02da37c3491fe7de822724a98738563f905ad0fddf2a11abb347946af9631496moonshine-aot-loader: 02da37c3 — Purchase-order lure, Moonshine.Core Native AOT, .gfx encrypted payload
Executive Summary
A .NET Native AOT compiled x64 PE using a custom runtime framework (Moonshine.Core) and masquerading as "Aether Sync Agent" by "Aether Dynamics Corp." Distributed as PO-20260527.exe (purchase-order social-engineering lure). The binary carries a high-entropy .gfx section (entropy 7.999) that serves as an encrypted payload container — the threat logic is not in the PE code sections but in this encrypted overlay. Static-only analysis; no CAPE detonation available. First confirmed sibling in a cluster of at least eight Moonshine.Core samples in this corpus.
What It Is
- SHA-256:
02da37c3491fe7de822724a98738563f905ad0fddf2a11abb347946af9631496 - Filename:
PO-20260527.exe^[metadata.json] - Size: 1,054,208 bytes (1.0 MB) ^[metadata.json]
- File type: PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
- Timestamp: Tue May 26 12:57:45 2026 UTC ^[pefile.txt:48]
- Linker: MSVC 14.50 (Visual Studio 2022 v143) ^[exiftool.json]
- COM_DESCRIPTOR: 0x0 — no CLR metadata; Native AOT compiled ^[pefile.txt:277]
- Internal name:
aethsync.exe/aethsync.dll^[strings.txt:2238] - Version info masquerade: "Aether Sync Agent" v4.1.0.0 by "Aether Dynamics Corp." ^[pefile.txt:327-336]
- OpenCTI labels:
exe,exe-in-archive,malware-bazaar,spamtrap^[metadata.json] - Signing: Unsigned ^[rabin2-info.txt:27]
How It Works
The binary is a .NET Native AOT compiled executable using a custom framework called Moonshine.Core. Native AOT strips all CLR metadata, rendering the binary opaque to dnSpy, ILSpy, and conventional .NET analysis tools. ^[sample 02da37c3/strings.txt:1239-1247]
The threat logic is not in the .text section but in a dedicated .gfx section:
- Section name:
.gfx^[pefile.txt:213] - Virtual size: 0x45649 (284,233 bytes) ^[pefile.txt:214]
- Raw size: 0x45800 ^[pefile.txt:218]
- Entropy: 7.999 (maximum randomness) ^[pefile.txt:226]
- Characteristics:
IMAGE_SCN_CNT_INITIALIZED_DATA | IMAGE_SCN_MEM_READonly — not executable ^[pefile.txt:224]
The .gfx section is decrypted at runtime and executed. The low import count and absence of network APIs in the IAT suggest the payload is either:
- A second-stage downloader that resolves C2 at runtime, or
- A fully self-contained RAT/stealer whose C2 is embedded in the encrypted
.gfxblob.
The import surface includes process/thread manipulation APIs (CreateThread, SuspendThread, ResumeThread, GetThreadContext, SetThreadContext) and token privilege APIs (OpenProcessToken, AdjustTokenPrivileges), consistent with process injection or hollowing. ^[pefile.txt:355-484]
Decompiled Behavior
Ghidra and radare2 both struggle with the 2,988 functions produced by Native AOT inlining. No capa analysis was available (signature path error). No floss output (command-line error). The binary has no meaningful exports and no delay imports. ^[rabin2-info.txt]
Radare2 analysis at level 2 found 2,988 functions, most unnamed, with heavy inlining of BCL runtime code. The entry point at 0x1400817BC initiates the Native AOT runtime bootstrap (Internal.Runtime.TypeLoader, System.Private.CoreLib). The actual malicious behavior is deferred to the .gfx decryption stub, which is not recoverable statically without the key. ^[rabin2-info.txt:23]
No decompiled function references to network, crypto, or persistence APIs were recoverable from the .text section alone.
C2 Infrastructure
No static C2 recovered. No URLs, IPs, domains, mutex names, named pipes, or registry keys were found in strings or imports. The C2 (if any) is either:
- Embedded in the encrypted
.gfxpayload and resolved at runtime, or - Absent because this is a loader that fetches a second stage via
System.Net.Http(compiled into the AOT runtime, not visible in the IAT).
The presence of System.Net.Http.EnableActivityPropagation and System.Net.SocketsHttpHandler.Http3Support strings confirms System.Net.Http is compiled into the binary. ^[strings.txt:1464-1465]
Interesting Tidbits
- Custom AOT runtime:
Moonshine.Coreis not a known open-source framework. It appears to be a private/custom Native AOT runtime built on top of .NET'sSystem.Private.CoreLib. The namespaceMoonshine{and classMoonshine.Coreare unique identifiers. ^[strings.txt:1239-1247] - Eight confirmed siblings in this corpus share the
Moonshine.Corefingerprint, spanning filenames likePO-20260527.exe,yea8hw1uN1NGD0za.exe,qwe-23wq-e.exe,Bonifico n.1101252230290346.docx.exe, andzira-miszsn.exe. ^[corpus cross-reference] - Purchase-order lure: The filename
PO-20260527.exefollows the standard social-engineering pattern targeting finance/procurement employees. ^[metadata.json] - No icon resources: The
.rsrcsection is only 0xB46 bytes and contains only RT_VERSION and RT_MANIFEST — no icons, no BITMAP carriers, no encrypted RCData. This is minimal-resource staging. ^[pefile.txt:173-190] - TLS directory present: A TLS callback array exists at
0x1400A2680(size 0x28). In Native AOT this is typically used for thread-local storage initialization, but it is also a known anti-analysis vector. ^[pefile.txt:675-681] - Build freshness: Compiled May 26 2026, submitted to MalwareBazaar May 27 2026 — less than 24 hours old at collection. ^[metadata.json]
How To Mess With It (Homelab Replication)
- Toolchain: .NET 8+ SDK with
PublishAot=true, RIDwin-x64, MSVC 14.50 linker. - Custom runtime: Build a minimal Native AOT executable that embeds an encrypted payload in a custom PE section (e.g.,
.gfx). - Decryption stub: At entry, read the custom section, decrypt with AES-256-GCM (key derived from
BCryptGenRandom+ env var), and reflectively execute. - Masquerade: Populate VS_VERSIONINFO with a plausible software company name and product.
- Verification: Run
rabin2 -Ion the reproducer and confirmCOM_DESCRIPTORis 0x0,langisc, andsignedisfalse.
Deployable Signatures
YARA Rule
rule moonshine_aot_loader {
meta:
description = "Moonshine.Core Native AOT loader with .gfx encrypted payload"
author = "PacketPursuit"
date = "2026-08-07"
sha256 = "02da37c3491fe7de822724a98738563f905ad0fddf2a11abb347946af9631496"
strings:
$moonshine_core = "Moonshine.Core" ascii wide
$aethsync = "aethsync" ascii wide
$moonshine_ns = "Moonshine{" ascii wide
$spc = "System.Private.CoreLib" ascii wide
$spre = "System.Private.Reflection.Execution" ascii wide
$sptl = "System.Private.TypeLoader" ascii wide
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections == 7 and
pe.section_index(".gfx") >= 0 and
3 of ($moonshine_core, $aethsync, $moonshine_ns) and
2 of ($spc, $spre, $sptl)
}
Behavioral Hunt Query (Sigma-style pseudocode)
title: Moonshine AOT Loader Execution
detection:
selection:
- Image|endswith: 'aethsync.exe'
- CommandLine|contains: 'PO-2026'
- PE_SectionName: '.gfx'
- Imphash|contains: 'low-iat-native-aot'
condition: selection
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 02da37c3491fe7de822724a98738563f905ad0fddf2a11abb347946af9631496 |
Hash |
| Filename | PO-20260527.exe |
Filename |
| Internal name | aethsync.exe / aethsync.dll |
String |
| CompanyName | Aether Dynamics Corp. |
Version info |
| ProductName | Aether Sync Agent |
Version info |
| Section name | .gfx |
PE section |
| Compile time | 2026-05-26 12:57:45 UTC |
Timestamp |
Behavioral Fingerprint
This binary is a .NET Native AOT compiled PE with no CLR metadata, a minimal .rsrc section containing only version and manifest data, and a large high-entropy .gfx section (entropy ~8.0) that is decrypted at runtime. It imports process/thread manipulation APIs (CreateThread, SuspendThread, ResumeThread, GetThreadContext, SetThreadContext) and token privilege APIs (OpenProcessToken, AdjustTokenPrivileges) but has no visible network imports in the IAT. The System.Net.Http stack is compiled into the AOT runtime. The version info masquerades as "Aether Sync Agent" by "Aether Dynamics Corp." The filename follows a purchase-order social-engineering pattern (PO-YYYYMMDD.exe).
Detection Signatures
- Mandiant capa: Not available (signature path error during triage). ^[capa.txt]
- MITRE ATT&CK (inferred from static):
- T1055 — Process Injection (CreateThread, SuspendThread, ResumeThread, GetThreadContext, SetThreadContext imports)
- T1134 — Access Token Manipulation (OpenProcessToken, AdjustTokenPrivileges)
- T1027.002 — Obfuscated Files or Information: Software Packing (Native AOT + encrypted
.gfxsection) - T1036.005 — Masquerading: Match Legitimate Name or Location ("Aether Sync Agent" version info)
- T1564.003 — Hide Artifacts: Hidden Window (Windows GUI subsystem)
References
- moonshine-aot-loader — family entity page
- dotnet-native-aot-rat-compilation — technique deep-dive on Native AOT as anti-analysis
- version-info-masquerade — version-info fabrication pattern
- social-engineering-purchase-order-masquerade — purchase-order lure pattern
- unclassified-dotnet-native-aot-loader — umbrella entity for generic Native AOT samples
Provenance
file.txt—filev5.44exiftool.json— ExifTool v12.76pefile.txt— pefile (Python) lateststrings.txt—stringsfrom binutilsrabin2-info.txt— radare2 v5.9.8binwalk.txt— binwalk v2.3.4capa.txt— capa v7.4.0 (signature path error)floss.txt— flare-floss v3.1.1 (command-line error)dynamic-analysis.md— CAPE skipped (no Windows guest)- Radare2 analysis level 2, 2988 functions recovered