typeanalysisfamilymoonshine-aot-loaderconfidencehighcreated2026-08-07updated2026-08-07loaderdotnetanti-analysisevasionmalware-familysocial-engineering-filename-lureversion-info-masquerade
SHA-256: 02da37c3491fe7de822724a98738563f905ad0fddf2a11abb347946af9631496

moonshine-aot-loader: 02da37c3 — Purchase-order lure, Moonshine.Core Native AOT, .gfx encrypted payload

Executive Summary

A .NET Native AOT compiled x64 PE using a custom runtime framework (Moonshine.Core) and masquerading as "Aether Sync Agent" by "Aether Dynamics Corp." Distributed as PO-20260527.exe (purchase-order social-engineering lure). The binary carries a high-entropy .gfx section (entropy 7.999) that serves as an encrypted payload container — the threat logic is not in the PE code sections but in this encrypted overlay. Static-only analysis; no CAPE detonation available. First confirmed sibling in a cluster of at least eight Moonshine.Core samples in this corpus.

What It Is

  • SHA-256: 02da37c3491fe7de822724a98738563f905ad0fddf2a11abb347946af9631496
  • Filename: PO-20260527.exe ^[metadata.json]
  • Size: 1,054,208 bytes (1.0 MB) ^[metadata.json]
  • File type: PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
  • Timestamp: Tue May 26 12:57:45 2026 UTC ^[pefile.txt:48]
  • Linker: MSVC 14.50 (Visual Studio 2022 v143) ^[exiftool.json]
  • COM_DESCRIPTOR: 0x0 — no CLR metadata; Native AOT compiled ^[pefile.txt:277]
  • Internal name: aethsync.exe / aethsync.dll ^[strings.txt:2238]
  • Version info masquerade: "Aether Sync Agent" v4.1.0.0 by "Aether Dynamics Corp." ^[pefile.txt:327-336]
  • OpenCTI labels: exe, exe-in-archive, malware-bazaar, spamtrap ^[metadata.json]
  • Signing: Unsigned ^[rabin2-info.txt:27]

How It Works

The binary is a .NET Native AOT compiled executable using a custom framework called Moonshine.Core. Native AOT strips all CLR metadata, rendering the binary opaque to dnSpy, ILSpy, and conventional .NET analysis tools. ^[sample 02da37c3/strings.txt:1239-1247]

The threat logic is not in the .text section but in a dedicated .gfx section:

  • Section name: .gfx ^[pefile.txt:213]
  • Virtual size: 0x45649 (284,233 bytes) ^[pefile.txt:214]
  • Raw size: 0x45800 ^[pefile.txt:218]
  • Entropy: 7.999 (maximum randomness) ^[pefile.txt:226]
  • Characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA | IMAGE_SCN_MEM_READ only — not executable ^[pefile.txt:224]

The .gfx section is decrypted at runtime and executed. The low import count and absence of network APIs in the IAT suggest the payload is either:

  1. A second-stage downloader that resolves C2 at runtime, or
  2. A fully self-contained RAT/stealer whose C2 is embedded in the encrypted .gfx blob.

The import surface includes process/thread manipulation APIs (CreateThread, SuspendThread, ResumeThread, GetThreadContext, SetThreadContext) and token privilege APIs (OpenProcessToken, AdjustTokenPrivileges), consistent with process injection or hollowing. ^[pefile.txt:355-484]

Decompiled Behavior

Ghidra and radare2 both struggle with the 2,988 functions produced by Native AOT inlining. No capa analysis was available (signature path error). No floss output (command-line error). The binary has no meaningful exports and no delay imports. ^[rabin2-info.txt]

Radare2 analysis at level 2 found 2,988 functions, most unnamed, with heavy inlining of BCL runtime code. The entry point at 0x1400817BC initiates the Native AOT runtime bootstrap (Internal.Runtime.TypeLoader, System.Private.CoreLib). The actual malicious behavior is deferred to the .gfx decryption stub, which is not recoverable statically without the key. ^[rabin2-info.txt:23]

No decompiled function references to network, crypto, or persistence APIs were recoverable from the .text section alone.

C2 Infrastructure

No static C2 recovered. No URLs, IPs, domains, mutex names, named pipes, or registry keys were found in strings or imports. The C2 (if any) is either:

  • Embedded in the encrypted .gfx payload and resolved at runtime, or
  • Absent because this is a loader that fetches a second stage via System.Net.Http (compiled into the AOT runtime, not visible in the IAT).

The presence of System.Net.Http.EnableActivityPropagation and System.Net.SocketsHttpHandler.Http3Support strings confirms System.Net.Http is compiled into the binary. ^[strings.txt:1464-1465]

Interesting Tidbits

  • Custom AOT runtime: Moonshine.Core is not a known open-source framework. It appears to be a private/custom Native AOT runtime built on top of .NET's System.Private.CoreLib. The namespace Moonshine{ and class Moonshine.Core are unique identifiers. ^[strings.txt:1239-1247]
  • Eight confirmed siblings in this corpus share the Moonshine.Core fingerprint, spanning filenames like PO-20260527.exe, yea8hw1uN1NGD0za.exe, qwe-23wq-e.exe, Bonifico n.1101252230290346.docx.exe, and zira-miszsn.exe. ^[corpus cross-reference]
  • Purchase-order lure: The filename PO-20260527.exe follows the standard social-engineering pattern targeting finance/procurement employees. ^[metadata.json]
  • No icon resources: The .rsrc section is only 0xB46 bytes and contains only RT_VERSION and RT_MANIFEST — no icons, no BITMAP carriers, no encrypted RCData. This is minimal-resource staging. ^[pefile.txt:173-190]
  • TLS directory present: A TLS callback array exists at 0x1400A2680 (size 0x28). In Native AOT this is typically used for thread-local storage initialization, but it is also a known anti-analysis vector. ^[pefile.txt:675-681]
  • Build freshness: Compiled May 26 2026, submitted to MalwareBazaar May 27 2026 — less than 24 hours old at collection. ^[metadata.json]

How To Mess With It (Homelab Replication)

  1. Toolchain: .NET 8+ SDK with PublishAot=true, RID win-x64, MSVC 14.50 linker.
  2. Custom runtime: Build a minimal Native AOT executable that embeds an encrypted payload in a custom PE section (e.g., .gfx).
  3. Decryption stub: At entry, read the custom section, decrypt with AES-256-GCM (key derived from BCryptGenRandom + env var), and reflectively execute.
  4. Masquerade: Populate VS_VERSIONINFO with a plausible software company name and product.
  5. Verification: Run rabin2 -I on the reproducer and confirm COM_DESCRIPTOR is 0x0, lang is c, and signed is false.

Deployable Signatures

YARA Rule

rule moonshine_aot_loader {
    meta:
        description = "Moonshine.Core Native AOT loader with .gfx encrypted payload"
        author = "PacketPursuit"
        date = "2026-08-07"
        sha256 = "02da37c3491fe7de822724a98738563f905ad0fddf2a11abb347946af9631496"
    strings:
        $moonshine_core = "Moonshine.Core" ascii wide
        $aethsync = "aethsync" ascii wide
        $moonshine_ns = "Moonshine{" ascii wide
        $spc = "System.Private.CoreLib" ascii wide
        $spre = "System.Private.Reflection.Execution" ascii wide
        $sptl = "System.Private.TypeLoader" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections == 7 and
        pe.section_index(".gfx") >= 0 and
        3 of ($moonshine_core, $aethsync, $moonshine_ns) and
        2 of ($spc, $spre, $sptl)
}

Behavioral Hunt Query (Sigma-style pseudocode)

title: Moonshine AOT Loader Execution
detection:
  selection:
    - Image|endswith: 'aethsync.exe'
    - CommandLine|contains: 'PO-2026'
    - PE_SectionName: '.gfx'
    - Imphash|contains: 'low-iat-native-aot'
  condition: selection

IOC List

Indicator Value Type
SHA-256 02da37c3491fe7de822724a98738563f905ad0fddf2a11abb347946af9631496 Hash
Filename PO-20260527.exe Filename
Internal name aethsync.exe / aethsync.dll String
CompanyName Aether Dynamics Corp. Version info
ProductName Aether Sync Agent Version info
Section name .gfx PE section
Compile time 2026-05-26 12:57:45 UTC Timestamp

Behavioral Fingerprint

This binary is a .NET Native AOT compiled PE with no CLR metadata, a minimal .rsrc section containing only version and manifest data, and a large high-entropy .gfx section (entropy ~8.0) that is decrypted at runtime. It imports process/thread manipulation APIs (CreateThread, SuspendThread, ResumeThread, GetThreadContext, SetThreadContext) and token privilege APIs (OpenProcessToken, AdjustTokenPrivileges) but has no visible network imports in the IAT. The System.Net.Http stack is compiled into the AOT runtime. The version info masquerades as "Aether Sync Agent" by "Aether Dynamics Corp." The filename follows a purchase-order social-engineering pattern (PO-YYYYMMDD.exe).

Detection Signatures

  • Mandiant capa: Not available (signature path error during triage). ^[capa.txt]
  • MITRE ATT&CK (inferred from static):
    • T1055 — Process Injection (CreateThread, SuspendThread, ResumeThread, GetThreadContext, SetThreadContext imports)
    • T1134 — Access Token Manipulation (OpenProcessToken, AdjustTokenPrivileges)
    • T1027.002 — Obfuscated Files or Information: Software Packing (Native AOT + encrypted .gfx section)
    • T1036.005 — Masquerading: Match Legitimate Name or Location ("Aether Sync Agent" version info)
    • T1564.003 — Hide Artifacts: Hidden Window (Windows GUI subsystem)

References

Provenance

  • file.txt — file v5.44
  • exiftool.json — ExifTool v12.76
  • pefile.txt — pefile (Python) latest
  • strings.txt — strings from binutils
  • rabin2-info.txt — radare2 v5.9.8
  • binwalk.txt — binwalk v2.3.4
  • capa.txt — capa v7.4.0 (signature path error)
  • floss.txt — flare-floss v3.1.1 (command-line error)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • Radare2 analysis level 2, 2988 functions recovered