600d4f1ca00a93e7e684c9b7efa436f09ef7f8edab035a9a7d06b2519fc1e0c1unclassified-nsis-dropper: 600d4f1c — Spanish invoice lure, SHA-384 fabricated cert, no VS_VERSIONINFO
Executive Summary
Thirteenth confirmed sibling in the unclassified-nsis-dropper cluster. Spanish-language invoice lure (GARPE (339) LISTADO DE FACTURAS PENDIENTES DE PAGO.pdf.exe), NSIS v3.12 exehead with MSVC 6.0 linker, LZMA:23 solid archive containing one high-entropy encrypted payload (Fuelled, 118 KB), one moderate-entropy file (Aquate, 34 KB), and four null-padded decoy files. No PowerShell cradle recovered statically. Novel cluster traits: SHA-384 Authenticode security directory (standard tools choke), fabricated self-signed cert with fresh word-salad subject (Bundsnren@Equationist.Oa1, Benitier100.), and complete absence of VS_VERSIONINFO. Static-only (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
600d4f1ca00a93e7e684c9b7efa436f09ef7f8edab035a9a7d06b2519fc1e0c1 - Filename:
GARPE (339) LISTADO DE FACTURAS PENDIENTES DE PAGO.pdf.exe^[triage.json] - Type: PE32 executable (GUI) Intel 80386, Nullsoft Installer self-extracting archive, 5 sections ^[file.txt]
- Size: 173,648 bytes
- Linker: MSVC 6.0 (MajorLinkerVersion 0x6, MinorLinkerVersion 0x0) ^[pefile.txt]
- Compile stamp: Sun Apr 19 20:38:47 2026 UTC ^[pefile.txt:34]
- Signed: Yes — security directory present at RVA 0x29C60, size 0x9F0, but SHA-384 digest algorithm (non-standard for Authenticode) ^[rabin2-info.txt]
- VS_VERSIONINFO: Absent ^[strings.txt] (no
CompanyName,FileDescription,ProductName,OriginalFilenamefound in binary) - CAPE: Skipped — no Windows guest available ^[dynamic-analysis.md]
Build / RE
Toolchain: NSIS v3.12 Unicode exehead compiled with MSVC 6.0 linker. Standard NSIS GUI imports (registry, file I/O, process creation, shell operations, COM initialisation) ^[pefile.txt:229-451]. No anti-debug, no VM detection, no packer beyond the NSIS LZMA archive itself.
Archive layout (extracted via 7z x):
$PLUGINSDIR/System.dll— standard NSIS plugin helperFuelled— 118,141 bytes, entropy 7.427 — high-entropy encrypted payload (likely inner PE or next-stage binary)Drivtmmer/directory:Aquate— 34,175 bytes, entropy 4.562 — moderate-entropy, possibly encrypted with structure or another layer of encodingankefristernes.esn— 53,746 bytes, entropy 0.159 — >99% null-padded garbagelandholders.vit— 41,710 bytes, entropy 0.156 — null-padded garbagerefund.rhe— 6,598 bytes, entropy 0.144 — null-padded garbagetermed.fla— 86,734 bytes, entropy 0.159 — null-padded garbage
The four .esn/.vit/.rhe/.fla files are decoys/padding; their near-zero entropy and lack of readable strings confirm they are not functional payloads. Aquate is the only file besides Fuelled with non-trivial entropy; its first bytes (00 00 00 5a ...) do not match any known magic header, suggesting it may be XOR-encrypted or part of a custom payload format.
Certificate: Self-signed X.509 v3 in the security directory. SHA-384 digest causes openssl pkcs7 and signtool to choke. Manual DER inspection reveals repeated subject fields: Bundsnren@Equationist.Oa1, Benitier100., 'Haandhaevelsen Tidsfaktors Traadrulles 1, Benitier0 ^[strings.txt:420-434]. Validity window 26 May 2003 → 27 May 2003 (backdated 23 years), confirming fabrication at build time.
Notable absence: VS_VERSIONINFO resource is completely missing. Prior siblings in this cluster fabricated word-salad VS_VERSIONINFO (bedimpled, excerpting, etc.) as an anti-triage layer; this sample drops the masquerade entirely, relying only on the double-extension .pdf.exe and the Spanish filename for social engineering.
Deploy / ATT&CK
- T1204.002 — Malicious Link / User Execution: relies on
.pdf.exedouble-extension and Spanish invoice lure - T1036.004 — Masquerade Task or Service: invoice-document filename
- T1036.005 — Match Legitimate Name or Location: uses real NSIS installer framework
- T1574.002 — Hijack Execution Flow: NSIS stub hijacks legitimate installer trust model
- T1620 — Reflective Code Loading: inferred — inner payload likely decrypted/loaded in memory by NSIS script at runtime
- T1027.002 — Obfuscated Files or Information: encrypted payload inside LZMA archive; null-padded decoy files
No static C2 IOCs, no registry keys, no mutex names, no network APIs. All behavioral indicators require dynamic execution of the NSIS script, which is compiled into NSIS bytecode inside the compressed archive and not exposed as plain text.
Interesting Tidbits
- SHA-384 Authenticode: First sibling in this cluster to use SHA-384 for the security directory. Standard Authenticode tooling (rabin2, openssl pkcs7) all warn or fail because SHA-384 is outside the supported set. This is either a toolchain upgrade or an accidental side effect of the certificate generator used by the operator.
- No VS_VERSIONINFO: Prior 12 siblings all had fabricated VS_VERSIONINFO word-salad. Removing it simplifies the build pipeline and may indicate the operator has shifted to faster/lower-effort packaging.
- Spanish lure: Targets Spanish-speaking victims with
FACTURAS PENDIENTES DE PAGO(pending payment invoices). Prior lures were Italian (Pagamento), US (Ref_702...), German (inquiry_4387), Chinese (AI软件操作系统), and generic English (Product_samples_pdf). This confirms the operator targets multiple language zones. - Payload naming:
Fuelled,Aquate,ankefristernes,landholders,refund,termed— English/Danish gibberish words consistent with the cluster's naming convention, but the.esn,.vit,.rhe,.flaextensions are new (prior siblings used.imp,.alk,.kom,.lob,.Mas,.Bes,.Pot).
How To Mess With It (Homelab Replication)
- Install NSIS 3.x on Windows.
- Write a
.nsithat embeds a payload and a few null-padded decoy files. - Compile with
makensis.exe. - Generate a self-signed cert with SHA-384 (requires OpenSSL 3.x or custom tool):
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -sha384 -days 365 -nodes - Sign the resulting
.exewithosslsigncode:osslsigncode sign -pkcs12 cert.pfx -in installer.exe -out signed.exe - Verify with
7z l signed.exeandrabin2 -I signed.exe.
Deployable Signatures
YARA rule:
rule NSIS_Dropper_Cluster_SHA384_Cert
{
meta:
description = "NSIS SFX dropper cluster sibling with SHA-384 security dir and fabricated word-salad cert"
author = "PacketPursuit"
date = "2026-08-25"
sha256 = "600d4f1ca00a93e7e684c9b7efa436f09ef7f8edab035a9a7d06b2519fc1e0c1"
strings:
$nsis = "Nullsoft.NSIS.exehead" ascii wide
$manifest = "Nullsoft Install System v3.12" ascii wide
$cert1 = "Bundsnren@Equationist.Oa1" ascii wide
$cert2 = "Benitier100." ascii wide
$cert3 = "Haandhaevelsen Tidsfaktors Traadrulles" ascii wide
$err1 = "Error writing temporary file. Make sure your temp folder is valid." ascii wide
$err2 = "Error launching installer" ascii wide
condition:
uint16(0) == 0x5A4D and
$nsis and
any of ($cert*) and
any of ($err*)
}
Behavioral fingerprint statement: This binary is a Nullsoft NSIS v3 self-extracting installer (PE32, MSVC 6.0 linker) with a LZMA-compressed archive containing a high-entropy encrypted payload file (entropy >7.0), one or more moderate-entropy files, and multiple null-padded decoy files with nonsense names and unusual extensions. The PE security directory contains a fabricated self-signed X.509 certificate with non-standard SHA-384 digest and word-salad subject fields. No VS_VERSIONINFO resource is present. Execution at runtime unpacks the archive to %TEMP% and launches the decrypted inner payload. No static network indicators.
IOC list:
- SHA-256:
600d4f1ca00a93e7e684c9b7efa436f09ef7f8edab035a9a7d06b2519fc1e0c1 - Filename observed:
GARPE (339) LISTADO DE FACTURAS PENDIENTES DE PAGO.pdf.exe - File size: 173,648 bytes
- Compile timestamp: 2026-04-19 20:38:47 UTC
- NSIS version: 3.12
- Certificate subject fields:
Bundsnren@Equationist.Oa1,Benitier100.,Haandhaevelsen Tidsfaktors Traadrulles 1,Benitier0 - Certificate validity: 2003-05-26 to 2003-05-27 (fabricated/backdated)
- Archive contents (extracted names):
Fuelled,Aquate,ankefristernes.esn,landholders.vit,refund.rhe,termed.fla,System.dll
Detection Signatures
- capa: Skipped — installer limitation warning ^[capa.txt]
- MITRE ATT&CK: T1204.002, T1036.004, T1036.005, T1574.002, T1620, T1027.002
References
- unclassified-nsis-dropper — cluster entity page
- nsis-lzma-embedded-payload — technique page
- character-skip-cipher-powershell-obfuscation — technique page (not present in this sample; see cluster siblings)
- fabricated-certificate-masquerade — concept page
- version-info-masquerade — concept page (not present in this sample; absent VS_VERSIONINFO is a delta)
Provenance
- Static analysis performed on
pp-hermes(Lab1BU, <lan>) usingfile(1),exiftool,pefile,strings,rabin2,7z,openssl,xxd, Python entropy analysis. - No dynamic execution (CAPE skipped — no Windows guest).
- Extraction timestamp: 2026-08-25.