480c184e69a19d4f3bb595324d618eead8f6fcc5176f1ebc5e44ee1389472503ValleyRAT — PrinterDoctor Inno Setup Dropper
SHA-256:
480c184e69a19d4f3bb595324d618eead8f6fcc5176f1ebc5e44ee1389472503Filename:1.chation_mscate..exeSize: 5,295,183 bytes No dynamic analysis (CAPE skipped — no Windows guest available).
Build / RE
Toolchain. Inno Setup 7.0.0.1 compiled with Embarcadero Delphi 36.0 (RAD Studio 12).^[strings.txt:7537]^[strings.txt:7702] The PE is the standard SetupLdr.e32 stub with an 11-section layout typical of Inno Setup: .text, .itext, .data, .bss, .idata, .didata, .edata, .tls, .rdata, .reloc, .rsrc.^[pefile.txt:76]
Overlay. The PE image ends at raw offset 0x105000 (1,069,056 bytes), leaving a 4.2 MB encrypted Inno Setup archive appended. The archive begins with the Inno Setup Setup Data (7.0.0.1) signature at offset 0x265701 within the overlay.^[binwalk.txt:0] Standard extraction tools (innoextract, 7z) fail because the archive uses Inno Setup's built-in encryption (AES-256 with embedded key/nonce). Carving the overlay and searching for PE headers returns no embedded executables — the payload is fully encrypted.^[overlay-analysis]
Signing. Authenticode-signed with a certificate issued to Beijing Qihu Technology Co., Ltd. (Qihoo 360) by DigiCert Assured ID Code Signing CA-1, serial 0A:1F:3A:05:7A:1D:CE:4B:F7:D7:6D:0C:7A:DF:83:7E, valid 2019-11-22 to 2023-02-04.^[certificate-extraction] The signature is SHA1 and the certificate has expired (validity ended Feb 2023). A DigiCert Timestamp 2021 counter-signature (SHA256) is present, which backdates the signature to within the validity window — this is standard Authenticode behaviour, not an anomaly.^[certificate-chain.txt]
Masquerade. VersionInfo claims the binary is "PrinterDoctor" version 2.2.28.112 by "深圳市点亮星空科技有限公司" (Shenzhen Starry Sky Technology Co., Ltd.).^[exiftool.json:382-389] The original filename field is empty. The VS_FIXEDFILEINFO numeric fields match the string version. No debug directory, no PDB, no Rich header — consistent with Delphi compiler output.^[pefile.txt:318-320]
Anti-analysis. None in the outer stub. Inno Setup itself is not hardened; evasion relies on the installer legitimacy, code-signing trust, and encrypted payload concealment. Delay imports for GetLogicalProcessorInformation (anti-VM) and MessageBoxA are present^[pefile.txt:630-642] but these are standard Inno Setup linker artefacts, not threat-actor additions.
Deploy / ATT&CK
All TTPs below are inferred from static artefacts; no runtime data is available.
| Technique | ID | Evidence |
|---|---|---|
| Malicious File | T1204.002 | Social-engineering filename (1.chation_mscate..exe) with double-extension camouflage.^[triage.json] |
| Masquerading | T1036.002 | "PrinterDoctor" by Chinese company masquerade.^[exiftool.json] |
| Software Packing | T1027.002 | Encrypted Inno Setup 7.0.0.1 overlay (4.2 MB).^[binwalk.txt] |
| Code Signing | T1553.002 | Expired Qihoo 360 Authenticode with DigiCert timestamp counter-signature.^[certificate-chain.txt] |
| Ingress Tool Transfer | T1105 | Inno Setup NumFileEntries/NumRunEntries will extract and execute payload at runtime.^[strings.txt:7151-7158] |
C2 / payload. None recoverable statically. The encrypted archive prevents payload identification without the embedded key.
Attribution. Chinese-language company name and product masquerade align with the broader ValleyRAT distribution cluster, which consistently uses Chinese-language installer lures. However, this sample carries only the valleyrat OpenCTI label (not silverfox), and its Inno Setup / Delphi build stack is completely distinct from the SilverFox Rust/C/.NET Native AOT cluster. It likely represents a separate distribution pipeline that shares the same valleyrat detection umbrella.
Related
- valleyrat — contested OpenCTI umbrella covering multiple unrelated build stacks
- silverfox — Rust/C/.NET Native AOT cluster co-labeled
valleyrat; no build overlap with this sample - inno-setup-legitimate-installer-abuse — concept page for Inno Setup abuse in malware distribution
- version-info-masquerade — generic masquerade technique