typeanalysisfamilyvalleyratconfidencelowcreated2026-09-06updated2026-09-06
SHA-256: 480c184e69a19d4f3bb595324d618eead8f6fcc5176f1ebc5e44ee1389472503

ValleyRAT — PrinterDoctor Inno Setup Dropper

SHA-256: 480c184e69a19d4f3bb595324d618eead8f6fcc5176f1ebc5e44ee1389472503 Filename: 1.chation_mscate..exe Size: 5,295,183 bytes No dynamic analysis (CAPE skipped — no Windows guest available).

Build / RE

Toolchain. Inno Setup 7.0.0.1 compiled with Embarcadero Delphi 36.0 (RAD Studio 12).^[strings.txt:7537]^[strings.txt:7702] The PE is the standard SetupLdr.e32 stub with an 11-section layout typical of Inno Setup: .text, .itext, .data, .bss, .idata, .didata, .edata, .tls, .rdata, .reloc, .rsrc.^[pefile.txt:76]

Overlay. The PE image ends at raw offset 0x105000 (1,069,056 bytes), leaving a 4.2 MB encrypted Inno Setup archive appended. The archive begins with the Inno Setup Setup Data (7.0.0.1) signature at offset 0x265701 within the overlay.^[binwalk.txt:0] Standard extraction tools (innoextract, 7z) fail because the archive uses Inno Setup's built-in encryption (AES-256 with embedded key/nonce). Carving the overlay and searching for PE headers returns no embedded executables — the payload is fully encrypted.^[overlay-analysis]

Signing. Authenticode-signed with a certificate issued to Beijing Qihu Technology Co., Ltd. (Qihoo 360) by DigiCert Assured ID Code Signing CA-1, serial 0A:1F:3A:05:7A:1D:CE:4B:F7:D7:6D:0C:7A:DF:83:7E, valid 2019-11-22 to 2023-02-04.^[certificate-extraction] The signature is SHA1 and the certificate has expired (validity ended Feb 2023). A DigiCert Timestamp 2021 counter-signature (SHA256) is present, which backdates the signature to within the validity window — this is standard Authenticode behaviour, not an anomaly.^[certificate-chain.txt]

Masquerade. VersionInfo claims the binary is "PrinterDoctor" version 2.2.28.112 by "深圳市点亮星空科技有限公司" (Shenzhen Starry Sky Technology Co., Ltd.).^[exiftool.json:382-389] The original filename field is empty. The VS_FIXEDFILEINFO numeric fields match the string version. No debug directory, no PDB, no Rich header — consistent with Delphi compiler output.^[pefile.txt:318-320]

Anti-analysis. None in the outer stub. Inno Setup itself is not hardened; evasion relies on the installer legitimacy, code-signing trust, and encrypted payload concealment. Delay imports for GetLogicalProcessorInformation (anti-VM) and MessageBoxA are present^[pefile.txt:630-642] but these are standard Inno Setup linker artefacts, not threat-actor additions.

Deploy / ATT&CK

All TTPs below are inferred from static artefacts; no runtime data is available.

Technique ID Evidence
Malicious File T1204.002 Social-engineering filename (1.chation_mscate..exe) with double-extension camouflage.^[triage.json]
Masquerading T1036.002 "PrinterDoctor" by Chinese company masquerade.^[exiftool.json]
Software Packing T1027.002 Encrypted Inno Setup 7.0.0.1 overlay (4.2 MB).^[binwalk.txt]
Code Signing T1553.002 Expired Qihoo 360 Authenticode with DigiCert timestamp counter-signature.^[certificate-chain.txt]
Ingress Tool Transfer T1105 Inno Setup NumFileEntries/NumRunEntries will extract and execute payload at runtime.^[strings.txt:7151-7158]

C2 / payload. None recoverable statically. The encrypted archive prevents payload identification without the embedded key.

Attribution. Chinese-language company name and product masquerade align with the broader ValleyRAT distribution cluster, which consistently uses Chinese-language installer lures. However, this sample carries only the valleyrat OpenCTI label (not silverfox), and its Inno Setup / Delphi build stack is completely distinct from the SilverFox Rust/C/.NET Native AOT cluster. It likely represents a separate distribution pipeline that shares the same valleyrat detection umbrella.

Related