a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4coinminer: a80c26e2 — .NET ConfuserEx crypter/loader with Rijndael+Deflate resource payload, May 2026 build
Executive Summary
A 7.1 MB .NET Framework PE32 executable compiled 2026-05-25 and packed with Confuser v1.9.0.0. The outer binary decrypts a ~7.3 MB embedded manifest resource via RijndaelManaged + DeflateStream, then reflectively loads the inner payload via DynamicMethod/ILGenerator and P/Invoke bridging. No network IOCs are recoverable statically; all C2 capability lives inside the encrypted resource. The preliminary OpenCTI coinminer label is low-confidence — the build fingerprint (.NET crypter/loader, ConfuserEx, May 2026) diverges sharply from the established PyInstaller coinminer cluster (MSVC 14.0, Sep 2018, zlib/AES overlay). This sample is a sibling of the unclassified-dotnet-crypter-loader family.
What It Is
- SHA-256:
a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4 - Size: 7,447,040 bytes (7.1 MB) ^[file.txt]
- Type: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 4 sections ^[file.txt]
- Compiled: Mon May 25 16:52:26 2026 UTC ^[rabin2-info.txt:11] ^[pefile.txt:34]
- Internal name:
Small.exe^[pefile.txt:256] - Version info: 0.0.0.0 across all fields, empty FileDescription/LegalCopyright ^[pefile.txt:254-259]
- Family attribution: Preliminary
coinminer(OpenCTI label). Low confidence — build stack is a .NET crypter/loader, not the PyInstaller cluster.
How It Works
Build / RE
Toolchain: .NET Framework 4.0+ (CLR v4.0.30319) ^[CLR header metadata analysis]. The PE carries a standard COR20 header with EntryPointToken 0x6000005 and 5 metadata streams (#-, #Strings, #US, #GUID, #Blob).
Obfuscator: Confuser v1.9.0.0 watermark present in #Strings metadata ^[strings.txt:13073]. All type/method/field names are stripped; only mscorlib namespace strings survive static extraction. Control-flow flattening and constant encryption are standard ConfuserEx behaviours; decompilers will fail to produce readable C# without deobfuscation.
Anti-analysis:
IsDebuggerPresentstring in metadata ^[strings.txt:13027]COR_ENABLE_PROFILING,COR_PROFILER, "Profiler detected", "Debugger detected (Managed)" ^[strings.txt:13053]- "Loop broken", "Module error", "Broken file" — likely anti-tamper or integrity-check failure messages ^[strings.txt]
- High-entropy
.text(7.51) and custom-named section9gSGXF+U(7.01) impede static clustering ^[pefile.txt:92,152]
Payload staging: Two encrypted containers:
- Embedded manifest resource (~7.29 MB at RVA
0x6d4cinside.text) — the primary payload. First 256 bytes show no recognizable magic; data is uniformly high-entropy ^[CLR header analysis]. - Custom section
9gSGXF+U(20,904 bytes, entropy 7.01) at RVA0x71c000— no recognizable header; likely secondary config or stage-2 payload ^[pefile.txt:138-156].
IAT: Only mscoree.dll!_CorExeMain ^[pefile.txt:271]. All other APIs resolved via .NET reflection or P/Invoke at runtime.
Signing: Unsigned ^[rabin2-info.txt:27].
Deploy / ATT&CK
Static-only analysis; CAPE skipped — no Windows guest available ^[dynamic-analysis.md]. Runtime behaviour inferred from recovered .NET API strings.
| MITRE ATT&CK | Technique | Evidence |
|---|---|---|
| T1027 | Obfuscated Files or Information | ConfuserEx v1.9.0.0 name stripping + control-flow flattening ^[strings.txt:13073] ^[capa.txt] |
| T1140 | Deobfuscate/Decode Files or Information | RijndaelManaged → CreateDecryptor → CryptoStream → DeflateStream chain on embedded resource ^[strings.txt:12952,12958,12960,12937] |
| T1620 | Reflective Code Loading | DynamicMethod + ILGenerator + GetDelegateForFunctionPointer + Assembly.Load ^[strings.txt:12964-12988] |
| T1055 | Process Injection (inferred) | Hidden ProcessStartInfo with set_CreateNoWindow, set_UseShellExecute, set_FileName, ExpandEnvironmentVariables ^[strings.txt:12771-12803] |
| T1129 | Shared Modules | GetManifestResourceStream + Assembly.GetExecutingAssembly resource resolution ^[strings.txt:12801,12997] |
| T1560.002 | Archive Collected Data::Archive via Library | DeflateStream decompression inside decryption pipeline ^[strings.txt:12937] |
| T1496 | Resource Hijacking | Cryptocurrency miner payload (preliminary family label; inner payload not recovered statically) |
Persistence: Not observed in outer binary. Any persistence would be enacted by the decrypted inner payload.
C2 / Network: No IP, domain, URL, or pool strings recovered statically. The ~7.3 MB encrypted resource likely encapsulates all network logic. This is consistent with crypter/loader design: the outer binary is a delivery vehicle, the inner payload holds the threat logic.
Attribution: No linguistic clues, infrastructure overlap, or code-reuse indicators visible in the outer binary. The Small.exe / MyApplication.app masquerade is a generic ConfuserEx default artefact, not a targeted lure.
Decompiled Behavior
Ghidra decompilation was not attempted; radare2 CIL support produces only raw IL bytecode with switch-based dispatch, which is unreadable against ConfuserEx-flattened control flow. The behavioural narrative above is reconstructed from:
- Recovered .NET namespace/type/method strings (see strings.txt lines 12771-13073)
- COR20 header and metadata stream inspection
- Section entropy and layout analysis
- Capa "packed sample" warning (file limitation) ^[capa.txt]
C2 Infrastructure
None recoverable statically. The encrypted manifest resource (~7.29 MB) and the 9gSGXF+U section (~20 KB) are both opaque without the runtime decryption key.
Interesting Tidbits
- Fresh compilation date: May 25 2026 is the most recent compilation timestamp observed in this corpus for any family. Either this is a live campaign or the timestamp is fabricated. ^[pefile.txt:34]
- Massive encrypted resource: 7.29 MB inside a 7.45 MB binary — 97.7% of the file is the encrypted payload. This dwarfs most crypter/loader siblings in the corpus. ^[CLR header analysis]
- No
#=q…==name mangling: Unlike typical ConfuserEx samples, this binary does not show the classic#=q[A-Za-z0-9_$]{10,}==mangled identifiers in strings. The obfuscation may be a newer ConfuserEx fork or a different mode (e.g.,koitoken renaming) that strips all readable names. ^[strings.txt] - Custom section name
9gSGXF+U: Randomized 8-character section names are sometimes used by crypters to evade signature-based clustering. The section is small (20 KB) but high-entropy, suggesting it is encrypted rather than compressed. ^[pefile.txt:138-156] - Floss failure: The
floss.txtoutput shows only the__main__.pyhelp text, indicating FireEye flare-floss could not extract any decoded strings from this binary. ConfuserEx string encryption is working as designed. ^[floss.txt]
How To Mess With It (Homelab Replication)
Goal: Reproduce a comparable ConfuserEx-obfuscated .NET crypter/loader that decrypts a resource payload at runtime.
-
Build a trivial .NET payload
// Any .NET console app Console.WriteLine("Payload executed"); -
Encrypt the payload
byte[] payload = File.ReadAllBytes("payload.exe"); byte[] key = Encoding.UTF8.GetBytes("weakpassword1234"); // 128-bit using (var aes = new RijndaelManaged()) { aes.Key = key; aes.GenerateIV(); using (var ms = new MemoryStream()) { ms.Write(aes.IV, 0, 16); using (var cs = new CryptoStream(ms, aes.CreateEncryptor(), CryptoStreamMode.Write)) using (var ds = new DeflateStream(cs, CompressionMode.Compress)) ds.Write(payload, 0, payload.Length); File.WriteAllBytes("encrypted.bin", ms.ToArray()); } } -
Embed as manifest resource in a .NET loader stub that reverses the pipeline (
DeflateStream→CryptoStream→Assembly.Load). -
Apply ConfuserEx with maximum preset (constant encryption, control-flow flattening, anti-tamper).
-
Verify:
capa <output.exe>should hitpackedlimitation;stringsshould show only mscorlib namespaces and anti-debug strings.
Deployable Signatures
YARA rule
rule ConfuserEx_Crypter_Loader_May2026
{
meta:
description = "ConfuserEx v1.9 .NET crypter/loader with Rijndael+Deflate resource payload"
author = "PacketPursuit"
date = "2026-07-31"
sha256 = "a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4"
strings:
$confuser = "Confuser v1.9.0.0" ascii wide
$rijndael = "RijndaelManaged" ascii wide
$deflate = "DeflateStream" ascii wide
$dynmethod = "DynamicMethod" ascii wide
$ilgen = "ILGenerator" ascii wide
$res_stream = "GetManifestResourceStream" ascii wide
$debug = "Debugger detected (Managed)" ascii wide
$profiler = "Profiler detected" ascii wide
$small = "Small.exe" ascii wide
$myapp = "MyApplication.app" ascii wide
condition:
uint16(0) == 0x5A4D and
pe.is_dotnet and
$confuser and
($rijndael or $deflate) and
($dynmethod or $ilgen or $res_stream) and
3 of ($debug, $profiler, $small, $myapp)
}
Behavioral fingerprint
This binary is a .NET Framework PE32 with a single native import (mscoree.dll!_CorExeMain). At startup it resolves an embedded manifest resource via GetManifestResourceStream, decrypts the blob via RijndaelManaged/CryptoStream, decompresses with DeflateStream, and loads the resulting assembly reflectively using DynamicMethod/ILGenerator and Assembly.Load. Anti-debug strings (Debugger detected, Profiler detected) and IsDebuggerPresent checks are present in metadata. No meaningful type/method names survive static extraction. The file is 97%+ encrypted payload by volume.
IOC list
- SHA-256:
a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4 - SSDeep:
196608:Z1v4Bb/JcgkqsR7tIole3lHWXzLlt33XCpyRqe2nkR2:Z0b/OlC3lHWXzhtypy - TLSH:
61763317568772BDC26117B063ACA170F2B26D5FD7C98EDDA88BB9B0AC108083F3D955 - Internal name:
Small.exe - Original filename:
Small.exe - Confuser version:
v1.9.0.0 - Compilation timestamp:
2026-05-25 16:52:26 UTC - Custom section name:
9gSGXF+U
Detection Signatures
| Capability | ATT&CK | Evidence |
|---|---|---|
| uses .NET resource stream | T1129 | GetManifestResourceStream in metadata ^[strings.txt:12801] |
| decrypts payload with AES/Rijndael | T1140 | RijndaelManaged, CreateDecryptor, CryptoStream ^[strings.txt:12952,12958,12960] |
| decompresses payload with Deflate | T1560.002 | DeflateStream ^[strings.txt:12937] |
| reflective code loading | T1620 | DynamicMethod, ILGenerator, CreateDelegate ^[strings.txt:12964-12981] |
| hidden process execution | T1055 (inferred) | ProcessStartInfo, set_CreateNoWindow, set_UseShellExecute ^[strings.txt:12771-12803] |
| anti-debug check | T1622 | IsDebuggerPresent, "Debugger detected (Managed)" ^[strings.txt:13027,13053] |
| anti-profiling check | T1622 | COR_ENABLE_PROFILING, "Profiler detected" ^[strings.txt:13053] |
References
- Artifact ID:
c85dd29b-22ca-4e0f-b5bb-30a885d084a5 - OpenCTI labels:
coinminer,exe,urlhaus - Related wiki pages: coinminer, confuserex-obfuscation, unclassified-dotnet-crypter-loader, dotnet-manifest-resource-decryption
Provenance
file.txt— file(1) outputpefile.txt— pefile Python library header dumprabin2-info.txt— radare2rabin2 -Isummarystrings.txt— GNU strings -a -n 6 output (13124 lines)capa.txt— Mandiant capa v7.1.1 packed-sample warningfloss.txt— FireEye flare-floss (no decoded strings recovered)binwalk.txt— binwalk embedded artifact scanexiftool.json— ExifTool 12.76 metadatassdeep.txt— ssdeep hashtlsh.txt— TLSH hash- CLR20 header and metadata stream inspection via custom Python/pefile script