typeanalysisfamilyunclassified-nsis-dropperconfidencelowcreated2026-08-11updated2026-08-11pedropperinstallerevasionobfuscationc2defense-evasionnsismasquerade
SHA-256: 7d9c7fabd525a058351c31fda2a8c34102afd2dc446500ecca9bd59d36bd8fa2

unclassified-nsis-dropper: 7d9c7fab — NSIS v2.46.5-ANSI foxmail masquerade

Executive Summary

PE32 GUI executable (2.8 MB) built as a Nullsoft Install System v2.46.5-ANSI self-extracting installer. The outer stub is a stock NSIS exehead compiled with MSVC 10.0 (Visual Studio 2010-era toolchain, timestamp 2014-08-20). A 2.6 MB encrypted/compressed overlay (entropy 8.00) follows the PE header — the actual payload lives inside the NSIS archive and is not recoverable statically without the archive password or NSIS script logic. VS_VERSIONINFO masquerades as foxmail v1.0.1.5 with Chinese-language OriginalFileName (202652500单.exe). OpenCTI labels it silverfox/valleyrat; static analysis does not support that attribution. No SilverFox stream-cipher constants, no LZSS decompressor, no process-hollowing APIs. Static-only (CAPE skipped — no Windows guest).

What It Is

Attribute Detail
SHA-256 7d9c7fabd525a058351c31fda2a8c34102afd2dc446500ecca9bd59d36bd8fa2
File type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Size 2,776,133 bytes (2.8 MB) ^[triage.json]
Timestamp Wed Aug 20 15:40:56 2014 UTC ^[pefile.txt:38]
Linker MSVC 10.0 (MajorLinkerVersion 0xA, Minor 0x0) ^[pefile.txt:49]
NSIS version v2.46.5-ANSI (from embedded manifest) ^[strings.txt:345]
Language C (rabin2 lang: c) ^[rabin2-info.txt:17]
Stripped No ^[rabin2-info.txt:30]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay 2,643,525 bytes, entropy 8.00 — NSIS compressed archive ^[binwalk.txt:8] ^[pefile.txt overlay calc]
Filename (source) AI软件操作系统.exe ("AI software operating system") ^[triage.json:5]

Version Information (VS_VERSIONINFO)

  • CompanyName: foxmail ^[exiftool.json:36] ^[pefile.txt:286]
  • FileDescription: foxmail ^[exiftool.json:37]
  • FileVersion: 1.0.1.5 ^[exiftool.json:38]
  • LegalCopyright: Copyright(C) 2025 Fuldho ^[exiftool.json:39]
  • LegalTrademarks: foxmail ^[exiftool.json:40]
  • OriginalFileName: 202652500单.exe (Chinese characters in filename) ^[exiftool.json:41] ^[pefile.txt:291]
  • ProductName: foxmail ^[exiftool.json:42]
  • Language: Chinese (Simplified) — LangID 0x0804 0x03a8 ^[exiftool.json:34] ^[pefile.txt:304]

How It Works

NSIS installer anatomy

The binary is a stock NSIS exehead — the open-source Nullsoft installer stub repackaged by a malware distributor. The stub:

  1. Parses command-line switches (/S silent, /D= install directory, /NCRC skip CRC check) ^[r2:entry0]
  2. Extracts the compressed payload archive from the file overlay into %TEMP% or a user-selected directory ^[r2:entry0]
  3. Executes the NSIS install script, which typically drops files to disk and launches the inner payload ^[r2:entry0]

The overlay starts at file offset 0xA600 (after the .reloc section ends at raw offset 0x9400 + 0xC00 = 0xA000, with the archive beginning shortly after the PE headers). Binwalk identifies LZMA compressed data at offset 0x2121C (135,708) ^[binwalk.txt:8], but standard LZMA decompression fails on the raw carve — the NSIS archive uses a custom framing or password-derived key that off-the-shelf tools cannot parse without the NSIS script logic.

Payload inference

The overlay contains at least one encrypted PE payload (inferred from 41 MZ markers found inside the overlay at offsets 0x38152, 0x3BEEC, 0x4E1C2, etc.) ^[overlay-scan]. These are likely encrypted or compressed inner executables that the NSIS script will extract and launch. No plaintext C2 URLs, mutex names, or registry keys were recovered from the stub or the overlay.

No SilverFox fingerprints

A full byte-level search across the binary returns zero matches for the SilverFox C-variant stream-cipher constants (0xcaaafe23, 0x3d57aa23, 0x44d9bb23, 0x9e37cb23) ^[entities/silverfox.md]. No LZSS sliding-window decompressor, no XOR-thunk API dispatch, no PEB-walking API resolver, no NtAllocateVirtualMemory / NtWriteVirtualMemory imports. The build stack (NSIS v2.46.5, MSVC 10.0, 2014 timestamp) is completely orthogonal to every confirmed SilverFox variant (Rust/C MSVC 14.0+, LZSS payload, process hollowing). The OpenCTI silverfox/valleyrat labels are contested for this sample.

Decompiled Behavior

Radare2 decompilation of entry0 (offset 0x00403391) reveals the standard NSIS installer flow ^[r2:entry0]:

  1. CRT init: InitCommonControls, SetErrorMode(0x8001), OleInitialize
  2. File info probe: SHGetFileInfoA on the installer path to get icon/type info
  3. Command-line parse: GetCommandLineA → string-copy into 0x448000 buffer; walk characters looking for /S, /D=, /NCRC switches
  4. Silent-install path: If /S is detected, skips UI dialogs and extracts directly
  5. Temp directory staging: GetTempPathA → lstrcatA("\Temp") → CreateDirectoryA → SetCurrentDirectoryA
  6. Archive extraction loop: Iterates over archive entries (function fcn.00405f7e), writes each to a temp file, then copies to the target path via CopyFileA
  7. Launch: ShellExecuteA or CreateProcessA on the extracted payload path (0x44f000 buffer)
  8. Cleanup: DeleteFileA on temp files, CloseHandle, ExitProcess

No anti-debug, no VM checks, no sandbox gates. The stub relies entirely on the installer trust model for evasion — users expect installers to write files and spawn processes.

C2 Infrastructure

Not observable statically. The NSIS archive is encrypted/compressed and the stub contains no hardcoded network indicators. The inner payload (one or more PEs inside the overlay) would need to be extracted and analyzed separately to recover C2. Based on the foxmail masquerade and Chinese VS_VERSIONINFO, the inner payload is likely a Chinese-language RAT or stealer, but this is speculation.

Interesting Tidbits

  • FoxMail masquerade: The VS_VERSIONINFO fields all read foxmail — a deliberate impersonation of the legitimate Tencent FoxMail email client. This is a well-known brand in China, making the masquerade locally credible. ^[exiftool.json:36-42]
  • OriginalFileName with Chinese: 202652500单.exe — the 单 character means "order/sheet/list". Combined with foxmail, this suggests an email-related social-engineering lure (e.g., "FoxMail order confirmation"). ^[pefile.txt:291]
  • 2014 timestamp, 2025 copyright: The PE timestamp is 2014 (NSIS v2.46.5 release era), but the VS_VERSIONINFO claims Copyright(C) 2025 Fuldho. The timestamp is likely the stock NSIS stub compile time; the malware author only patched the version info and payload. ^[pefile.txt:38] ^[exiftool.json:39]
  • RequireAdministrator manifest: The embedded XML manifest requests requireAdministrator execution level ^[strings.txt:345], ensuring the installer (and any payload it spawns) runs elevated.
  • No network imports in stub: KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, VERSION — all local/system APIs. Any C2 would come from the inner payload, not the installer stub. ^[pefile.txt:306-500]
  • High-entropy overlay: 8.00 entropy across 2.6 MB means the archive is either strongly encrypted or compressed with a solid LZMA stream. The lack of decompressible fragments suggests encryption or a password-protected archive. ^[overlay-entropy-calc]

How To Mess With It (Homelab Replication)

  1. Build a comparable NSIS dropper: Download NSIS v2.46.5 (or v3.x) from https://nsis.sourceforge.io. Write a simple .nsi script:

    OutFile "payload_installer.exe"
    RequestExecutionLevel admin
    Section
      SetOutPath "$TEMP"
      File "payload.exe"
      Exec "$TEMP\payload.exe"
    SectionEnd
    

    Compile with makensis installer.nsi.

  2. Patch version info: Use Resource Hacker or rcedit to replace VS_VERSIONINFO with brand masquerade strings (e.g., CompanyName: foxmail, OriginalFileName: order.exe).

  3. Verify capa fingerprint: Run capa your_installer.exe — should hit (internal) installer file limitation warning, just like this sample ^[capa.txt]. Capa cannot inspect the inner payload without extraction.

  4. What you learn: Installers are a common malware delivery vector because they bypass user suspicion and execute with elevated privileges. The outer stub is often benign-looking; the threat lives in the archive.

Deployable Signatures

YARA — NSIS installer dropper with foxmail masquerade

rule nsis_foxmail_masquerade_dropper
{
    meta:
        description = "NSIS installer dropper with foxmail VS_VERSIONINFO masquerade and Chinese filename"
        author = "Titus"
        date = "2026-08-11"
        hash = "7d9c7fabd525a058351c31fda2a8c34102afd2dc446500ecca9bd59d36bd8fa2"
    strings:
        $nsis_manifest = "Nullsoft.NSIS.exehead" ascii wide
        $nsis_desc = "Nullsoft Install System" ascii wide
        $foxmail_company = "CompanyName: foxmail" ascii wide
        $foxmail_product = "ProductName: foxmail" ascii wide
        $foxmail_desc = "FileDescription: foxmail" ascii wide
        $fuldho = "Copyright(C) 2025 Fuldho" ascii wide
        $origfile = "202652500\xe5\x8d\x95.exe" ascii
        $install_progress = "verifying installer: %d%%" ascii
        $nsis_error = "NSIS Error" ascii
        $tmp_file = "~nsu.tmp" ascii
    condition:
        uint16(0) == 0x5A4D and
        $nsis_manifest and
        $nsis_desc and
        2 of ($foxmail_*) and
        any of ($fuldho, $origfile) and
        any of ($install_progress, $nsis_error, $tmp_file)
}

Sigma — NSIS installer execution with elevated privileges

title: NSIS Installer Execution with Administrator Privileges
status: experimental
description: Detects execution of NSIS-based installers that request administrator privileges, especially when launched from suspicious paths or with unexpected filenames.
logsource:
    category: process_creation
    product: windows
detection:
    selection_nsis:
        - Image|endswith: '\.exe'
        - CommandLine|contains: '/S'
        - CommandLine|contains: '/NCRC'
    selection_masquerade:
        - OriginalFileName|contains: 'foxmail'
        - Company|contains: 'foxmail'
        - Description|contains: 'foxmail'
    selection_elevated:
        IntegrityLevel: 'High'
    condition: selection_nsis and selection_masquerade and selection_elevated
falsepositives:
    - Legitimate NSIS installers using foxmail branding (unlikely)
level: medium

IOC List

Type Value Assessment
SHA-256 7d9c7fabd525a058351c31fda2a8c34102afd2dc446500ecca9bd59d36bd8fa2 NSIS installer dropper
Filename AI软件操作系统.exe Social-engineering lure (Chinese)
OriginalFileName 202652500单.exe Masquerade string inside VS_VERSIONINFO
CompanyName foxmail Brand impersonation
LegalCopyright Copyright(C) 2025 Fuldho Nonsense/falsified copyright
NSIS version v2.46.5-ANSI Installer framework version
Overlay size 2,643,525 bytes Encrypted/compressed payload archive
Overlay entropy 8.00 Strongly encrypted or solid LZMA

Behavioral Fingerprint

This binary is a 2.8 MB PE32 GUI executable with a 2014-era NSIS v2.46.5-ANSI installer stub (MSVC 10.0 linker). It imports only standard Win32 system APIs (KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, VERSION) with no networking surface. The file overlay is 2.6 MB of high-entropy data (entropy 8.00) beginning with an XML manifest identifying the binary as a Nullsoft installer requesting administrator privileges. VS_VERSIONINFO fields are falsified to impersonate the foxmail email client with a Chinese-language original filename (202652500单.exe). The installer stub parses /S, /D=, and /NCRC command-line switches, extracts archive contents to %TEMP%, and executes the extracted payload via ShellExecuteA or CreateProcessA. No anti-debug, no VM detection, no sandbox gates. The threat logic is entirely contained within the encrypted overlay and not statically recoverable.

Detection Signatures

No capa capabilities mapped — the tool flagged the sample as an installer and refused to analyze the inner payload ^[capa.txt]. The outer stub has no ATT&CK-mappable malicious behaviors beyond the social-engineering masquerade. The inner payload would need to be extracted for capability mapping.

References

  • OpenCTI labels: exe, malware-bazaar, silverfox, valleyrat — contested for this sample
  • NSIS project: https://nsis.sourceforge.io
  • Related wiki pages:

Provenance

Analysis based on:

  • file.txt — file command output
  • pefile.txt — pefile Python library full PE dump (45 KB)
  • exiftool.json — ExifTool metadata
  • strings.txt — strings -a -n 6 output (41 KB, 5,038 lines)
  • rabin2-info.txt — radare2 rabin2 -I header summary
  • triage.json — triage pipeline metadata
  • metadata.json — OpenCTI connector metadata
  • binwalk.txt — binwalk entropy signatures
  • capa.txt — capa installer-limitation warning
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • Radare2 live analysis (level 2, 99 functions) — entry-point decompilation, import table, string search

Tools: radare2 5.9.x, pefile 2023.x, ExifTool 12.76, binwalk 2.x, capa 7.x, Python 3.12.


Family attribution contested. OpenCTI labels silverfox and valleyrat are not supported by static evidence. This sample is an NSIS installer dropper with foxmail masquerade — treat as unclassified-nsis-dropper until the inner payload is extracted and analyzed.