9a69ad1b616d4cd2d475b2d4ddf98f3446ea9da715cb1ec7ac263c1f853eeae19a69ad1b — .NET 9 Native AOT DLL with Chromium/Edge ELF Export Masquerade
Build / RE
Toolchain: .NET 9 SDK with PublishAot=true, RID win-x64. Linker MSVC 14.40 (Visual Studio 2022 v143). ^[file.txt] ^[exiftool.json:18]
Native AOT artefacts: System.Private.CoreLib, System.Collections, System.Linq, System.Private.Reflection.Execution, System.Private.TypeLoader, System.Text.RegularExpressions all inlined — no external framework dependency. ^[strings.txt] COM_DESCRIPTOR RVA is 0x0, confirming zero CLR metadata. ^[pefile.txt]
Export table (163 entries): 39 legitimate Microsoft Edge / Chromium ELF export names mixed with 124 randomized alphanumeric noise names (e.g., 03Z1V9eKQfj7aZO4lZ5BknYZe, 08MBh2GSIL8VIQk7kZGA0). ^[pefile.txt:333] The real names include full edge_pwahelper::PwaHelperImpl vtable methods (ctor, dtor, BadgeNotification, DigitalGoodsConsume, PinTileToTaskbar, ValidateHandShake, InitMojo, etc.) plus Crashpad/Chrome ELF thunks (SignalChromeElf, EdgeGetElfCommandLine, GetCrashpadDatabasePath_ExportThunk, InjectDumpForHungInput_ExportThunk). ^[strings.txt:6068-6161] All 163 exports resolve to tiny stubs in the .text section — the table is deliberately flooded to hide the true entry point among noise.
Version-info masquerade: VS_VERSIONINFO block claims CompanyName="Crankily LLC", ProductName="Sheldrakes Flamencos", FileDescription="Autotoxic barleysick micrometry suffragancy outfencing variegates interfulgent lanson hemiparasitic.", OriginalFilename="ReviewabilityPersuasions.exe", InternalName="Receptaculitidae Alodium", LegalCopyright="© 2026 Crankily LLC", version 8.73.773.26. ^[exiftool.json:36-43] Pure gibberish — no known software vendor matches these strings.
Packing / obfuscation: None. No UPX, no Themida, no ConfuserEx. High entropy in .text (6.57) and .rdata (6.74) is explained by the self-contained Native AOT runtime and the large export-name string table. ^[entropy check via pefile]
Anti-analysis:
- Export-table semantic-jargon obfuscation — a novel pattern in this corpus. By embedding real Chromium/Edge ELF API names among random noise, the malware evades naive export-string clustering while still exposing enough legitimate-looking exports to appear benign during superficial triage.
- Native AOT compilation defeats dnSpy/ILSpy/de4dot; no IL to disassemble.
Code quality: The entry point (entry0 at 0x180137954) is a short 357-byte stub with 26 basic blocks and cyclomatic complexity 15 — typical of the AOT runtime bootstrap. ^[r2:entry0] No custom encryption loop or payload staging visible in the first-level decompilation.
Signing: Unsigned. No Authenticode signature block present. ^[pefile.txt]
Embedded resources: Single 976-byte VS_VERSIONINFO in .rsrc (RT_VERSION). No icons, no bitmap carriers, no encrypted payload resource. ^[pefile.txt]
Deploy / ATT&CK
Dynamic analysis: Unavailable — CAPE skipped (no Windows guest). Static-only inference follows. ^[dynamic-analysis.md]
No observable malicious behaviour from static:
- Zero C2 URLs, IP addresses, or domain strings. ^[strings.txt grep for TLDs / IP patterns]
- Zero persistence mechanism strings (Run keys, scheduled tasks, services, Startup folder). ^[strings.txt grep for registry / schtasks / services]
- Zero network API imports (
WinInet,WinHTTP,URLMon,WSAStartup,socket,connect). The IAT surface is limited tontdll,KERNEL32,ADVAPI32,ole32,bcrypt— all standard Windows DLLs. ^[pefile.txt] - No Powershell, cmd.exe, WScript, or other staging strings. ^[strings.txt]
TTPs inferred from build artefacts and masquerade:
- T1027.002 — Obfuscated Files or Information: export-table semantic-jargon obfuscation. ^[techniques/semantic-jargon-export-obfuscation.md]
- T1036.005 — Match Legitimate Name or Location: full Chromium/Edge ELF / Crashpad export name reuse to masquerade as a browser component DLL. ^[concepts/version-info-masquerade.md]
- T1562.001 — Impair Defenses: Native AOT compilation removes all CLR metadata, defeating conventional .NET analysis tools and EDR reflection-based detections.
Attribution: None. No linguistic clues, no PDB path, no build-machine artefacts, no hardcoded infrastructure. The fabricated company name "Crankily LLC" and product name "Sheldrakes Flamencos" are random English dictionary words, not culturally specific. The Chromium export names indicate the author had access to the Edge/Chromium source or symbol dump, but that is public knowledge.
Family placement: Fits the unclassified-dotnet-native-aot-loader umbrella — third confirmed sibling. Divergent from prior siblings (fbc07658, ef48ae9e) in that it uses export-table masquerade instead of an encrypted payload resource, and masquerades as Microsoft Edge / Chromium rather than a generic utility. No overlap with valleyrat or silverfox build artefacts.
IOCs
| Type | Value | Note |
|---|---|---|
| SHA-256 | 9a69ad1b616d4cd2d475b2d4ddf98f3446ea9da715cb1ec7ac263c1f853eeae1 |
|
| Compile timestamp | 2025-10-22 21:05:34 UTC |
^[exiftool.json:15] |
| File size | 2.5 MB (2,560,512 bytes) | |
| PE type | PE32+ DLL, GUI, x64 | ^[file.txt] |
| OriginalFilename | ReviewabilityPersuasions.exe |
^[exiftool.json:41] |
| InternalName | Receptaculitidae Alodium |
^[exiftool.json:42] |
| CompanyName | Crankily LLC |
^[exiftool.json:36] |
| ProductName | Sheldrakes Flamencos |
^[exiftool.json:37] |
| FileVersion | 8.73.773.26 |
^[exiftool.json:39] |
| Export count | 163 (39 real Edge/Chrome ELF + 124 noise) | ^[pefile.txt:333] |
| CLR metadata | Absent (COM_DESCRIPTOR RVA = 0) |
^[pefile.txt] |
| Authenticode | Unsigned | ^[pefile.txt] |
| .rsrc content | 976-byte RT_VERSION only | ^[pefile.txt] |
| Sections | .text, .rdata, .data, .pdata, .rsrc, .reloc | ^[pefile.txt] |
Verdict
Medium-confidence placement in unclassified-dotnet-native-aot-loader. The binary is a deliberately crafted anti-analysis artefact: Native AOT to strip CLR metadata, a massive export table mixing real Chromium names with random noise to poison clustering and string-based detection, and fabricated version-info to survive superficial triage. No payload or C2 recovered statically; the threat may lie in a companion file, a reflective loader, or runtime-decrypted secondary stage not present in the PE image. Without CAPE detonation, the true runtime behaviour is unknown.