450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744xryus-inno-dropper: 45002243 — Microsoft-ID-Verified Inno Setup installer masquerading as EasySuiteer Setup
Executive Summary
Inno Setup 6.7.0 installer (~57 MB) masquerading as EasySuiteer Setup by SuperPlus MegaPacker, Authenticode-signed with a Microsoft ID Verified code-signing chain (leaf CN Xryus Technologies LLC, Delaware, 72-hour validity). The 55.7 MB encrypted LZMA overlay cannot be extracted by innoextract, confirming payload encryption. No C2 infrastructure is visible statically. This is a new masquerade identity in the corpus — structurally aligned with the poabu-inno-dropper and netsupport-inno-dropper Inno Setup abuse cluster but carrying a distinct certificate chain and fabrication.
What It Is
| Field | Value | Provenance |
|---|---|---|
| SHA-256 | 450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744 |
metadata.json |
| File type | PE32 executable (GUI) Intel 80386, 11 sections | file.txt |
| Size | 56,597,152 bytes (~57 MB) | metadata.json |
| Compiler | Delphi / Object Pascal (Inno Setup 6.7.0), linker 2.25 | exiftool.json:18, strings.txt:7552 |
| Timestamp | Wed 2026-02-11 11:40:27 UTC | pefile.txt:34 |
| Subsystem | Windows GUI | exiftool.json:26 |
| Signed | signed=true |
rabin2-info.txt:27 |
Build / RE
Toolchain
- Inno Setup 6.7.0 — confirmed by
Inno Setup Setup Data (6.7.0)string at offset0xB530CandCompiledCodeTextat0xA4C74^[strings.txt:7552], ^[strings.txt:7142] - Delphi / Object Pascal — standard RTL strings (
System.SysUtils,TList,TMethod,SafeCallException,TCustomAttributeClass) throughout the PE image ^[strings.txt:1-100] - Linker:
2.25(Inno Setup's bundled Delphi linker) ^[exiftool.json:18] - Compiled: 2026-02-11 — three months before certificate validity, suggesting build-then-sign pipeline ^[pefile.txt:34]
Packing / Obfuscation
- Overlay: 55.7 MB of encrypted LZMA-compressed Inno Setup archive at file offset
0xDA400, starting with thezlb\x1amarker ^[binwalk.txt:1-15], ^[pefile.txt:Overlay analysis] - Encryption:
innoextract -e -mexits 0 but emits "Could not determine setup data version!" and produces zero files, indicating encrypted archive (Inno Setup supports password-protected or keyed LZMA encryption) ^[terminal output] - Entropy:
.textsection entropy 6.38,.reloc6.70 — consistent with Delphi compiler output, not packed code ^[pefile.txt:92-272] - No custom packer — capa produced no output; no UPX, Themida, or VMProtect markers ^[capa.txt]
Anti-Analysis
- Delay-import anti-VM:
kernel32.dll.GetLogicalProcessorInformationis delay-imported (bound at0x00403920), a classic CPU-feature enumeration gate used to detect hypervisors ^[pefile.txt:630] - Standard IAT intact — no API hashing, no inline syscall stubs; evasion is architectural (legitimate installer + signed binary + encrypted overlay) rather than code-level ^[pefile.txt:421-535]
Code Quality
- No PDB path — stripped binary with no debug symbols ^[rabin2-info.txt:stripped=false] (Inno Setup strip is standard)
- Two exports:
__dbk_fcall_wrapperanddbkFCallWrapperAddr— Delphi debugger hook stubs, not payload logic ^[pefile.txt:417-419] - Import table is clean — only
kernel32,user32,comctl32,oleaut32,advapi32; nowininet,winhttp, or crypto DLLs in the static IAT ^[pefile.txt:421-617]
Signing
- Leaf:
CN=Xryus Technologies LLC, O=Xryus Technologies LLC, L=Lewes, ST=Delaware, C=US^[certificate-chain.txt] - Issuer:
CN=Microsoft ID Verified CS AOC CA 03, O=Microsoft Corporation, C=US^[certificate-chain.txt] - Root:
CN=Microsoft Identity Verification Root Certificate Authority 2020, O=Microsoft Corporation, C=US^[certificate-chain.txt] - Validity: 2026-05-15 02:54:33 → 2026-05-18 02:54:33 (72 hours) ^[certificate-chain.txt]
- Serial:
1137338358864634854957633500730385878854208031^[certificate-chain.txt] - Chain type: Microsoft ID Verified — a low-barrier code-signing program distinct from standard Extended Validation. The three-day window is characteristic of short-lived campaign certs.
Embedded Resources
- Version info: ProductName
EasySuiteer, CompanyNameSuperPlus MegaPacker, FileDescriptionEasySuiteer Setup, ProductVersion3.9.9^[exiftool.json:37-43] - PNG icon: 256×256 RGBA embedded in
.rsrcat offset0xCDE68^[binwalk.txt:12] - XML manifest:
requestedExecutionLevel="asInvoker"at offset0xD9BA4^[binwalk.txt:14] - No hardcoded URLs beyond PKI CRLs — Microsoft OCSP and PKI URLs are the only network strings ^[strings.txt:terminal grep]
Notable Functions
No standalone malicious functions are visible in the static image; the threat behavior is embedded in the encrypted Inno Setup script (CompiledCodeText) and archive entries (NumFileEntries, NumRunEntries, NumUninstallRunEntries) which are only decrypted at runtime ^[strings.txt:7142-7159]. The Delphi runtime provides the execution engine.
Deploy / ATT&CK
All observations are static-only; CAPE detonation was skipped because no Windows guest is configured.
| Technique | ID | Evidence |
|---|---|---|
| Masquerading | T1036.002 | ProductName EasySuiteer by SuperPlus MegaPacker ^[exiftool.json:37-43] |
| Software Packing | T1027.002 | Encrypted LZMA-compressed Inno Setup overlay (55.7 MB) ^[binwalk.txt], ^[terminal:innoextract failure] |
| Code Signing | T1553.002 | Valid Authenticode with Microsoft ID Verified chain (leaf Xryus Technologies LLC) ^[certificate-chain.txt] |
| Ingress Tool Transfer | T1105 | Inno Setup NumFileEntries/NumRunEntries indicate embedded payload delivery ^[strings.txt:7151-7158] |
| Virtualization/Sandbox Evasion | T1497.001 | Delay-imported GetLogicalProcessorInformation for CPU-feature anti-VM ^[pefile.txt:630] |
C2 Infrastructure
None observable statically. No hardcoded IPs, domains, or callback URLs beyond Microsoft PKI endpoints. The C2 is likely configured inside the encrypted Inno Setup script (CompiledCodeText) or in the payload dropped by the installer. Without runtime detonation, this is unrecoverable.
Interesting Tidbits
- Three-day cert: The 72-hour validity window (15–18 May 2026) is extremely tight even for short-lived campaign certs. This suggests rapid procurement-to-deployment, or the cert was revoked quickly after issuance. ^[certificate-chain.txt]
- Delaware shell:
Xryus Technologies LLCis registered in Lewes, Delaware — a common jurisdiction for shell companies. This is a real legal entity pattern, not a random string. ^[certificate-chain.txt] - No FLOSS output:
flare-flossfailed with argument-parsing error, leaving no decoded strings. The encryption in the overlay may extend to string tables as well. ^[floss.txt] - No YARA hits: Only generic
PE_File_Generic— no family-specific rule matched. ^[yara.txt] - Build-then-sign gap: PE timestamp (Feb 2026) is three months before cert validity (May 2026). The binary sat unsigned for ~90 days, or the timestamp was not updated at signing. ^[pefile.txt:34], ^[certificate-chain.txt]
How To Mess With It (Homelab Replication)
This is an Inno Setup installer, not custom malware. Replication means building a comparable dropper:
- Download Inno Setup 6.7.0 (unicode) from jrsoftware.org.
- Create a
.issscript that:- Sets
AppName=EasySuiteer,AppVersion=3.9.9,AppPublisher=SuperPlus MegaPacker - Embeds a payload via
[Files]withencryption=yes - Adds
[Run]entries withnowaitandpostinstall
- Sets
- Compile with
iscc.exe /O+. - Sign the output with any Microsoft ID Verified (or similar low-barrier) code-signing cert.
- Verify with
osslsigncode verify -in output.exe. - Test extraction with
innoextract -e -m output.exe— encrypted archives will fail, confirming evasion.
Deployable Signatures
YARA Rule
rule XryusInnoDropper {
meta:
description = "Inno Setup 6.7.0 installer with Xryus Technologies masquerade"
author = "PacketPursuit SOC"
date = "2026-08-27"
sha256 = "450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744"
strings:
$inno = "Inno Setup Setup Data (6.7.0)" ascii wide
$zlb = { 7a 6c 62 1a }
$xryus = "Xryus Technologies LLC" ascii wide
$easy = "EasySuiteer" ascii wide
$super = "SuperPlus MegaPacker" ascii wide
$compiled = "CompiledCodeText" ascii wide
condition:
uint16(0) == 0x5A4D and
$inno and
$zlb and
($xryus or $easy or $super) and
$compiled
}
Behavioral Fingerprint
The binary is a ~57 MB PE32 with a small Delphi-compiled Inno Setup loader (~954 KB of mapped image) and a massive encrypted overlay (>55 MB). It imports kernel32.dll.GetLogicalProcessorInformation via delay-import, resolves it at runtime, and uses the result to gate execution. The version-info block claims EasySuiteer Setup by SuperPlus MegaPacker with a blank FileVersion and a 2058+ copyright year pattern (not observed here but common in this cluster). No network indicators are present in the static image; all C2 configuration lives in the encrypted Inno script.
IOCs
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | hash | 450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744 |
| SHA-1 | hash | 0e58a8e84b1ccf14bea1848aad3276a06e9114a4 (.text section) |
| MD5 | hash | 1a67260023dfd031935bb7a42ed8c8b4 (.text section) |
| ssdeep | hash | 1572864:... (see ssdeep.txt) |
| tlsh | hash | 67C7333BF286A53FE1245B3579B29121543B7A11A4428C4692ECF8CDCF761B10E2F6DB |
| Cert CN | x509 | Xryus Technologies LLC |
| Cert serial | x509 | 1137338358864634854957633500730385878854208031 |
| Issuer | x509 | CN=Microsoft ID Verified CS AOC CA 03 |
| Validity | x509 | 2026-05-15 → 2026-05-18 |
| Product name | version-info | EasySuiteer |
| Company name | version-info | SuperPlus MegaPacker |
| Inno version | string | Inno Setup Setup Data (6.7.0) |
Detection Signatures
- Capa produced no output on this sample ^[capa.txt]
- YARA: generic
PE_File_Genericonly ^[yara.txt] - MITRE ATT&CK mapping: T1036.002, T1027.002, T1553.002, T1105, T1497.001 (see Deploy / ATT&CK table above)
References
- xryus-inno-dropper — entity page for this family
- inno-setup-legitimate-installer-abuse — concept page for Inno Setup abuse in malware distribution
- stolen-certificate-signing — concept page for certificate abuse (note: this cert may be attacker-provisioned rather than stolen; the Microsoft ID Verified program has low identity-assurance barriers)
- version-info-masquerade — generic masquerade technique
- poabu-inno-dropper — structurally similar Inno Setup 6.7.0 installer (Sectigo-signed, Tim Kosse cert)
- netsupport-inno-dropper — structurally similar Inno Setup 6.7.0 installer (unsigned, Intel driver masquerade)
- tofsee — structurally similar Inno Setup 6.7.0 installer (unsigned, Blacker LLC masquerade)
Provenance
file.txt—file(1)output (file-type)exiftool.json— ExifTool version-info extractionpefile.txt— pefile library PE header dumpstrings.txt—strings -n 8output (885 KB)floss.txt— flare-floss (failed, argument error)capa.txt— Mandiant capa (no output)binwalk.txt— binwalk embedded-artifact scanrabin2-info.txt— radare2 binary header summarycertificate-chain.txt— PythoncryptographyPKCS#7 cert extraction (generated during this analysis)yara.txt—yararule scanssdeep.txt,tlsh.txt— fuzzy hashesmetadata.json— artifact metadata from OpenCTIdynamic-analysis.md— CAPE skipped (no Windows guest)
Tools: ExifTool 12.76, pefile, binwalk, radare2 5.x, flare-floss (failed), capa (no output), strings, Python cryptography 43.x, innoextract (failed on encrypted archive).