typeanalysisfamilyxryus-inno-dropperconfidencelowmalware-familyloaderpeinstallerevasionsigningmasquerading
SHA-256: 450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744

xryus-inno-dropper: 45002243 — Microsoft-ID-Verified Inno Setup installer masquerading as EasySuiteer Setup

Executive Summary

Inno Setup 6.7.0 installer (~57 MB) masquerading as EasySuiteer Setup by SuperPlus MegaPacker, Authenticode-signed with a Microsoft ID Verified code-signing chain (leaf CN Xryus Technologies LLC, Delaware, 72-hour validity). The 55.7 MB encrypted LZMA overlay cannot be extracted by innoextract, confirming payload encryption. No C2 infrastructure is visible statically. This is a new masquerade identity in the corpus — structurally aligned with the poabu-inno-dropper and netsupport-inno-dropper Inno Setup abuse cluster but carrying a distinct certificate chain and fabrication.

What It Is

Field Value Provenance
SHA-256 450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744 metadata.json
File type PE32 executable (GUI) Intel 80386, 11 sections file.txt
Size 56,597,152 bytes (~57 MB) metadata.json
Compiler Delphi / Object Pascal (Inno Setup 6.7.0), linker 2.25 exiftool.json:18, strings.txt:7552
Timestamp Wed 2026-02-11 11:40:27 UTC pefile.txt:34
Subsystem Windows GUI exiftool.json:26
Signed signed=true rabin2-info.txt:27

Build / RE

Toolchain

  • Inno Setup 6.7.0 — confirmed by Inno Setup Setup Data (6.7.0) string at offset 0xB530C and CompiledCodeText at 0xA4C74 ^[strings.txt:7552], ^[strings.txt:7142]
  • Delphi / Object Pascal — standard RTL strings (System.SysUtils, TList, TMethod, SafeCallException, TCustomAttributeClass) throughout the PE image ^[strings.txt:1-100]
  • Linker: 2.25 (Inno Setup's bundled Delphi linker) ^[exiftool.json:18]
  • Compiled: 2026-02-11 — three months before certificate validity, suggesting build-then-sign pipeline ^[pefile.txt:34]

Packing / Obfuscation

  • Overlay: 55.7 MB of encrypted LZMA-compressed Inno Setup archive at file offset 0xDA400, starting with the zlb\x1a marker ^[binwalk.txt:1-15], ^[pefile.txt:Overlay analysis]
  • Encryption: innoextract -e -m exits 0 but emits "Could not determine setup data version!" and produces zero files, indicating encrypted archive (Inno Setup supports password-protected or keyed LZMA encryption) ^[terminal output]
  • Entropy: .text section entropy 6.38, .reloc 6.70 — consistent with Delphi compiler output, not packed code ^[pefile.txt:92-272]
  • No custom packer — capa produced no output; no UPX, Themida, or VMProtect markers ^[capa.txt]

Anti-Analysis

  • Delay-import anti-VM: kernel32.dll.GetLogicalProcessorInformation is delay-imported (bound at 0x00403920), a classic CPU-feature enumeration gate used to detect hypervisors ^[pefile.txt:630]
  • Standard IAT intact — no API hashing, no inline syscall stubs; evasion is architectural (legitimate installer + signed binary + encrypted overlay) rather than code-level ^[pefile.txt:421-535]

Code Quality

  • No PDB path — stripped binary with no debug symbols ^[rabin2-info.txt:stripped=false] (Inno Setup strip is standard)
  • Two exports: __dbk_fcall_wrapper and dbkFCallWrapperAddr — Delphi debugger hook stubs, not payload logic ^[pefile.txt:417-419]
  • Import table is clean — only kernel32, user32, comctl32, oleaut32, advapi32; no wininet, winhttp, or crypto DLLs in the static IAT ^[pefile.txt:421-617]

Signing

  • Leaf: CN=Xryus Technologies LLC, O=Xryus Technologies LLC, L=Lewes, ST=Delaware, C=US ^[certificate-chain.txt]
  • Issuer: CN=Microsoft ID Verified CS AOC CA 03, O=Microsoft Corporation, C=US ^[certificate-chain.txt]
  • Root: CN=Microsoft Identity Verification Root Certificate Authority 2020, O=Microsoft Corporation, C=US ^[certificate-chain.txt]
  • Validity: 2026-05-15 02:54:33 → 2026-05-18 02:54:33 (72 hours) ^[certificate-chain.txt]
  • Serial: 1137338358864634854957633500730385878854208031 ^[certificate-chain.txt]
  • Chain type: Microsoft ID Verified — a low-barrier code-signing program distinct from standard Extended Validation. The three-day window is characteristic of short-lived campaign certs.

Embedded Resources

  • Version info: ProductName EasySuiteer, CompanyName SuperPlus MegaPacker, FileDescription EasySuiteer Setup, ProductVersion 3.9.9 ^[exiftool.json:37-43]
  • PNG icon: 256×256 RGBA embedded in .rsrc at offset 0xCDE68 ^[binwalk.txt:12]
  • XML manifest: requestedExecutionLevel="asInvoker" at offset 0xD9BA4 ^[binwalk.txt:14]
  • No hardcoded URLs beyond PKI CRLs — Microsoft OCSP and PKI URLs are the only network strings ^[strings.txt:terminal grep]

Notable Functions

No standalone malicious functions are visible in the static image; the threat behavior is embedded in the encrypted Inno Setup script (CompiledCodeText) and archive entries (NumFileEntries, NumRunEntries, NumUninstallRunEntries) which are only decrypted at runtime ^[strings.txt:7142-7159]. The Delphi runtime provides the execution engine.

Deploy / ATT&CK

All observations are static-only; CAPE detonation was skipped because no Windows guest is configured.

Technique ID Evidence
Masquerading T1036.002 ProductName EasySuiteer by SuperPlus MegaPacker ^[exiftool.json:37-43]
Software Packing T1027.002 Encrypted LZMA-compressed Inno Setup overlay (55.7 MB) ^[binwalk.txt], ^[terminal:innoextract failure]
Code Signing T1553.002 Valid Authenticode with Microsoft ID Verified chain (leaf Xryus Technologies LLC) ^[certificate-chain.txt]
Ingress Tool Transfer T1105 Inno Setup NumFileEntries/NumRunEntries indicate embedded payload delivery ^[strings.txt:7151-7158]
Virtualization/Sandbox Evasion T1497.001 Delay-imported GetLogicalProcessorInformation for CPU-feature anti-VM ^[pefile.txt:630]

C2 Infrastructure

None observable statically. No hardcoded IPs, domains, or callback URLs beyond Microsoft PKI endpoints. The C2 is likely configured inside the encrypted Inno Setup script (CompiledCodeText) or in the payload dropped by the installer. Without runtime detonation, this is unrecoverable.

Interesting Tidbits

  • Three-day cert: The 72-hour validity window (15–18 May 2026) is extremely tight even for short-lived campaign certs. This suggests rapid procurement-to-deployment, or the cert was revoked quickly after issuance. ^[certificate-chain.txt]
  • Delaware shell: Xryus Technologies LLC is registered in Lewes, Delaware — a common jurisdiction for shell companies. This is a real legal entity pattern, not a random string. ^[certificate-chain.txt]
  • No FLOSS output: flare-floss failed with argument-parsing error, leaving no decoded strings. The encryption in the overlay may extend to string tables as well. ^[floss.txt]
  • No YARA hits: Only generic PE_File_Generic — no family-specific rule matched. ^[yara.txt]
  • Build-then-sign gap: PE timestamp (Feb 2026) is three months before cert validity (May 2026). The binary sat unsigned for ~90 days, or the timestamp was not updated at signing. ^[pefile.txt:34], ^[certificate-chain.txt]

How To Mess With It (Homelab Replication)

This is an Inno Setup installer, not custom malware. Replication means building a comparable dropper:

  1. Download Inno Setup 6.7.0 (unicode) from jrsoftware.org.
  2. Create a .iss script that:
    • Sets AppName=EasySuiteer, AppVersion=3.9.9, AppPublisher=SuperPlus MegaPacker
    • Embeds a payload via [Files] with encryption=yes
    • Adds [Run] entries with nowait and postinstall
  3. Compile with iscc.exe /O+.
  4. Sign the output with any Microsoft ID Verified (or similar low-barrier) code-signing cert.
  5. Verify with osslsigncode verify -in output.exe.
  6. Test extraction with innoextract -e -m output.exe — encrypted archives will fail, confirming evasion.

Deployable Signatures

YARA Rule

rule XryusInnoDropper {
    meta:
        description = "Inno Setup 6.7.0 installer with Xryus Technologies masquerade"
        author = "PacketPursuit SOC"
        date = "2026-08-27"
        sha256 = "450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744"
    strings:
        $inno = "Inno Setup Setup Data (6.7.0)" ascii wide
        $zlb = { 7a 6c 62 1a }
        $xryus = "Xryus Technologies LLC" ascii wide
        $easy = "EasySuiteer" ascii wide
        $super = "SuperPlus MegaPacker" ascii wide
        $compiled = "CompiledCodeText" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        $inno and
        $zlb and
        ($xryus or $easy or $super) and
        $compiled
}

Behavioral Fingerprint

The binary is a ~57 MB PE32 with a small Delphi-compiled Inno Setup loader (~954 KB of mapped image) and a massive encrypted overlay (>55 MB). It imports kernel32.dll.GetLogicalProcessorInformation via delay-import, resolves it at runtime, and uses the result to gate execution. The version-info block claims EasySuiteer Setup by SuperPlus MegaPacker with a blank FileVersion and a 2058+ copyright year pattern (not observed here but common in this cluster). No network indicators are present in the static image; all C2 configuration lives in the encrypted Inno script.

IOCs

Indicator Type Value
SHA-256 hash 450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744
SHA-1 hash 0e58a8e84b1ccf14bea1848aad3276a06e9114a4 (.text section)
MD5 hash 1a67260023dfd031935bb7a42ed8c8b4 (.text section)
ssdeep hash 1572864:... (see ssdeep.txt)
tlsh hash 67C7333BF286A53FE1245B3579B29121543B7A11A4428C4692ECF8CDCF761B10E2F6DB
Cert CN x509 Xryus Technologies LLC
Cert serial x509 1137338358864634854957633500730385878854208031
Issuer x509 CN=Microsoft ID Verified CS AOC CA 03
Validity x509 2026-05-15 → 2026-05-18
Product name version-info EasySuiteer
Company name version-info SuperPlus MegaPacker
Inno version string Inno Setup Setup Data (6.7.0)

Detection Signatures

  • Capa produced no output on this sample ^[capa.txt]
  • YARA: generic PE_File_Generic only ^[yara.txt]
  • MITRE ATT&CK mapping: T1036.002, T1027.002, T1553.002, T1105, T1497.001 (see Deploy / ATT&CK table above)

References

Provenance

  • file.txt — file(1) output (file-type)
  • exiftool.json — ExifTool version-info extraction
  • pefile.txt — pefile library PE header dump
  • strings.txt — strings -n 8 output (885 KB)
  • floss.txt — flare-floss (failed, argument error)
  • capa.txt — Mandiant capa (no output)
  • binwalk.txt — binwalk embedded-artifact scan
  • rabin2-info.txt — radare2 binary header summary
  • certificate-chain.txt — Python cryptography PKCS#7 cert extraction (generated during this analysis)
  • yara.txt — yara rule scan
  • ssdeep.txt, tlsh.txt — fuzzy hashes
  • metadata.json — artifact metadata from OpenCTI
  • dynamic-analysis.md — CAPE skipped (no Windows guest)

Tools: ExifTool 12.76, pefile, binwalk, radare2 5.x, flare-floss (failed), capa (no output), strings, Python cryptography 43.x, innoextract (failed on encrypted archive).