,952-byte encrypted RCData in.rsrc. Unique GUID21b9771a-0ead-4a20-9584-91c88cd03202. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910.html]
|- b5bbf49b — Twentieth confirmed sibling (nega.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Bare filename with no social-engineering masquerade; 88,152-byte encrypted RCData in .rsrc. Unique GUID cce15acd-4387-46c9-8e17-643151fbfa1d. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/b5bbf49baec35490f473b8ab0b2933f1479fda2625fb30a4892455368bb1b499.html]
Capabilities
registry-run-persistencedotnet-reflective-assembly-loadingraw-tcp-c2-keepalivehost-cache-dynamic-updatepipe-based-plugin-ipcconfuserex-name-obfuscationresource-zip-encryptionfile-system-copy-deleteregistry-query-enumerationsystem-information-discoverymd5-hash-data-checkrijndael-deflate-resource-decryption
Related Entities / Techniques
-
confuserex-obfuscation — primary obfuscator observed.
-
smartassembly-obfuscation — alternative commercial .NET obfuscator seen with other families.
-
930b692d— Fourteenth confirmed sibling (jvegter.nl.exe), same Feb 2015 batch, ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade (jvegter.nl); 90,464-byte encrypted RCData in.rsrc. Unique GUID08186e7b-fc6a-4a22-832f-d29dc50a34fc. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/930b692df3835501f7c276763fbf80928fe64d808e8f1f52d8fe091a5e58ca56.html] -
36115e96— Fifteenth confirmed sibling (coffeeandsuch.nl.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade (coffeeandsuch.nl); 90,608-byte encrypted RCData in.rsrc. Unique GUID8dc51bf4-8f2c-404b-98a0-1d777ffdbc54. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/36115e96dd16090fa669229c36d861ac7cff249e5562a3a272e74db1b7da33e7.html] -
e4774281— Sixteenth confirmed sibling (aboddehousing.co.uk.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. UK housing-domain masquerade (aboddehousing.co.uk); ~90,464-byte encrypted RCData in.rsrc. Unique GUID15e065f2-6a0c-418b-8192-dc66272ecfda. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/e4774281b944c049949b4a2ad4ac3123aef31275be846ab026c2f005f8dbf9c1.html]
|- 38cac999 — Seventeenth confirmed sibling (nam.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Bare filename with no social-engineering masquerade; ~90,464-byte encrypted RCData in .rsrc. Unique GUID 47a89a76-c40c-4e5f-9273-94732e5f42cf. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/38cac999881944e48e997877535b8cc653bc2b441e8e7e8eaa5773207848df72.html]
||- b0daeb6a — Eighteenth confirmed sibling (schoenberg-ensemble.nl.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch classical-music domain masquerade; ~90,080-byte encrypted RCData in .rsrc. Unique GUID 7e3c957d-3516-4313-add2-1d2b57e0ca5f. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/b0daeb6a0db9c277f3cf9778d9bde3b6c85ccd96b2a95dfec7299bd611b42e11.html]
||- 4eed8d8f — Twenty-first confirmed sibling (sh4.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Bare three-character filename with no social-engineering masquerade; 90,176-byte encrypted RCData in .rsrc. Unique GUID a96b9d76-0029-412c-98b8-5276d49306fe. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/4eed8d8f0ee2f147dd5106c5d783085a3964b127f88f8e4a203896c40fb88e28.html]
|- 96ddc5067 — Nineteenth confirmed sibling (cash-win.nl.exe), same Feb 2015 batch (22 Feb 2015 00:49:37 UTC), ConfuserEx-obfuscated VB.NET client v1.2.2.0. Dutch domain masquerade (cash-win.nl); 89,952-byte encrypted RCData in .rsrc. Unique GUID 21b9771a-0ead-4a20-9584-91c88cd03202. RijndaelManaged + DeflateStream decryption pipeline confirmed. No hardcoded C2. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/96ddc50677b32d42f224a09f7c436924502c8accaf2c5af2aa9706bbc1ae6910.html]