family9d2ca3 (contested — 8th distinct morph)confidencelowcreated2026-09-05
SHA-256: d7c9efe83a46acea1c8a012e0ac0b697c3b6bc282d192d2b07cf2361d8fd8345

Deep Analysis: d7c9efe83a46acea1c8a012e0ac0b697c3b6bc282d192d2b07cf2361d8fd8345

1. Build / RE

Toolchain: Rust stable-x86_64-pc-windows-msvc ^[rabin2-info.txt]. Release build, compiled Fri May 29 13:22:17 2026 ^[rabin2-info.txt]. PDB path gh.pdb ^[strings.txt].

Dependency stack (recovered from .cargo/registry/src panic strings) ^[strings.txt]:

  • tokio-1.52.3 — async multi-thread runtime
  • wreq-6.0.0-rc.28 — HTTP client (custom fork; wreq::client, wreq::tls, wreq::redirect)
  • http2-0.5.17 — HTTP/2 framing
  • boring2-5.0.0-alpha.13 + tokio-boring2-5.0.0 — BoringSSL TLS bindings
  • flate2-1.1.9 — deflate decompression
  • url-2.5.8, idna-1.1.0, icu_normalizer-2.2.0 — URL parsing / IDNA
  • parking_lot-0.12.5, hashbrown-0.17.1, indexmap-2.14.0 — std containers

Packing / obfuscation: None. Standard Rust release artifact. 7.3 MB on disk, 5 sections ^[file.txt]. ASLR + DEP enabled, canary present, PIC, no signing ^[rabin2-info.txt].

Anti-analysis: None observed. No debug checks, no VM detection, no sandbox gates. The binary is a straight HTTP worker.

Notable functions: The entire .text is Rust std + tokio + wreq. No custom crypto, no shellcode, no PE injection. The threat logic is entirely HTTP orchestration against a single target endpoint.

2. Deploy / ATT&CK

Target: https://kr-hana-live.spooncast.net/cast/ ^[strings.txt] — SpoonCast Korean live-streaming platform HLS endpoint.

HTTP masquerade: Rotating library of ~100+ browser User-Agent strings covering Chrome (v100–v147), Edge, Firefox (v109–v149), Opera, Safari — across Windows, macOS, Linux, Android, iOS ^[strings.txt]. Full Accept-Language, sec-fetch-*, and priority header fidelity. Multiple TLS 1.2 and TLS 1.3 cipher-suite configurations, including post-quantum hybrid X25519MLKEM768:X25519:P-256:P-384:P-521 ^[strings.txt].

Proxy / tunnel support: Reads ALL_PROXY/all_proxy/HTTP_PROXY/http_proxy/HTTPS_PROXY/https_proxy/NO_PROXY/no_proxy environment variables ^[strings.txt]. Proxy-Authorization and CONNECT tunnel handling in wreq.

Behavior: This is an engagement bot / viewbot for a live-streaming service, not an infostealer, RAT, or dropper. The massive UA corpus and TLS fingerprinting library are designed to make each connection appear as a distinct browser session, evading platform-side rate-limiting and bot detection.

Static-only inference (CAPE skipped — no Windows guest):

Technique ID Evidence
Application Layer Protocol T1071.001 HTTPS GET/POST to kr-hana-live.spooncast.net ^[strings.txt]
Proxy T1090 ALL_PROXY/HTTP_PROXY env support, CONNECT tunnel ^[strings.txt]
Masquerading T1036 Chrome/Edge/Firefox/Opera/Safari UA rotation ^[strings.txt]
Data Encoding T1132.001 Standard HTTP request encoding (no custom obfuscation)

No observed: persistence, process injection, credential theft, registry modification, file dropping, C2 beaconing, exfiltration, or lateral movement. The binary is a single-purpose HTTP worker.

Attribution / Family Context

This sample carries the OpenCTI 9d2ca3 label but shares zero build artefacts with any prior morph in that cluster (MinGW-w64 encrypted droppers, Go 1.25.4 infostealers, .NET 4.0/4.6.2 stagers, MinGW-w64 reflective downloader). It is the eighth distinct morph under this contested grab-bag label. See 9d2ca3 entity page for the full cluster breakdown.

Confidence: Low. Family attribution is purely co-label noise from the Amadey downloader pipeline; this binary is build-distinct and purpose-distinct (engagement fraud vs. payload delivery).

Indicators

  • Network: https://kr-hana-live.spooncast.net/cast/
  • UA rotation: Chrome/Edge/Firefox/Opera/Safari versions 100–147 across all major platforms
  • TLS fingerprint: Post-quantum hybrid key exchange (X25519MLKEM768) + extensive cipher list
  • Binary size: 7,255,040 bytes, SHA-256 d7c9efe8...
  • PDB: gh.pdb