typeanalysisfamilymeshcentral-agent-dropperconfidencehighcreated2026-08-08updated2026-08-08pegolangdownloaderinstallerpersistencec2defense-evasion
SHA-256: 9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91

meshcentral-agent-dropper: 90989061 — Go 1.26.2 MeshCentral agent installer, azurenetfiles.net C2

Executive Summary

A Go 1.26.2 PE64+ compiled from meshdrop/main.go that downloads, validates, installs, and launches a MeshCentral remote-access agent as a Windows service. Hardcoded HTTPS C2 at azurenetfiles.net with embedded mesh ID. Distributed via the gcleaner dropper pipeline (OpenCTI label bb5.file is a distribution tag, not a technical family). One confirmed sibling (d65f14e5) shares identical source paths and C2 URL. Static-only — no CAPE detonation available.

What It Is

  • File: PE32+ executable (GUI) x86-64, 8 sections, 6,099,968 bytes ^[file.txt]
  • Compiler / Linker: Go 1.26.2, CGO_ENABLED=0, -trimpath=true ^[strings.txt:6380]
  • Go build ID: l1adTAVcMDhQZv7_h-4b/K9j-ERalHvuhleIF5KZE/lvQbcJnOFz4nMdeseY6x/DoMnCTM66l39NJiZxgt0 ^[strings.txt:9]
  • Module path: meshdrop (devel) ^[strings.txt:6377]
  • Source files recovered: meshdrop/main.go, meshdrop/exec_windows.go, meshdrop/install_windows.go ^[strings.txt:15610]
  • TimeDateStamp: 0x0 (stripped / reproducible build) ^[pefile.txt:34]
  • Signed: No — IMAGE_DIRECTORY_ENTRY_SECURITY empty, signed: false in rabin2 ^[rabin2-info.txt:27]
  • No VS_VERSIONINFO / resource directory ^[pefile.txt:246]
  • IAT: Minimal — only kernel32.dll imports (48 entries), no wininet/winhttp IAT entries; all networking via Go stdlib ^[pefile.txt:288]
  • OpenCTI labels: bb5.file, dropped-by-gcleaner, exe, f, malware-bazaar ^[triage.json]

How It Works

1. Build / RE

Toolchain: Go 1.26.2 with -trimpath=true and CGO_ENABLED=0. The build strips host paths but leaks the module name meshdrop and Go version via buildinfo and pclntab strings ^[strings.txt:6377]. This is a standard Go cross-compile for Windows AMD64 — no anti-analysis packing, no obfuscation, no UPX. The binary is almost entirely unmodified Go runtime (~2.7 MB .text) plus standard library HTTP/TLS/crypto code.

Anti-analysis: None observed statically. No debugger checks, no VM detection, no timing gates, no import table obfuscation. The binary relies on appearing benign (legitimate remote-access tool installer) rather than on technical evasion.

Code quality: The Go source follows idiomatic patterns — defer wrappers, error returns, context propagation. Function names are not randomized (unlike the acrstealer / lummastealer Go clusters), making static analysis trivial once the binary is recognized as Go.

2. Deploy / ATT&CK

Entry-point flow (inferred from recovered Go symbol names):

  1. main.main → checks admin rights (main.requireAdmin) and hides console window (main.hideWindow) ^[strings.txt:14239]
  2. main.download → HTTPS GET to https://azurenetfiles.net/meshagents?id=4&meshid=9Y7M9CsyteFGxSZPNyUB%4027EFbzf0wS%40r8bsW77uObPaWIigg2EiEGfpoYF%24W8Bb ^[strings.txt:6374]
  3. main.validatePE → checks the downloaded blob is a valid PE before writing to disk ^[strings.txt:14256]
  4. main.runInstall → stages the agent to a temp path (main.tempAgentPath), installs it as a Windows service (main.waitForService, main.serviceRunning, main.scRunning), and starts it ^[strings.txt:14243]
  5. main.runAgent → executes the installed agent binary ^[strings.txt:14245]

ATT&CK mapping:

Behavior Technique Evidence
Service installation T1543.003 — Create or Modify System Process: Windows Service main.waitForService, main.serviceRunning, main.scRunning, OpenSCManagerW in runtime strings ^[strings.txt:6112]
Admin privilege check T1088 — Bypass User Account Control (inferred) main.requireAdmin ^[strings.txt:14239]
Window hiding T1564.010 — Hide Artifacts: VBScript (analogous) main.hideWindow ^[strings.txt:14240]
HTTPS payload download T1105 — Ingress Tool Transfer Hardcoded azurenetfiles.net URL ^[strings.txt:6374]
PE validation before execution T1027.002 — Obfuscated Files or Information: Software Packing (analogous) main.validatePE ^[strings.txt:14256]
Masquerade as legitimate software T1036.005 — Masquerading: Match Legitimate Name or Location Installs to C:\Program Files\Mesh Agent\MeshAgent.exe ^[strings.txt:6152]

C2 Infrastructure:

  • URL: https://azurenetfiles.net/meshagents?id=4&meshid=9Y7M9CsyteFGxSZPNyUB%4027EFbzf0wS%40r8bsW77uObPaWIigg2EiEGfpoYF%24W8Bb ^[strings.txt:6374]
  • Domain: azurenetfiles.net
  • Mesh ID: Embedded in URL query parameter (URL-encoded @ as %40)
  • Protocol: HTTPS over TLS 1.2/1.3 via Go crypto/tls and net/http ^[strings.txt:2335]

Attribution:

  • Distributed via gcleaner dropper pipeline per OpenCTI label dropped-by-gcleaner ^[triage.json]
  • The bb5.file label is a distribution classification, not a technical family. The actual payload is a MeshCentral agent installer.
  • azurenetfiles.net domain masquerades as Azure cloud infrastructure — a common typosquatting / brand-abuse pattern.

Decompiled Behavior

Ghidra/r2 decompilation is unnecessary — the Go symbol table is intact and reveals the complete control flow. Key functions:

  • main.download — wraps net/http.Client.Do with HTTPS transport. No custom TLS pinning observed; uses system CA store via Go x509 root pool.
  • main.validatePE — likely parses DOS/NT headers and checks e_magic / Signature fields before writing to %TEMP%.
  • main.runInstall — uses Windows SCM APIs (OpenSCManagerW, CreateServiceW, StartServiceW) via syscall package to install MeshAgent.exe as a service.
  • main.runAgent — spawns the installed binary, likely via os/exec or direct CreateProcessW.

C2 Infrastructure

Indicator Value Type
C2 URL https://azurenetfiles.net/meshagents?id=4&meshid=9Y7M9CsyteFGxSZPNyUB%4027EFbzf0wS%40r8bsW77uObPaWIigg2EiEGfpoYF%24W8Bb hardcoded HTTPS download
Domain azurenetfiles.net brand-typosquatting
Install path C:\Program Files\Mesh Agent\MeshAgent.exe hardcoded service binary path
Service name Mesh Agent (inferred from path) Windows service

Interesting Tidbits

  • Sibling cluster: Sample d65f14e5 (OpenCTI label uniq.file, also dropped-by-gcleaner) is a near-identical build — same meshdrop module, same azurenetfiles.net C2 URL, same Go 1.26.2 version, size delta only ~15 KB. Confirms builder-template constancy across distribution labels ^[sample d65f14e5/strings.txt].
  • FIPS 140 mode: Build flags include FIPS 140-3 references (crypto/internal/fips140/*) — unusual for crimeware, likely inherited from the upstream Go 1.26 toolchain defaults ^[strings.txt:5289].
  • No .rsrc section: No icons, no version info, no manifest — bare Go binary. This is actually anti-triage because it looks like a command-line tool rather than a GUI application despite the PE subsystem flag.
  • MeshCentral abuse: MeshCentral is a legitimate open-source remote-management platform. This sample weaponizes its agent installer for unauthorized remote access — a textbook case of legitimate-remote-access-tool-abuse.

How To Mess With It (Homelab Replication)

Toolchain: Go 1.26.2 for Windows AMD64 Build flags: CGO_ENABLED=0 GOOS=windows GOARCH=amd64 go build -trimpath -ldflags="-s -w" Verification: Build a minimal HTTPS downloader + service installer in Go using net/http + golang.org/x/sys/windows/svc. Compare capa fingerprint — should hit T1105 and T1543.003 if capa signatures are installed.

What you'll learn: How Go's buildinfo and pclntab leak module paths even with -trimpath, and how trivial it is to recognize a Go binary versus a C/C++ one by section entropy and string density.

Deployable Signatures

YARA rule

rule MESHDROP_Go126_MeshCentral_Installer {
    meta:
        description = "Go 1.26.2 MeshCentral agent dropper (meshdrop)"
        author = "PacketPursuit"
        date = "2026-08-08"
        hash1 = "9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91"
        hash2 = "d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1"
    strings:
        $go_build = "go1.26.2" ascii
        $mod_path = "path\tmeshdrop" ascii
        $c2_url = "https://azurenetfiles.net/meshagents" ascii
        $func1 = "main.download" ascii
        $func2 = "main.validatePE" ascii
        $func3 = "main.runInstall" ascii
        $func4 = "main.runAgent" ascii
        $install_path = "C:\\Program Files\\Mesh Agent\\MeshAgent.exe" ascii
        $svc1 = "OpenSCManagerW" ascii
        $svc2 = "QueryServiceStatus" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        $mod_path and
        ($c2_url or $install_path) and
        2 of ($func*) and
        1 of ($svc*)
}

Sigma rule

title: MeshCentral Agent Dropper Execution
description: Detects Go-based MeshCentral agent installer downloading payload and installing Windows service
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Image|endswith: '\\MeshAgent.exe'
    - CommandLine|contains:
        - 'Mesh Agent'
        - 'azurenetfiles'
  network:
    Initiated: 'true'
    DestinationHostname|contains: 'azurenetfiles.net'
  condition: selection or network
falsepositives:
  - Legitimate MeshCentral agent installation by authorized IT staff
level: high

IOC list

Indicator Type Context
9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91 SHA-256 This sample
d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1 SHA-256 Confirmed sibling
azurenetfiles.net Domain C2 / payload hosting
https://azurenetfiles.net/meshagents?id=4&meshid=... URL Hardcoded download URL
C:\Program Files\Mesh Agent\MeshAgent.exe File path Install target
Mesh Agent Service name Windows service (inferred)

Behavioral fingerprint statement

This binary is a Go 1.26.2 PE64+ with a minimal IAT (kernel32 only) and no .rsrc section. Within 30 seconds of launch, it performs an HTTPS GET to azurenetfiles.net, writes a downloaded PE to a temporary path under %TEMP%, validates the DOS/NT headers, then uses the Windows Service Control Manager to install the payload as a service named "Mesh Agent" under C:\Program Files\Mesh Agent\. The process tree will show the parent Go binary spawning MeshAgent.exe or svchost-like service execution.

Detection Signatures

Capability ATT&CK Source
Ingress Tool Transfer T1105 Hardcoded HTTPS download URL ^[strings.txt:6374]
Create or Modify System Process: Windows Service T1543.003 SCM API strings + main.*Service* functions ^[strings.txt:6112]
Masquerading T1036.005 Installs to Program Files\Mesh Agent\ ^[strings.txt:6152]
Abuse Legitimate Remote Access Software T1219 MeshCentral agent abuse ^[strings.txt:6377]

References

  • Sample: 9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91
  • Sibling: d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1
  • OpenCTI labels: bb5.file, dropped-by-gcleaner, uniq.file
  • MeshCentral project: https://github.com/Ylianst/MeshCentral (legitimate open-source tool)
  • Related wiki pages: meshcentral-agent-dropper, gcleaner, legitimate-remote-access-tool-abuse

Provenance

Analysis derived from static artefacts in raw/analyses/9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91/:

  • file.txt — file type identification
  • pefile.txt — PE header and import table inspection
  • strings.txt — string extraction (Go symbols, URLs, API names)
  • rabin2-info.txt — radare2 binary summary
  • triage.json — OpenCTI labels and family classification
  • binwalk.txt — embedded artefact scan
  • metadata.json — artifact metadata Tools: strings, pefile, rabin2 (radare2 5.9.8), binwalk. No Ghidra decompilation required — Go symbol table was intact.