typeanalysisfamilyunclassified-dotnet-crypter-loaderconfidencemediumcreated2026-08-01updated2026-08-01dotnetmalware-familyloaderobfuscationpayloadcode-injectiondefense-evasionreflective-loadingaesrijndaeltripledesmd5gzipdeflate
SHA-256: 5d1d22f92b87dc8d5a4d0603da456b8b35432a1bcaa646fead9df2d5a5b01d02

unclassified-dotnet-crypter-loader: 5d1d22f9 — TripleDES+DeflateStream multi-crypto variant, CS2 cheat masquerade

Executive Summary

Eighth confirmed sibling in the unclassified-dotnet-crypter-loader family. A .NET Framework 4.0+ PE32 crypter/loader distributed as a Counter-Strike 2 cheat (Neverlose Cs 2.exe). Unlike prior siblings, this variant does not use ConfuserEx obfuscation and does not contain AMSI bypass strings. Instead it layers TripleDES, RijndaelManaged, AesCryptoServiceProvider, MD5CryptoServiceProvider, GZipStream, and DeflateStream in a single binary — the broadest crypto surface observed in this family to date. The decrypted payload is bridged into native code via DynamicMethod/ILGenerator and nativeEntry/nativeSizeOfCode fields. No network IOCs recoverable statically. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: 5d1d22f92b87dc8d5a4d0603da456b8b35432a1bcaa646fead9df2d5a5b01d02
  • Filename: Neverlose Cs 2.exe (CS2 cheat social-engineering lure) ^[triage.json]
  • Internal name: Yknifhcnxi.exe ^[pefile.txt:243]
  • File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
  • Size: 583,680 bytes (570 KB)
  • Timestamp: Tue Apr 11 13:44:03 2073 UTC — fabricated future date ^[pefile.txt:34]
  • Linker: MSVC v48.0 (Visual Studio 2019+) ^[pefile.txt:45]
  • CLR: .NET Framework 4.0 (v4.0.30319) ^[strings.txt:12]
  • Compiler artefacts: Microsoft.CodeAnalysis.EmbeddedAttribute, RefSafetyRulesAttribute — C# 8.0+ / Roslyn ^[strings.txt:41-44]
  • Signing: Unsigned
  • VS_VERSIONINFO: Empty fields; InternalName / OriginalFilename = Yknifhcnxi.exe, FileVersion = 1.0.0.0 ^[pefile.txt:233-243]
  • OpenCTI labels: exe, malware-bazaar, stealer ^[triage.json]

How It Works

The outer binary is a standard .NET Framework PE32 that decrypts and reflectively loads an encrypted inner payload. The family fingerprint is well documented on the unclassified-dotnet-crypter-loader entity page; this report focuses on per-sample deltas.

Obfuscation delta — no ConfuserEx. Prior siblings 07835853 and a80c26e2 carry ConfuserEx #=q…== name mangling or control-flow flattening. This sample uses plain 20-character random alphanumeric identifiers (HW7A4L2WKORYOCvcVf, C9yW5Ja61Js1UP73y8, ojHG8YWRQi832NSQbD, etc.) across types, methods, and fields ^[strings.txt:45-55,100-140]. Field names follow a secondary pattern: m_<guid> (e.g. m_52d9a1b238b54e3c85b21bb17175164e) ^[strings.txt:578-600]. The result is functionally equivalent obfuscation without ConfuserEx artefacts.

Crypto surface delta — six primitives. Most siblings use AES-CSP or RijndaelManaged plus one compression layer. This sample references TripleDES, RijndaelManaged, AesCryptoServiceProvider, MD5CryptoServiceProvider, GZipStream, and DeflateStream in the same binary ^[strings.txt:184-193,318-327,525]. Whether all six are used in a single decryption chain or whether the builder embeds redundant crypto imports as anti-static noise is not recoverable without dynamic execution.

AMSI bypass delta — absent. Siblings 931242f8, 673e6738, 4e31a886, and 5f54948e contain explicit AmsiOpenSession/AmsiScanBuffer byte-signature bypass strings. This sample has none ^[strings.txt]. The builder appears to have toggled the AMSI-bypass module off for this build.

Native bridging — unchanged. nativeEntry and nativeSizeOfCode fields are present ^[strings.txt:490-491], suggesting the decrypted payload is unmanaged shellcode or a PE mapped into RWX memory. LoadLibrary/GetProcAddress P/Invoke strings ^[strings.txt:419-422] and VirtualProtect parameter names (flNewProtect, lpflOldProtect) ^[strings.txt:512-513] support the standard reflective-injection path.

14 hardcoded 64-character hex strings. Lines 564–577 of strings.txt contain fourteen 64-character uppercase hex strings (e.g. 03DCEB56B5842C722DE2821DA9906CD70AB73267EAB1A3947BFD894D19372BC7) ^[strings.txt:564-577]. None match the sample's SHA-256 or any known corpus hash. Purpose is unclear — likely payload-segment integrity hashes or builder-template watermarking.

No network surface in outer layer. No System.Net, HttpWebRequest, WebClient, TcpClient, or hardcoded URLs/IPs are present in the outer binary. C2 and exfil logic live inside the encrypted inner payload, unreachable without runtime decryption.

Decompiled Behavior

Static analysis of CIL via radare2 is limited — radare2 emits No SN reg alias for 'cil' warnings throughout and cannot resolve CIL opcodes to meaningful decompilation ^[rabin2-info.txt]. Ghidra was not invoked for this sample because the CIL metadata surface is already well-characterised by capa and string extraction.

Observed control-flow patterns from capa and strings:

  1. Entry point → mscoree.dll!_CorExeMain (standard .NET bootstrap) ^[pefile.txt:255]
  2. Resource extraction → GetManifestResourceStream called on the executing assembly ^[strings.txt:348]
  3. Decryption chain (inferred) → FromBase64String → MD5CryptoServiceProvider.ComputeHash (key derivation) → CreateDecryptor on AesCryptoServiceProvider, RijndaelManaged, or TripleDES → CryptoStream → GZipStream or DeflateStream decompression ^[capa.txt]
  4. Reflective execution → Assembly.Load(byte[]) or DynamicMethod + ILGenerator.Emit + GetDelegateForFunctionPointer → jump to nativeEntry with nativeSizeOfCode ^[strings.txt:343-348,372,425,490-491]

The high .text entropy (7.86) suggests the encrypted payload is embedded directly in the .text section rather than a named .rsrc manifest resource ^[pefile.txt:92]. This is consistent with sibling a80c26e2 which stores ~7.29 MB of encrypted payload in .text (97.7 % of file).

C2 Infrastructure

None recoverable statically. No hardcoded domains, IPs, URLs, mutex names, named pipes, or registry keys are present in the outer binary. The inner payload's C2 is decrypted at runtime.

Interesting Tidbits

  • Game-hack masquerade — Neverlose Cs 2.exe targets CS2 players, a common distribution vector for crypter/loader stubs (victims expect to run unsigned "cheat" software). ^[triage.json]
  • Future-dated timestamp — 2073 PE timestamp is a deliberate anti-clustering tactic also seen in siblings 38582041 (Dec 2050) and bc38233e (2040). ^[pefile.txt:34]
  • classthis field — The string classthis at offset ~489 suggests a builder template that names the native bridging class classthis, a pattern observed in other commodity .NET crypters. ^[strings.txt:489]
  • Zkwydijwth property — A single property get_Zkwydijwth stands out among the random noise names ^[strings.txt:227], possibly a hardcoded config or resource accessor the builder forgot to randomise.
  • No System.Net imports — Confirms the outer binary is purely a stage-1 loader; all C2 logic is delegated to the inner payload.

How To Mess With It (Homelab Replication)

Goal: Build a comparable .NET crypter/loader that capa fingerprints similarly.

  1. Toolchain: Visual Studio 2022, .NET Framework 4.8, C# 8.0+.
  2. Project: Console or WinForms app. Add references to System.IO.Compression and System.Security.
  3. Encrypt a payload (any PE or shellcode) with:
    • RijndaelManaged in CBC mode, 256-bit key derived from MD5CryptoServiceProvider.ComputeHash(password).
    • Compress ciphertext with GZipStream (or DeflateStream).
    • Base64-encode or embed as raw byte array.
  4. Decrypt at runtime:
    byte[] key = new MD5CryptoServiceProvider().ComputeHash(Encoding.UTF8.GetBytes("YourPassword"));
    RijndaelManaged rm = new RijndaelManaged();
    rm.Key = key; rm.IV = key.Take(16).ToArray();
    CryptoStream cs = new CryptoStream(new GZipStream(new MemoryStream(cipher), CompressionMode.Decompress), rm.CreateDecryptor(), CryptoStreamMode.Read);
    byte[] payload = new BinaryReader(cs).ReadBytes((int)cs.Length);
    
  5. Reflective load:
    Assembly.Load(payload).EntryPoint.Invoke(null, null);
    
    Or use DynamicMethod + ILGenerator + GetDelegateForFunctionPointer for native bridging.
  6. Obfuscate: Use an open-source .NET obfuscator (e.g. ConfuserEx) or manually rename all types/methods to 20-char random alphanumeric strings.
  7. Verify: Run capa on the compiled binary. Expect hits on T1140, T1027, T1620, T1129, T1560.002 — same as this sample's capa.txt.

Deployable Signatures

YARA Rule

rule unclassified_dotnet_crypter_loader_multi_crypto {
    meta:
        description = "Detects unclassified-dotnet-crypter-loader family with multi-crypto surface"
        author = "PacketPursuit"
        date = "2026-08-01"
        sha256 = "5d1d22f92b87dc8d5a4d0603da456b8b35432a1bcaa646fead9df2d5a5b01d02"
    strings:
        $a1 = "nativeEntry" ascii wide
        $a2 = "nativeSizeOfCode" ascii wide
        $a3 = "DynamicMethod" ascii wide
        $a4 = "ILGenerator" ascii wide
        $a5 = "GetDelegateForFunctionPointer" ascii wide
        $a6 = "LoadLibrary" ascii wide
        $a7 = "GetProcAddress" ascii wide
        $b1 = "CryptoStream" ascii wide
        $b2 = "GZipStream" ascii wide
        $b3 = "DeflateStream" ascii wide
        $b4 = "AesCryptoServiceProvider" ascii wide
        $b5 = "RijndaelManaged" ascii wide
        $b6 = "MD5CryptoServiceProvider" ascii wide
        $b7 = "TripleDES" ascii wide
        $c1 = "GetManifestResourceStream" ascii wide
        $c2 = "Yknifhcnxi.Properties" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 1MB and
        2 of ($a*) and
        4 of ($b*) and
        1 of ($c*)
}

Behavioral Hunt Query (Sysmon)

// Hunt: .NET multi-crypto reflective loader process spawn
// Target: Sysmon EID 1 (ProcessCreate) + EID 7 (ImageLoad)
EventID=1 AND (
    Image="*\\Yknifhcnxi.exe" OR
    CommandLine="*Neverlose Cs 2*" OR
    CommandLine="*Yknifhcnxi*"
)
// Correlated with CLR load (EventID=7, ImageLoaded contains "clr.dll")

IOC List

Indicator Value Notes
SHA-256 5d1d22f92b87dc8d5a4d0603da456b8b35432a1bcaa646fead9df2d5a5b01d02 Outer loader
Filename Neverlose Cs 2.exe Distribution name
Internal name Yknifhcnxi.exe VS_VERSIONINFO
VS_VERSIONINFO Empty fields, FileVersion: 1.0.0.0 Minimal masquerade
PE Timestamp 2073-04-11 13:44:03 UTC Fabricated future date
Namespace Yknifhcnxi.Properties Obfuscated property namespace
Hardcoded hashes (14×) 03DCEB56..., 0E448EF5..., etc. 64-char hex strings; purpose unknown

Behavioral Fingerprint

This binary is a .NET Framework 4.0+ PE32 crypter/loader that decrypts a multi-layer payload using RijndaelManaged/AesCryptoServiceProvider/TripleDES + MD5CryptoServiceProvider key derivation, decompresses via GZipStream/DeflateStream, and reflectively loads the inner payload via DynamicMethod/ILGenerator or Assembly.Load. It bridges into native code through nativeEntry/nativeSizeOfCode fields with LoadLibrary/GetProcAddress runtime API resolution. No AMSI bypass strings are present in this variant. The outer binary contains no System.Net surface; C2 is runtime-resolved from the decrypted inner payload.

Detection Signatures

MITRE ATT&CK Technique Evidence
T1140 Deobfuscate/Decode Files or Information CryptoStream + CreateDecryptor + GZipStream/DeflateStream chain ^[capa.txt]
T1027 Obfuscated Files or Information Multi-layer AES/Rijndael/TripleDES + GZip/Deflate encryption ^[capa.txt]
T1620 Reflective Code Loading DynamicMethod + ILGenerator + GetDelegateForFunctionPointer ^[capa.txt]
T1129 Shared Modules LoadLibrary + GetProcAddress P/Invoke ^[strings.txt:419-422]
T1560.002 Archive Collected Data::Archive via Library GZipStream decompression of payload ^[capa.txt]
T1083 File and Directory Discovery check if file exists capa match ^[capa.txt]

References

Provenance

  • file.txt — file(1) output ^[file.txt]
  • pefile.txt — pefile DOS/NT/section/import/resource analysis ^[pefile.txt]
  • rabin2-info.txt — radare2 binary header summary ^[rabin2-info.txt]
  • strings.txt — static ASCII/Unicode string extraction ^[strings.txt]
  • capa.txt — Mandiant flare-capa v7 static capability detection ^[capa.txt]
  • exiftool.json — ExifTool PE metadata ^[exiftool.json]
  • binwalk.txt — embedded artefact scan ^[binwalk.txt]
  • triage.json — triage pipeline metadata ^[triage.json]
  • dynamic-analysis.md — CAPE sandbox status (skipped, no Windows guest) ^[dynamic-analysis.md]
  • floss.txt — FireEye flare-floss invocation failed (CLI argument error) ^[floss.txt]

Tools: file v5.44, pefile 2023.2.7, rabin2 5.9.2, strings (binutils), capa v7.0.1, ExifTool 12.76, binwalk 2.3.4, floss v3.1.1 (failed), radare2 analysis level 3 (CIL warnings).