7d9c7fabd525a058351c31fda2a8c34102afd2dc446500ecca9bd59d36bd8fa2unclassified-nsis-dropper: 7d9c7fab — NSIS v2.46.5-ANSI foxmail masquerade
Executive Summary
PE32 GUI executable (2.8 MB) built as a Nullsoft Install System v2.46.5-ANSI self-extracting installer. The outer stub is a stock NSIS exehead compiled with MSVC 10.0 (Visual Studio 2010-era toolchain, timestamp 2014-08-20). A 2.6 MB encrypted/compressed overlay (entropy 8.00) follows the PE header — the actual payload lives inside the NSIS archive and is not recoverable statically without the archive password or NSIS script logic. VS_VERSIONINFO masquerades as foxmail v1.0.1.5 with Chinese-language OriginalFileName (202652500单.exe). OpenCTI labels it silverfox/valleyrat; static analysis does not support that attribution. No SilverFox stream-cipher constants, no LZSS decompressor, no process-hollowing APIs. Static-only (CAPE skipped — no Windows guest).
What It Is
| Attribute | Detail |
|---|---|
| SHA-256 | 7d9c7fabd525a058351c31fda2a8c34102afd2dc446500ecca9bd59d36bd8fa2 |
| File type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Size | 2,776,133 bytes (2.8 MB) ^[triage.json] |
| Timestamp | Wed Aug 20 15:40:56 2014 UTC ^[pefile.txt:38] |
| Linker | MSVC 10.0 (MajorLinkerVersion 0xA, Minor 0x0) ^[pefile.txt:49] |
| NSIS version | v2.46.5-ANSI (from embedded manifest) ^[strings.txt:345] |
| Language | C (rabin2 lang: c) ^[rabin2-info.txt:17] |
| Stripped | No ^[rabin2-info.txt:30] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | 2,643,525 bytes, entropy 8.00 — NSIS compressed archive ^[binwalk.txt:8] ^[pefile.txt overlay calc] |
| Filename (source) | AI软件操作系统.exe ("AI software operating system") ^[triage.json:5] |
Version Information (VS_VERSIONINFO)
- CompanyName:
foxmail^[exiftool.json:36] ^[pefile.txt:286] - FileDescription:
foxmail^[exiftool.json:37] - FileVersion:
1.0.1.5^[exiftool.json:38] - LegalCopyright:
Copyright(C) 2025 Fuldho^[exiftool.json:39] - LegalTrademarks:
foxmail^[exiftool.json:40] - OriginalFileName:
202652500单.exe(Chinese characters in filename) ^[exiftool.json:41] ^[pefile.txt:291] - ProductName:
foxmail^[exiftool.json:42] - Language: Chinese (Simplified) — LangID
0x0804 0x03a8^[exiftool.json:34] ^[pefile.txt:304]
How It Works
NSIS installer anatomy
The binary is a stock NSIS exehead — the open-source Nullsoft installer stub repackaged by a malware distributor. The stub:
- Parses command-line switches (
/Ssilent,/D=install directory,/NCRCskip CRC check) ^[r2:entry0] - Extracts the compressed payload archive from the file overlay into
%TEMP%or a user-selected directory ^[r2:entry0] - Executes the NSIS install script, which typically drops files to disk and launches the inner payload ^[r2:entry0]
The overlay starts at file offset 0xA600 (after the .reloc section ends at raw offset 0x9400 + 0xC00 = 0xA000, with the archive beginning shortly after the PE headers). Binwalk identifies LZMA compressed data at offset 0x2121C (135,708) ^[binwalk.txt:8], but standard LZMA decompression fails on the raw carve — the NSIS archive uses a custom framing or password-derived key that off-the-shelf tools cannot parse without the NSIS script logic.
Payload inference
The overlay contains at least one encrypted PE payload (inferred from 41 MZ markers found inside the overlay at offsets 0x38152, 0x3BEEC, 0x4E1C2, etc.) ^[overlay-scan]. These are likely encrypted or compressed inner executables that the NSIS script will extract and launch. No plaintext C2 URLs, mutex names, or registry keys were recovered from the stub or the overlay.
No SilverFox fingerprints
A full byte-level search across the binary returns zero matches for the SilverFox C-variant stream-cipher constants (0xcaaafe23, 0x3d57aa23, 0x44d9bb23, 0x9e37cb23) ^[entities/silverfox.md]. No LZSS sliding-window decompressor, no XOR-thunk API dispatch, no PEB-walking API resolver, no NtAllocateVirtualMemory / NtWriteVirtualMemory imports. The build stack (NSIS v2.46.5, MSVC 10.0, 2014 timestamp) is completely orthogonal to every confirmed SilverFox variant (Rust/C MSVC 14.0+, LZSS payload, process hollowing). The OpenCTI silverfox/valleyrat labels are contested for this sample.
Decompiled Behavior
Radare2 decompilation of entry0 (offset 0x00403391) reveals the standard NSIS installer flow ^[r2:entry0]:
- CRT init:
InitCommonControls,SetErrorMode(0x8001),OleInitialize - File info probe:
SHGetFileInfoAon the installer path to get icon/type info - Command-line parse:
GetCommandLineA→ string-copy into0x448000buffer; walk characters looking for/S,/D=,/NCRCswitches - Silent-install path: If
/Sis detected, skips UI dialogs and extracts directly - Temp directory staging:
GetTempPathA→lstrcatA("\Temp")→CreateDirectoryA→SetCurrentDirectoryA - Archive extraction loop: Iterates over archive entries (function
fcn.00405f7e), writes each to a temp file, then copies to the target path viaCopyFileA - Launch:
ShellExecuteAorCreateProcessAon the extracted payload path (0x44f000buffer) - Cleanup:
DeleteFileAon temp files,CloseHandle,ExitProcess
No anti-debug, no VM checks, no sandbox gates. The stub relies entirely on the installer trust model for evasion — users expect installers to write files and spawn processes.
C2 Infrastructure
Not observable statically. The NSIS archive is encrypted/compressed and the stub contains no hardcoded network indicators. The inner payload (one or more PEs inside the overlay) would need to be extracted and analyzed separately to recover C2. Based on the foxmail masquerade and Chinese VS_VERSIONINFO, the inner payload is likely a Chinese-language RAT or stealer, but this is speculation.
Interesting Tidbits
- FoxMail masquerade: The VS_VERSIONINFO fields all read
foxmail— a deliberate impersonation of the legitimate Tencent FoxMail email client. This is a well-known brand in China, making the masquerade locally credible. ^[exiftool.json:36-42] - OriginalFileName with Chinese:
202652500单.exe— the单character means "order/sheet/list". Combined withfoxmail, this suggests an email-related social-engineering lure (e.g., "FoxMail order confirmation"). ^[pefile.txt:291] - 2014 timestamp, 2025 copyright: The PE timestamp is 2014 (NSIS v2.46.5 release era), but the VS_VERSIONINFO claims
Copyright(C) 2025 Fuldho. The timestamp is likely the stock NSIS stub compile time; the malware author only patched the version info and payload. ^[pefile.txt:38] ^[exiftool.json:39] - RequireAdministrator manifest: The embedded XML manifest requests
requireAdministratorexecution level ^[strings.txt:345], ensuring the installer (and any payload it spawns) runs elevated. - No network imports in stub: KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, VERSION — all local/system APIs. Any C2 would come from the inner payload, not the installer stub. ^[pefile.txt:306-500]
- High-entropy overlay: 8.00 entropy across 2.6 MB means the archive is either strongly encrypted or compressed with a solid LZMA stream. The lack of decompressible fragments suggests encryption or a password-protected archive. ^[overlay-entropy-calc]
How To Mess With It (Homelab Replication)
-
Build a comparable NSIS dropper: Download NSIS v2.46.5 (or v3.x) from
https://nsis.sourceforge.io. Write a simple.nsiscript:OutFile "payload_installer.exe" RequestExecutionLevel admin Section SetOutPath "$TEMP" File "payload.exe" Exec "$TEMP\payload.exe" SectionEndCompile with
makensis installer.nsi. -
Patch version info: Use Resource Hacker or
rceditto replace VS_VERSIONINFO with brand masquerade strings (e.g.,CompanyName: foxmail,OriginalFileName: order.exe). -
Verify capa fingerprint: Run
capa your_installer.exe— should hit(internal) installer file limitationwarning, just like this sample ^[capa.txt]. Capa cannot inspect the inner payload without extraction. -
What you learn: Installers are a common malware delivery vector because they bypass user suspicion and execute with elevated privileges. The outer stub is often benign-looking; the threat lives in the archive.
Deployable Signatures
YARA — NSIS installer dropper with foxmail masquerade
rule nsis_foxmail_masquerade_dropper
{
meta:
description = "NSIS installer dropper with foxmail VS_VERSIONINFO masquerade and Chinese filename"
author = "Titus"
date = "2026-08-11"
hash = "7d9c7fabd525a058351c31fda2a8c34102afd2dc446500ecca9bd59d36bd8fa2"
strings:
$nsis_manifest = "Nullsoft.NSIS.exehead" ascii wide
$nsis_desc = "Nullsoft Install System" ascii wide
$foxmail_company = "CompanyName: foxmail" ascii wide
$foxmail_product = "ProductName: foxmail" ascii wide
$foxmail_desc = "FileDescription: foxmail" ascii wide
$fuldho = "Copyright(C) 2025 Fuldho" ascii wide
$origfile = "202652500\xe5\x8d\x95.exe" ascii
$install_progress = "verifying installer: %d%%" ascii
$nsis_error = "NSIS Error" ascii
$tmp_file = "~nsu.tmp" ascii
condition:
uint16(0) == 0x5A4D and
$nsis_manifest and
$nsis_desc and
2 of ($foxmail_*) and
any of ($fuldho, $origfile) and
any of ($install_progress, $nsis_error, $tmp_file)
}
Sigma — NSIS installer execution with elevated privileges
title: NSIS Installer Execution with Administrator Privileges
status: experimental
description: Detects execution of NSIS-based installers that request administrator privileges, especially when launched from suspicious paths or with unexpected filenames.
logsource:
category: process_creation
product: windows
detection:
selection_nsis:
- Image|endswith: '\.exe'
- CommandLine|contains: '/S'
- CommandLine|contains: '/NCRC'
selection_masquerade:
- OriginalFileName|contains: 'foxmail'
- Company|contains: 'foxmail'
- Description|contains: 'foxmail'
selection_elevated:
IntegrityLevel: 'High'
condition: selection_nsis and selection_masquerade and selection_elevated
falsepositives:
- Legitimate NSIS installers using foxmail branding (unlikely)
level: medium
IOC List
| Type | Value | Assessment |
|---|---|---|
| SHA-256 | 7d9c7fabd525a058351c31fda2a8c34102afd2dc446500ecca9bd59d36bd8fa2 |
NSIS installer dropper |
| Filename | AI软件操作系统.exe |
Social-engineering lure (Chinese) |
| OriginalFileName | 202652500单.exe |
Masquerade string inside VS_VERSIONINFO |
| CompanyName | foxmail |
Brand impersonation |
| LegalCopyright | Copyright(C) 2025 Fuldho |
Nonsense/falsified copyright |
| NSIS version | v2.46.5-ANSI |
Installer framework version |
| Overlay size | 2,643,525 bytes | Encrypted/compressed payload archive |
| Overlay entropy | 8.00 | Strongly encrypted or solid LZMA |
Behavioral Fingerprint
This binary is a 2.8 MB PE32 GUI executable with a 2014-era NSIS v2.46.5-ANSI installer stub (MSVC 10.0 linker). It imports only standard Win32 system APIs (KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, VERSION) with no networking surface. The file overlay is 2.6 MB of high-entropy data (entropy 8.00) beginning with an XML manifest identifying the binary as a Nullsoft installer requesting administrator privileges. VS_VERSIONINFO fields are falsified to impersonate the foxmail email client with a Chinese-language original filename (202652500单.exe). The installer stub parses /S, /D=, and /NCRC command-line switches, extracts archive contents to %TEMP%, and executes the extracted payload via ShellExecuteA or CreateProcessA. No anti-debug, no VM detection, no sandbox gates. The threat logic is entirely contained within the encrypted overlay and not statically recoverable.
Detection Signatures
No capa capabilities mapped — the tool flagged the sample as an installer and refused to analyze the inner payload ^[capa.txt]. The outer stub has no ATT&CK-mappable malicious behaviors beyond the social-engineering masquerade. The inner payload would need to be extracted for capability mapping.
References
- OpenCTI labels:
exe,malware-bazaar,silverfox,valleyrat— contested for this sample - NSIS project: https://nsis.sourceforge.io
- Related wiki pages:
- unclassified-nsis-dropper — umbrella entity for NSIS-based malware droppers
- silverfox — actual SilverFox family (Rust/C variants with LZSS + process hollowing; not this sample)
- version-info-masquerade — concept page for falsified VS_VERSIONINFO fields
- social-engineering-filename-lure — concept page for business-document and brand-impersonation filenames
Provenance
Analysis based on:
file.txt—filecommand outputpefile.txt— pefile Python library full PE dump (45 KB)exiftool.json— ExifTool metadatastrings.txt—strings -a -n 6output (41 KB, 5,038 lines)rabin2-info.txt— radare2rabin2 -Iheader summarytriage.json— triage pipeline metadatametadata.json— OpenCTI connector metadatabinwalk.txt— binwalk entropy signaturescapa.txt— capa installer-limitation warningdynamic-analysis.md— CAPE skipped (no Windows guest)- Radare2 live analysis (level 2, 99 functions) — entry-point decompilation, import table, string search
Tools: radare2 5.9.x, pefile 2023.x, ExifTool 12.76, binwalk 2.x, capa 7.x, Python 3.12.
Family attribution contested. OpenCTI labels silverfox and valleyrat are not supported by static evidence. This sample is an NSIS installer dropper with foxmail masquerade — treat as unclassified-nsis-dropper until the inner payload is extracted and analyzed.