9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91meshcentral-agent-dropper: 90989061 — Go 1.26.2 MeshCentral agent installer, azurenetfiles.net C2
Executive Summary
A Go 1.26.2 PE64+ compiled from meshdrop/main.go that downloads, validates, installs, and launches a MeshCentral remote-access agent as a Windows service. Hardcoded HTTPS C2 at azurenetfiles.net with embedded mesh ID. Distributed via the gcleaner dropper pipeline (OpenCTI label bb5.file is a distribution tag, not a technical family). One confirmed sibling (d65f14e5) shares identical source paths and C2 URL. Static-only — no CAPE detonation available.
What It Is
- File: PE32+ executable (GUI) x86-64, 8 sections, 6,099,968 bytes ^[file.txt]
- Compiler / Linker: Go 1.26.2,
CGO_ENABLED=0,-trimpath=true^[strings.txt:6380] - Go build ID:
l1adTAVcMDhQZv7_h-4b/K9j-ERalHvuhleIF5KZE/lvQbcJnOFz4nMdeseY6x/DoMnCTM66l39NJiZxgt0^[strings.txt:9] - Module path:
meshdrop(devel) ^[strings.txt:6377] - Source files recovered:
meshdrop/main.go,meshdrop/exec_windows.go,meshdrop/install_windows.go^[strings.txt:15610] - TimeDateStamp: 0x0 (stripped / reproducible build) ^[pefile.txt:34]
- Signed: No — IMAGE_DIRECTORY_ENTRY_SECURITY empty,
signed: falsein rabin2 ^[rabin2-info.txt:27] - No VS_VERSIONINFO / resource directory ^[pefile.txt:246]
- IAT: Minimal — only
kernel32.dllimports (48 entries), nowininet/winhttpIAT entries; all networking via Go stdlib ^[pefile.txt:288] - OpenCTI labels:
bb5.file,dropped-by-gcleaner,exe,f,malware-bazaar^[triage.json]
How It Works
1. Build / RE
Toolchain: Go 1.26.2 with -trimpath=true and CGO_ENABLED=0. The build strips host paths but leaks the module name meshdrop and Go version via buildinfo and pclntab strings ^[strings.txt:6377]. This is a standard Go cross-compile for Windows AMD64 — no anti-analysis packing, no obfuscation, no UPX. The binary is almost entirely unmodified Go runtime (~2.7 MB .text) plus standard library HTTP/TLS/crypto code.
Anti-analysis: None observed statically. No debugger checks, no VM detection, no timing gates, no import table obfuscation. The binary relies on appearing benign (legitimate remote-access tool installer) rather than on technical evasion.
Code quality: The Go source follows idiomatic patterns — defer wrappers, error returns, context propagation. Function names are not randomized (unlike the acrstealer / lummastealer Go clusters), making static analysis trivial once the binary is recognized as Go.
2. Deploy / ATT&CK
Entry-point flow (inferred from recovered Go symbol names):
main.main→ checks admin rights (main.requireAdmin) and hides console window (main.hideWindow) ^[strings.txt:14239]main.download→ HTTPS GET tohttps://azurenetfiles.net/meshagents?id=4&meshid=9Y7M9CsyteFGxSZPNyUB%4027EFbzf0wS%40r8bsW77uObPaWIigg2EiEGfpoYF%24W8Bb^[strings.txt:6374]main.validatePE→ checks the downloaded blob is a valid PE before writing to disk ^[strings.txt:14256]main.runInstall→ stages the agent to a temp path (main.tempAgentPath), installs it as a Windows service (main.waitForService,main.serviceRunning,main.scRunning), and starts it ^[strings.txt:14243]main.runAgent→ executes the installed agent binary ^[strings.txt:14245]
ATT&CK mapping:
| Behavior | Technique | Evidence |
|---|---|---|
| Service installation | T1543.003 — Create or Modify System Process: Windows Service | main.waitForService, main.serviceRunning, main.scRunning, OpenSCManagerW in runtime strings ^[strings.txt:6112] |
| Admin privilege check | T1088 — Bypass User Account Control (inferred) | main.requireAdmin ^[strings.txt:14239] |
| Window hiding | T1564.010 — Hide Artifacts: VBScript (analogous) | main.hideWindow ^[strings.txt:14240] |
| HTTPS payload download | T1105 — Ingress Tool Transfer | Hardcoded azurenetfiles.net URL ^[strings.txt:6374] |
| PE validation before execution | T1027.002 — Obfuscated Files or Information: Software Packing (analogous) | main.validatePE ^[strings.txt:14256] |
| Masquerade as legitimate software | T1036.005 — Masquerading: Match Legitimate Name or Location | Installs to C:\Program Files\Mesh Agent\MeshAgent.exe ^[strings.txt:6152] |
C2 Infrastructure:
- URL:
https://azurenetfiles.net/meshagents?id=4&meshid=9Y7M9CsyteFGxSZPNyUB%4027EFbzf0wS%40r8bsW77uObPaWIigg2EiEGfpoYF%24W8Bb^[strings.txt:6374] - Domain:
azurenetfiles.net - Mesh ID: Embedded in URL query parameter (URL-encoded
@as%40) - Protocol: HTTPS over TLS 1.2/1.3 via Go
crypto/tlsandnet/http^[strings.txt:2335]
Attribution:
- Distributed via
gcleanerdropper pipeline per OpenCTI labeldropped-by-gcleaner^[triage.json] - The
bb5.filelabel is a distribution classification, not a technical family. The actual payload is a MeshCentral agent installer. azurenetfiles.netdomain masquerades as Azure cloud infrastructure — a common typosquatting / brand-abuse pattern.
Decompiled Behavior
Ghidra/r2 decompilation is unnecessary — the Go symbol table is intact and reveals the complete control flow. Key functions:
main.download— wrapsnet/http.Client.Dowith HTTPS transport. No custom TLS pinning observed; uses system CA store via Go x509 root pool.main.validatePE— likely parses DOS/NT headers and checkse_magic/Signaturefields before writing to%TEMP%.main.runInstall— uses Windows SCM APIs (OpenSCManagerW,CreateServiceW,StartServiceW) viasyscallpackage to installMeshAgent.exeas a service.main.runAgent— spawns the installed binary, likely viaos/execor directCreateProcessW.
C2 Infrastructure
| Indicator | Value | Type |
|---|---|---|
| C2 URL | https://azurenetfiles.net/meshagents?id=4&meshid=9Y7M9CsyteFGxSZPNyUB%4027EFbzf0wS%40r8bsW77uObPaWIigg2EiEGfpoYF%24W8Bb |
hardcoded HTTPS download |
| Domain | azurenetfiles.net |
brand-typosquatting |
| Install path | C:\Program Files\Mesh Agent\MeshAgent.exe |
hardcoded service binary path |
| Service name | Mesh Agent (inferred from path) |
Windows service |
Interesting Tidbits
- Sibling cluster: Sample
d65f14e5(OpenCTI labeluniq.file, alsodropped-by-gcleaner) is a near-identical build — samemeshdropmodule, sameazurenetfiles.netC2 URL, same Go 1.26.2 version, size delta only ~15 KB. Confirms builder-template constancy across distribution labels ^[sample d65f14e5/strings.txt]. - FIPS 140 mode: Build flags include FIPS 140-3 references (
crypto/internal/fips140/*) — unusual for crimeware, likely inherited from the upstream Go 1.26 toolchain defaults ^[strings.txt:5289]. - No .rsrc section: No icons, no version info, no manifest — bare Go binary. This is actually anti-triage because it looks like a command-line tool rather than a GUI application despite the PE subsystem flag.
- MeshCentral abuse: MeshCentral is a legitimate open-source remote-management platform. This sample weaponizes its agent installer for unauthorized remote access — a textbook case of legitimate-remote-access-tool-abuse.
How To Mess With It (Homelab Replication)
Toolchain: Go 1.26.2 for Windows AMD64
Build flags: CGO_ENABLED=0 GOOS=windows GOARCH=amd64 go build -trimpath -ldflags="-s -w"
Verification: Build a minimal HTTPS downloader + service installer in Go using net/http + golang.org/x/sys/windows/svc. Compare capa fingerprint — should hit T1105 and T1543.003 if capa signatures are installed.
What you'll learn: How Go's buildinfo and pclntab leak module paths even with -trimpath, and how trivial it is to recognize a Go binary versus a C/C++ one by section entropy and string density.
Deployable Signatures
YARA rule
rule MESHDROP_Go126_MeshCentral_Installer {
meta:
description = "Go 1.26.2 MeshCentral agent dropper (meshdrop)"
author = "PacketPursuit"
date = "2026-08-08"
hash1 = "9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91"
hash2 = "d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1"
strings:
$go_build = "go1.26.2" ascii
$mod_path = "path\tmeshdrop" ascii
$c2_url = "https://azurenetfiles.net/meshagents" ascii
$func1 = "main.download" ascii
$func2 = "main.validatePE" ascii
$func3 = "main.runInstall" ascii
$func4 = "main.runAgent" ascii
$install_path = "C:\\Program Files\\Mesh Agent\\MeshAgent.exe" ascii
$svc1 = "OpenSCManagerW" ascii
$svc2 = "QueryServiceStatus" ascii
condition:
uint16(0) == 0x5A4D and
$go_build and
$mod_path and
($c2_url or $install_path) and
2 of ($func*) and
1 of ($svc*)
}
Sigma rule
title: MeshCentral Agent Dropper Execution
description: Detects Go-based MeshCentral agent installer downloading payload and installing Windows service
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: '\\MeshAgent.exe'
- CommandLine|contains:
- 'Mesh Agent'
- 'azurenetfiles'
network:
Initiated: 'true'
DestinationHostname|contains: 'azurenetfiles.net'
condition: selection or network
falsepositives:
- Legitimate MeshCentral agent installation by authorized IT staff
level: high
IOC list
| Indicator | Type | Context |
|---|---|---|
9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91 |
SHA-256 | This sample |
d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1 |
SHA-256 | Confirmed sibling |
azurenetfiles.net |
Domain | C2 / payload hosting |
https://azurenetfiles.net/meshagents?id=4&meshid=... |
URL | Hardcoded download URL |
C:\Program Files\Mesh Agent\MeshAgent.exe |
File path | Install target |
Mesh Agent |
Service name | Windows service (inferred) |
Behavioral fingerprint statement
This binary is a Go 1.26.2 PE64+ with a minimal IAT (kernel32 only) and no .rsrc section. Within 30 seconds of launch, it performs an HTTPS GET to azurenetfiles.net, writes a downloaded PE to a temporary path under %TEMP%, validates the DOS/NT headers, then uses the Windows Service Control Manager to install the payload as a service named "Mesh Agent" under C:\Program Files\Mesh Agent\. The process tree will show the parent Go binary spawning MeshAgent.exe or svchost-like service execution.
Detection Signatures
| Capability | ATT&CK | Source |
|---|---|---|
| Ingress Tool Transfer | T1105 | Hardcoded HTTPS download URL ^[strings.txt:6374] |
| Create or Modify System Process: Windows Service | T1543.003 | SCM API strings + main.*Service* functions ^[strings.txt:6112] |
| Masquerading | T1036.005 | Installs to Program Files\Mesh Agent\ ^[strings.txt:6152] |
| Abuse Legitimate Remote Access Software | T1219 | MeshCentral agent abuse ^[strings.txt:6377] |
References
- Sample:
9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91 - Sibling:
d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1 - OpenCTI labels:
bb5.file,dropped-by-gcleaner,uniq.file - MeshCentral project: https://github.com/Ylianst/MeshCentral (legitimate open-source tool)
- Related wiki pages: meshcentral-agent-dropper, gcleaner, legitimate-remote-access-tool-abuse
Provenance
Analysis derived from static artefacts in raw/analyses/9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91/:
file.txt— file type identificationpefile.txt— PE header and import table inspectionstrings.txt— string extraction (Go symbols, URLs, API names)rabin2-info.txt— radare2 binary summarytriage.json— OpenCTI labels and family classificationbinwalk.txt— embedded artefact scanmetadata.json— artifact metadata Tools: strings, pefile, rabin2 (radare2 5.9.8), binwalk. No Ghidra decompilation required — Go symbol table was intact.