typeanalysisfamilycoinminerconfidencelowcreated2026-07-31updated2026-07-31dotnetobfuscationcryptominerloaderdefense-evasionpe
SHA-256: a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4

coinminer: a80c26e2 — .NET ConfuserEx crypter/loader with Rijndael+Deflate resource payload, May 2026 build

Executive Summary

A 7.1 MB .NET Framework PE32 executable compiled 2026-05-25 and packed with Confuser v1.9.0.0. The outer binary decrypts a ~7.3 MB embedded manifest resource via RijndaelManaged + DeflateStream, then reflectively loads the inner payload via DynamicMethod/ILGenerator and P/Invoke bridging. No network IOCs are recoverable statically; all C2 capability lives inside the encrypted resource. The preliminary OpenCTI coinminer label is low-confidence — the build fingerprint (.NET crypter/loader, ConfuserEx, May 2026) diverges sharply from the established PyInstaller coinminer cluster (MSVC 14.0, Sep 2018, zlib/AES overlay). This sample is a sibling of the unclassified-dotnet-crypter-loader family.

What It Is

  • SHA-256: a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4
  • Size: 7,447,040 bytes (7.1 MB) ^[file.txt]
  • Type: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 4 sections ^[file.txt]
  • Compiled: Mon May 25 16:52:26 2026 UTC ^[rabin2-info.txt:11] ^[pefile.txt:34]
  • Internal name: Small.exe ^[pefile.txt:256]
  • Version info: 0.0.0.0 across all fields, empty FileDescription/LegalCopyright ^[pefile.txt:254-259]
  • Family attribution: Preliminary coinminer (OpenCTI label). Low confidence — build stack is a .NET crypter/loader, not the PyInstaller cluster.

How It Works

Build / RE

Toolchain: .NET Framework 4.0+ (CLR v4.0.30319) ^[CLR header metadata analysis]. The PE carries a standard COR20 header with EntryPointToken 0x6000005 and 5 metadata streams (#-, #Strings, #US, #GUID, #Blob).

Obfuscator: Confuser v1.9.0.0 watermark present in #Strings metadata ^[strings.txt:13073]. All type/method/field names are stripped; only mscorlib namespace strings survive static extraction. Control-flow flattening and constant encryption are standard ConfuserEx behaviours; decompilers will fail to produce readable C# without deobfuscation.

Anti-analysis:

  • IsDebuggerPresent string in metadata ^[strings.txt:13027]
  • COR_ENABLE_PROFILING, COR_PROFILER, "Profiler detected", "Debugger detected (Managed)" ^[strings.txt:13053]
  • "Loop broken", "Module error", "Broken file" — likely anti-tamper or integrity-check failure messages ^[strings.txt]
  • High-entropy .text (7.51) and custom-named section 9gSGXF+U (7.01) impede static clustering ^[pefile.txt:92,152]

Payload staging: Two encrypted containers:

  1. Embedded manifest resource (~7.29 MB at RVA 0x6d4c inside .text) — the primary payload. First 256 bytes show no recognizable magic; data is uniformly high-entropy ^[CLR header analysis].
  2. Custom section 9gSGXF+U (20,904 bytes, entropy 7.01) at RVA 0x71c000 — no recognizable header; likely secondary config or stage-2 payload ^[pefile.txt:138-156].

IAT: Only mscoree.dll!_CorExeMain ^[pefile.txt:271]. All other APIs resolved via .NET reflection or P/Invoke at runtime.

Signing: Unsigned ^[rabin2-info.txt:27].

Deploy / ATT&CK

Static-only analysis; CAPE skipped — no Windows guest available ^[dynamic-analysis.md]. Runtime behaviour inferred from recovered .NET API strings.

MITRE ATT&CK Technique Evidence
T1027 Obfuscated Files or Information ConfuserEx v1.9.0.0 name stripping + control-flow flattening ^[strings.txt:13073] ^[capa.txt]
T1140 Deobfuscate/Decode Files or Information RijndaelManaged → CreateDecryptor → CryptoStream → DeflateStream chain on embedded resource ^[strings.txt:12952,12958,12960,12937]
T1620 Reflective Code Loading DynamicMethod + ILGenerator + GetDelegateForFunctionPointer + Assembly.Load ^[strings.txt:12964-12988]
T1055 Process Injection (inferred) Hidden ProcessStartInfo with set_CreateNoWindow, set_UseShellExecute, set_FileName, ExpandEnvironmentVariables ^[strings.txt:12771-12803]
T1129 Shared Modules GetManifestResourceStream + Assembly.GetExecutingAssembly resource resolution ^[strings.txt:12801,12997]
T1560.002 Archive Collected Data::Archive via Library DeflateStream decompression inside decryption pipeline ^[strings.txt:12937]
T1496 Resource Hijacking Cryptocurrency miner payload (preliminary family label; inner payload not recovered statically)

Persistence: Not observed in outer binary. Any persistence would be enacted by the decrypted inner payload.

C2 / Network: No IP, domain, URL, or pool strings recovered statically. The ~7.3 MB encrypted resource likely encapsulates all network logic. This is consistent with crypter/loader design: the outer binary is a delivery vehicle, the inner payload holds the threat logic.

Attribution: No linguistic clues, infrastructure overlap, or code-reuse indicators visible in the outer binary. The Small.exe / MyApplication.app masquerade is a generic ConfuserEx default artefact, not a targeted lure.

Decompiled Behavior

Ghidra decompilation was not attempted; radare2 CIL support produces only raw IL bytecode with switch-based dispatch, which is unreadable against ConfuserEx-flattened control flow. The behavioural narrative above is reconstructed from:

  1. Recovered .NET namespace/type/method strings (see strings.txt lines 12771-13073)
  2. COR20 header and metadata stream inspection
  3. Section entropy and layout analysis
  4. Capa "packed sample" warning (file limitation) ^[capa.txt]

C2 Infrastructure

None recoverable statically. The encrypted manifest resource (~7.29 MB) and the 9gSGXF+U section (~20 KB) are both opaque without the runtime decryption key.

Interesting Tidbits

  • Fresh compilation date: May 25 2026 is the most recent compilation timestamp observed in this corpus for any family. Either this is a live campaign or the timestamp is fabricated. ^[pefile.txt:34]
  • Massive encrypted resource: 7.29 MB inside a 7.45 MB binary — 97.7% of the file is the encrypted payload. This dwarfs most crypter/loader siblings in the corpus. ^[CLR header analysis]
  • No #=q…== name mangling: Unlike typical ConfuserEx samples, this binary does not show the classic #=q[A-Za-z0-9_$]{10,}== mangled identifiers in strings. The obfuscation may be a newer ConfuserEx fork or a different mode (e.g., koi token renaming) that strips all readable names. ^[strings.txt]
  • Custom section name 9gSGXF+U: Randomized 8-character section names are sometimes used by crypters to evade signature-based clustering. The section is small (20 KB) but high-entropy, suggesting it is encrypted rather than compressed. ^[pefile.txt:138-156]
  • Floss failure: The floss.txt output shows only the __main__.py help text, indicating FireEye flare-floss could not extract any decoded strings from this binary. ConfuserEx string encryption is working as designed. ^[floss.txt]

How To Mess With It (Homelab Replication)

Goal: Reproduce a comparable ConfuserEx-obfuscated .NET crypter/loader that decrypts a resource payload at runtime.

  1. Build a trivial .NET payload

    // Any .NET console app
    Console.WriteLine("Payload executed");
    
  2. Encrypt the payload

    byte[] payload = File.ReadAllBytes("payload.exe");
    byte[] key = Encoding.UTF8.GetBytes("weakpassword1234"); // 128-bit
    using (var aes = new RijndaelManaged())
    {
        aes.Key = key;
        aes.GenerateIV();
        using (var ms = new MemoryStream())
        {
            ms.Write(aes.IV, 0, 16);
            using (var cs = new CryptoStream(ms, aes.CreateEncryptor(), CryptoStreamMode.Write))
            using (var ds = new DeflateStream(cs, CompressionMode.Compress))
                ds.Write(payload, 0, payload.Length);
            File.WriteAllBytes("encrypted.bin", ms.ToArray());
        }
    }
    
  3. Embed as manifest resource in a .NET loader stub that reverses the pipeline (DeflateStream → CryptoStream → Assembly.Load).

  4. Apply ConfuserEx with maximum preset (constant encryption, control-flow flattening, anti-tamper).

  5. Verify: capa <output.exe> should hit packed limitation; strings should show only mscorlib namespaces and anti-debug strings.

Deployable Signatures

YARA rule

rule ConfuserEx_Crypter_Loader_May2026
{
    meta:
        description = "ConfuserEx v1.9 .NET crypter/loader with Rijndael+Deflate resource payload"
        author = "PacketPursuit"
        date = "2026-07-31"
        sha256 = "a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4"

    strings:
        $confuser = "Confuser v1.9.0.0" ascii wide
        $rijndael = "RijndaelManaged" ascii wide
        $deflate = "DeflateStream" ascii wide
        $dynmethod = "DynamicMethod" ascii wide
        $ilgen = "ILGenerator" ascii wide
        $res_stream = "GetManifestResourceStream" ascii wide
        $debug = "Debugger detected (Managed)" ascii wide
        $profiler = "Profiler detected" ascii wide
        $small = "Small.exe" ascii wide
        $myapp = "MyApplication.app" ascii wide

    condition:
        uint16(0) == 0x5A4D and
        pe.is_dotnet and
        $confuser and
        ($rijndael or $deflate) and
        ($dynmethod or $ilgen or $res_stream) and
        3 of ($debug, $profiler, $small, $myapp)
}

Behavioral fingerprint

This binary is a .NET Framework PE32 with a single native import (mscoree.dll!_CorExeMain). At startup it resolves an embedded manifest resource via GetManifestResourceStream, decrypts the blob via RijndaelManaged/CryptoStream, decompresses with DeflateStream, and loads the resulting assembly reflectively using DynamicMethod/ILGenerator and Assembly.Load. Anti-debug strings (Debugger detected, Profiler detected) and IsDebuggerPresent checks are present in metadata. No meaningful type/method names survive static extraction. The file is 97%+ encrypted payload by volume.

IOC list

  • SHA-256: a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4
  • SSDeep: 196608:Z1v4Bb/JcgkqsR7tIole3lHWXzLlt33XCpyRqe2nkR2:Z0b/OlC3lHWXzhtypy
  • TLSH: 61763317568772BDC26117B063ACA170F2B26D5FD7C98EDDA88BB9B0AC108083F3D955
  • Internal name: Small.exe
  • Original filename: Small.exe
  • Confuser version: v1.9.0.0
  • Compilation timestamp: 2026-05-25 16:52:26 UTC
  • Custom section name: 9gSGXF+U

Detection Signatures

Capability ATT&CK Evidence
uses .NET resource stream T1129 GetManifestResourceStream in metadata ^[strings.txt:12801]
decrypts payload with AES/Rijndael T1140 RijndaelManaged, CreateDecryptor, CryptoStream ^[strings.txt:12952,12958,12960]
decompresses payload with Deflate T1560.002 DeflateStream ^[strings.txt:12937]
reflective code loading T1620 DynamicMethod, ILGenerator, CreateDelegate ^[strings.txt:12964-12981]
hidden process execution T1055 (inferred) ProcessStartInfo, set_CreateNoWindow, set_UseShellExecute ^[strings.txt:12771-12803]
anti-debug check T1622 IsDebuggerPresent, "Debugger detected (Managed)" ^[strings.txt:13027,13053]
anti-profiling check T1622 COR_ENABLE_PROFILING, "Profiler detected" ^[strings.txt:13053]

References

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile Python library header dump
  • rabin2-info.txt — radare2 rabin2 -I summary
  • strings.txt — GNU strings -a -n 6 output (13124 lines)
  • capa.txt — Mandiant capa v7.1.1 packed-sample warning
  • floss.txt — FireEye flare-floss (no decoded strings recovered)
  • binwalk.txt — binwalk embedded artifact scan
  • exiftool.json — ExifTool 12.76 metadata
  • ssdeep.txt — ssdeep hash
  • tlsh.txt — TLSH hash
  • CLR20 header and metadata stream inspection via custom Python/pefile script