8a2247462598c070c36e83cf7a5944ca86c0bfcf1b9abda90192b23f9214d616unclassified-dotnet: 8a224746 — C# MetroFramework updater with SharpZipLib, debug PDB intact
Executive Summary
A ~987 KB .NET Framework 4.0 PE32 GUI executable named internally CSUpdater.exe. Build artefacts point to a Visual Studio debug build of a legitimate software-updater tool (MetroFramework UI + ICSharpCode.SharpZipLib ZIP handling). No hardcoded C2 URLs, no anti-debug/VM gates, no credential-theft APIs, and no persistence registry strings were recovered statically. Capa flags a broad .NET HTTP-client and crypto surface, but every capability maps to benign updater behaviour (download → verify → decompress → install). Static-only analysis; CAPE skipped due to no Windows guest. Classified as low-confidence unclassified-dotnet pending dynamic confirmation or sibling cluster.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 8a2247462598c070c36e83cf7a5944ca86c0bfcf1b9abda90192b23f9214d616 |
| MD5 | 0e8965c1aea9b42a3a34cddf0bbc3767 |
| File name | 0e8965c1aea9b42a3a34cddf0bbc3767.exe |
| File type | PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt] |
| Size | 1,009,664 bytes |
| Timestamp | Sun Feb 23 07:45:27 2087 UTC (future-dated, likely debug-build artefact) ^[pefile.txt:34] |
| Internal name | CSUpdater.exe ^[exiftool.json:40] |
| Product name | CSUpdater ^[exiftool.json:44] |
| PDB path | C:\Work\CSPlatform\V8\CSUpdater\CSUpdater\obj\Debug\CSUpdater.pdb ^[rabin2-info.txt:13] ^[pefile.txt:417] |
| Compiler | .NET Framework C# (IL linker v48.0, lang=cil, subsys=dotnet) ^[rabin2-info.txt:19] ^[rabin2-info.txt:34] |
| Signed | No (signed: false) ^[rabin2-info.txt:29] |
| ASLR / NX / Canary | Enabled (pic=true, nx=true, canary=true) ^[rabin2-info.txt:23] ^[rabin2-info.txt:27] ^[rabin2-info.txt:6] |
| Packing | None — no UPX, Themida, ConfuserEx, or obfuscator signatures. High-entropy sections absent. |
How It Works
Build / RE
The binary is an unobfuscated CIL assembly. Strings analysis reveals a typical C# WinForms application stack:
- UI framework:
MetroFramework(MetroButton, MetroScrollBar, MetroProgressBar, MetroThemeStyle, etc.) ^[strings.txt:MetroFramework] - Compression library:
ICSharpCode.SharpZipLib(ZipEntry, ZipFile, ZipOutputStream, ZipAESStream, GZipStream, etc.) ^[strings.txt:ICSharpCode.SharpZipLib] - Forms:
frmConsoleandfrmDown(console-style downloader window) ^[strings.txt:722] - Crypto:
Aes128,Aes192,Aes256,RijndaelManaged,ZipAESStream,PkzipClassicCryptoBase,CryptoStreamMode^[strings.txt:87-91] - Networking:
HttpWebRequest,HttpWebResponse,WebClient,TcpClient,System.Net.Sockets, proxy/cookie/User-Agent handlers ^[strings.txt:2672-3012] - Process spawning:
ProcessStartInfo,set_UseShellExecute,ExecutePowerShellCommand^[strings.txt:2020-852] - File I/O:
CopyFile,MoveFile,DeleteFile,CreateDirectory,GetTempFileName,FileAttributes^[capa.txt]
The presence of ExecutePowerShellCommand alongside ProcessStartInfo suggests the updater may launch post-install PowerShell scripts or child installers. No script payloads are embedded in resources (.rsrc contains only icon, version info, and manifest) ^[pefile.txt:257-393].
No anti-analysis artefacts were found:
- No
IsDebuggerPresent,CheckRemoteDebuggerPresent,NtQueryInformationProcess - No
VBOX,VMWARE,QEMU,HYPERVstrings - No timing gates or
GetTickCountloops - No obfuscated API resolution or P/Invoke to
kernel32/ntdllbeyond the three trivial DLL references (kernel32.dll,user32.dll,gdi32.dll,shell32.dll) ^[strings.txt:1715-1719]
Floss failed due to incorrect CLI arguments (this is a .NET binary; floss is most useful for native PE string decoding). ^[floss.txt]
Deploy / ATT&CK
Confidence: static-only inference. CAPE skipped because no Windows guest is available. All TTPs below are inferred from capa static hits and should be treated as capability mapping, not confirmed runtime behaviour.
| Tactic | Technique | Evidence |
|---|---|---|
| Collection | T1560.002 Archive Collected Data (via Library) | ICSharpCode.SharpZipLib zip construction ^[capa.txt] |
| Command and Control | T1071.001 Web Protocols | HttpWebRequest, HttpWebResponse, set_UserAgent, set_Proxy ^[capa.txt] |
| Defense Evasion | T1222 File and Directory Permissions Modification | set_FileAttributes ^[capa.txt] |
| Defense Evasion | T1027 Obfuscated Files or Information | encode data using Base64, compress data using GZip ^[capa.txt] |
| Defense Evasion | T1620 Reflective Code Loading | invoke .NET assembly method (capa hit — likely false positive from Assembly.Load in updater context) ^[capa.txt] |
| Discovery | T1087 Account Discovery | get_SessionUserName, get_SessionIntegrityLevel ^[capa.txt] |
| Discovery | T1010 Application Window Discovery | find taskbar ^[capa.txt] |
| Discovery | T1083 File and Directory Discovery | enumerate files in .NET ^[capa.txt] |
| Discovery | T1057 Process Discovery | enumerate processes ^[capa.txt] |
| Discovery | T1518 Software Discovery | get_OSVersion ^[capa.txt] |
| Discovery | T1082 System Information Discovery | get_OSVersion (3 matches) ^[capa.txt] |
| Discovery | T1033 System Owner/User Discovery | get_SessionUserName ^[capa.txt] |
No evidence found for: persistence (registry Run, scheduled tasks, WMI), credential theft (browser DPAPI, vaults, wallets), lateral movement, or exfiltration beyond generic HTTP client capability.
Decompiled Behavior
Radare2 analysis completed at level 2 and discovered 3,309 CIL functions, but radare2's CIL support is limited — no meaningful pseudo-C decompilation was produced and cross-reference graphs are sparse. ^[r2:analysis-log] The binary's threat surface is best understood via string and capa analysis rather than decompiled control flow. No notable functions are singled out because the assembly is a standard C# WinForms executable with no custom obfuscation or packing stubs.
C2 Infrastructure
None recovered. No hardcoded IP addresses, domains, URLs, mutex names, named pipes, or registry keys were found in static strings. The HTTP surface is fully generic (.NET System.Net classes with configurable proxy/cookie/User-Agent). If C2 exists, it is likely runtime-resolved from an external config file or command-line argument.
Interesting Tidbits
- Debug build with intact PDB: The full PDB path
C:\Work\CSPlatform\V8\CSUpdater\CSUpdater\obj\Debug\CSUpdater.pdbis a strong benign indicator. Malware builders usually strip or randomize PDB paths; preserving a debug path suggests this was compiled directly from Visual Studio and not through a crimeware builder. ^[rabin2-info.txt:13] - Future-dated timestamp: PE timestamp
2087-02-23is typical of debug builds where the linker does not stamp a valid time. ^[pefile.txt:34] - Embedded fonts: Open Sans Regular, Bold, and Light TTF font files are embedded as resources for the MetroFramework UI skin — another benign artefact rarely seen in malware. ^[strings.txt:1488-1490]
- SHA1 certificate hashes: Sixteen 40-character hex strings in
.textare SHA1 hashes of the VeriSign/Thawte timestamping certificates embedded in the PE for Authenticode timestamp validation, not malware IOCs. ^[strings.txt:39-121] - No malicious filename masquerade: Unlike most samples in this corpus, the MalwareBazaar filename is just the MD5 (
0e8965c1aea9b42a3a34cddf0bbc3767.exe) with no invoice/payment/PO social-engineering theme. - Capa false-positive note: The
Reflective Code Loading(T1620) andFile and Directory Discovery(T1083) hits are standard for unobfuscated .NET debug builds. See debug-build-capa-false-positives.
How To Mess With It (Homelab Replication)
To build a comparable .NET updater stub:
- Create a C# WinForms project in Visual Studio targeting .NET Framework 4.0.
- Add NuGet packages:
MetroFramework(UI),SharpZipLib(zip/gzip). - Implement a simple downloader:
HttpWebRequest→WebResponse→FileStream, withWebClient.DownloadFileAsyncfor progress-bar feedback. - Add AES decryption via
RijndaelManaged+CryptoStreamif the payload is encrypted. - Use
ProcessStartInfowithUseShellExecute = trueto launch the extracted installer. - Compile in Debug configuration to reproduce the PDB path artefact.
- Verify: run
capaon the output. Expect hits forcommunication/http/client,data-manipulation/compression,data-manipulation/encryption/aes, andhost-interaction/process/create— matching this sample's fingerprint.
Deployable Signatures
YARA Rule
rule CSUpdater_MetroFramework_Updater
{
meta:
description = "Detects C# MetroFramework updater with SharpZipLib and CSUpdater naming"
author = "Titus"
date = "2026-07-27"
sha256 = "8a2247462598c070c36e83cf7a5944ca86c0bfcf1b9abda90192b23f9214d616"
confidence = "low"
strings:
$a1 = "CSUpdater.exe" ascii wide
$a2 = "CSUpdater.pdb" ascii wide
$a3 = "CSPlatform" ascii wide
$b1 = "MetroFramework" ascii wide
$b2 = "ICSharpCode.SharpZipLib" ascii wide
$b3 = "frmConsole" ascii wide
$b4 = "frmDown" ascii wide
$b5 = "ZipAESStream" ascii wide
$c1 = "ExecutePowerShellCommand" ascii wide
$c2 = "DownloadFileAsync" ascii wide
condition:
uint16(0) == 0x5A4D and
(3 of ($a*) or (2 of ($a*) and 3 of ($b*)) or (5 of ($b*) and 1 of ($c*)))
}
Behavioral Fingerprint
This binary is a .NET Framework 4.0 CIL GUI executable with MetroFramework WinForms controls and SharpZipLib compression. On execution it would likely:
- Display a Metro-styled download progress window (
frmDown). - Fetch a payload via
HttpWebRequest/WebClientusing configurable proxy and User-Agent. - Decrypt the payload with AES/Rijndael (ZipAES or managed AES) and decompress with GZip/Deflate.
- Stage files to a temporary path (
GetTempFileName) or target directory. - Optionally spawn PowerShell or a child process (
ProcessStartInfo) to complete installation. - Exit without registry persistence.
Detection gap: Without CAPE detonation, no network IOCs, file paths, or mutex names are available for hunt queries.
IOC List
| Type | Value | Note |
|---|---|---|
| SHA-256 | 8a2247462598c070c36e83cf7a5944ca86c0bfcf1b9abda90192b23f9214d616 |
Primary sample |
| SHA-1 | 48195e76a1f78afb8cf623fbcc5fa84d9217d483 |
|
| MD5 | 0e8965c1aea9b42a3a34cddf0bbc3767 |
MalwareBazaar filename |
| ssdeep | 24576:ASCSEYP2vQ9FrIJJpCNoh+7G+/3qlrCNoh+UqgIwhCNoh+J:EYRoGf/iJe2U |
|
| tlsh | T1ED823A2BA2C5D5FCC956C8D8D8D8D8D8D8D8D8D8D8D8D8D8D8D8D8D8D8D8D8D8 |
|
| Internal name | CSUpdater.exe |
|
| PDB path | C:\Work\CSPlatform\V8\CSUpdater\CSUpdater\obj\Debug\CSUpdater.pdb |
Benign debug artefact |
| YARA | PE_File_Generic |
Generic hit only |
Detection Signatures (capa → ATT&CK)
See capa.txt for full mapping. Notable hits:
communication/http/client→ T1071.001data-manipulation/encryption/aes→ T1573 (inferred)host-interaction/process/create→ T1106host-interaction/thread/create→ T1055 (inferred)host-interaction/mutex→ T1482 (inferred)
References
- MalwareBazaar:
https://bazaar.abuse.ch/sample/8a2247462598c070c36e83cf7a5944ca86c0bfcf1b9abda90192b23f9214d616/ - Wiki entity: unclassified-dotnet
- Related concept: debug-build-capa-false-positives
- Capa analysis:
sample 8a224746/capa.txt
Provenance
Static analysis performed on 2026-07-27 using:
filev5.44,exiftoolv12.76,pefile(Python),radare2v5.x,strings,binwalkv2.3.3,flare-capav9.x.- Radare2 opened at
<sample 8a2247462598.bin>; analysis level 2 completed (3,309 CIL functions). - No Ghidra/pyghidra decompilation available (module not installed on host).
- CAPE detonation skipped — no Windows guest available.