d7c9efe83a46acea1c8a012e0ac0b697c3b6bc282d192d2b07cf2361d8fd8345Deep Analysis: d7c9efe83a46acea1c8a012e0ac0b697c3b6bc282d192d2b07cf2361d8fd8345
1. Build / RE
Toolchain: Rust stable-x86_64-pc-windows-msvc ^[rabin2-info.txt]. Release build, compiled Fri May 29 13:22:17 2026 ^[rabin2-info.txt]. PDB path gh.pdb ^[strings.txt].
Dependency stack (recovered from .cargo/registry/src panic strings) ^[strings.txt]:
tokio-1.52.3— async multi-thread runtimewreq-6.0.0-rc.28— HTTP client (custom fork;wreq::client,wreq::tls,wreq::redirect)http2-0.5.17— HTTP/2 framingboring2-5.0.0-alpha.13+tokio-boring2-5.0.0— BoringSSL TLS bindingsflate2-1.1.9— deflate decompressionurl-2.5.8,idna-1.1.0,icu_normalizer-2.2.0— URL parsing / IDNAparking_lot-0.12.5,hashbrown-0.17.1,indexmap-2.14.0— std containers
Packing / obfuscation: None. Standard Rust release artifact. 7.3 MB on disk, 5 sections ^[file.txt]. ASLR + DEP enabled, canary present, PIC, no signing ^[rabin2-info.txt].
Anti-analysis: None observed. No debug checks, no VM detection, no sandbox gates. The binary is a straight HTTP worker.
Notable functions: The entire .text is Rust std + tokio + wreq. No custom crypto, no shellcode, no PE injection. The threat logic is entirely HTTP orchestration against a single target endpoint.
2. Deploy / ATT&CK
Target: https://kr-hana-live.spooncast.net/cast/ ^[strings.txt] — SpoonCast Korean live-streaming platform HLS endpoint.
HTTP masquerade: Rotating library of ~100+ browser User-Agent strings covering Chrome (v100–v147), Edge, Firefox (v109–v149), Opera, Safari — across Windows, macOS, Linux, Android, iOS ^[strings.txt]. Full Accept-Language, sec-fetch-*, and priority header fidelity. Multiple TLS 1.2 and TLS 1.3 cipher-suite configurations, including post-quantum hybrid X25519MLKEM768:X25519:P-256:P-384:P-521 ^[strings.txt].
Proxy / tunnel support: Reads ALL_PROXY/all_proxy/HTTP_PROXY/http_proxy/HTTPS_PROXY/https_proxy/NO_PROXY/no_proxy environment variables ^[strings.txt]. Proxy-Authorization and CONNECT tunnel handling in wreq.
Behavior: This is an engagement bot / viewbot for a live-streaming service, not an infostealer, RAT, or dropper. The massive UA corpus and TLS fingerprinting library are designed to make each connection appear as a distinct browser session, evading platform-side rate-limiting and bot detection.
Static-only inference (CAPE skipped — no Windows guest):
| Technique | ID | Evidence |
|---|---|---|
| Application Layer Protocol | T1071.001 | HTTPS GET/POST to kr-hana-live.spooncast.net ^[strings.txt] |
| Proxy | T1090 | ALL_PROXY/HTTP_PROXY env support, CONNECT tunnel ^[strings.txt] |
| Masquerading | T1036 | Chrome/Edge/Firefox/Opera/Safari UA rotation ^[strings.txt] |
| Data Encoding | T1132.001 | Standard HTTP request encoding (no custom obfuscation) |
No observed: persistence, process injection, credential theft, registry modification, file dropping, C2 beaconing, exfiltration, or lateral movement. The binary is a single-purpose HTTP worker.
Attribution / Family Context
This sample carries the OpenCTI 9d2ca3 label but shares zero build artefacts with any prior morph in that cluster (MinGW-w64 encrypted droppers, Go 1.25.4 infostealers, .NET 4.0/4.6.2 stagers, MinGW-w64 reflective downloader). It is the eighth distinct morph under this contested grab-bag label. See 9d2ca3 entity page for the full cluster breakdown.
Confidence: Low. Family attribution is purely co-label noise from the Amadey downloader pipeline; this binary is build-distinct and purpose-distinct (engagement fraud vs. payload delivery).
Indicators
- Network:
https://kr-hana-live.spooncast.net/cast/ - UA rotation: Chrome/Edge/Firefox/Opera/Safari versions 100–147 across all major platforms
- TLS fingerprint: Post-quantum hybrid key exchange (
X25519MLKEM768) + extensive cipher list - Binary size: 7,255,040 bytes, SHA-256
d7c9efe8... - PDB:
gh.pdb