typeanalysisfamilyunclassified-dotnet-bee-themed-rasterizerconfidencemediumdotnetsocial-engineering-filename-lureversion-info-masquerademalware-family
SHA-256: fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc

unclassified-dotnet-bee-themed-rasterizer: fc944b54 — shipping-document masquerade, bee-themed internal naming, static-only analysis

Executive Summary

A .NET Framework 4.7.2 PE32 GUI executable distributed as TOMPS_209645_MV W TRADER_ORDER.exe, masquerading as a 3D software rasterizer ("SoftwareRasterizer3D" v1.0.9.0). Static analysis reveals no malicious APIs — the binary is a genuine 3D renderer (OBJ loader, Matrix4x4 math, wireframe toggle) wrapped in bee-themed internal naming (Extract_Hive_Comb, swarmReversed, apiaryFrame, etc.). It belongs to a nine-sibling cluster sharing identical code, build artifacts, and a hardcoded 32-byte hex string. Threat is social-engineering: a benign-appearing executable delivered under a business-document filename to exploit Windows extension-hiding. No CAPE detonation available.

What It Is

  • SHA-256: fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc
  • Filename: TOMPS_209645_MV W TRADER_ORDER.exe ^[triage.json]
  • File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
  • Size: 1,060,352 bytes (1.06 MB) ^[triage.json]
  • Build timestamp: 2026-05-27 01:24:18 UTC ^[pefile.txt]
  • Compiler: .NET Framework 4.7.2 (CLR v4.0.30319) ^[rabin2-info.txt]
  • Linker: Standard Mono/.NET PE32 linker, version 48.0 ^[exiftool.json]
  • Signing: Unsigned (no certificate directory, no Authenticode) ^[pefile.txt]
  • Packing / obfuscation: None. No ConfuserEx, SmartAssembly, Xenocode, UPX, or Themida. ^[capa.txt]
  • YARA: PE_File_Generic only ^[yara.txt]

How It Works

The binary is a compiled .NET Framework WinForms application presenting a functional 3D software rasterizer. On launch it opens a MainForm with PictureBox render surface, TrackBar rotation controls (X/Y/Z), CheckBox toggles for wireframe mode and backface culling, and an OpenFileDialog to load .obj 3D model files. A Timer drives the RenderFrame loop.

Key components observed in #Strings metadata:

  • SoftwareRasterizer3D.Engine.Mesh — stores triangle list (Tris), loads .obj via LoadFromObjFile ^[strings.txt:77]
  • SoftwareRasterizer3D.Engine.Rasterizer — RenderFrame, projection matrix, camera/light vectors ^[strings.txt:82]
  • SoftwareRasterizer3D.Math.Matrix4x4 / Vector3D — full 3D math pipeline (rotation, translation, projection, cross/dot product, normalization) ^[strings.txt:34,150]
  • SoftwareRasterizer3D.UI.MainForm — WinForms GUI with apiaryFrame, btnLoadObj, chkWireframe, chkCulling, chkAutoRotate ^[strings.txt:83,87,134]

The bee-themed naming (swarmReversed, colonyBrand, broodCycles, nectarFlow, combReserve) appears to be the original author's internal naming convention — possibly a joke, a project codename, or an intentional obfuscation layer. No evidence these fields are used for malicious logic.

Decompiled Behavior

Radare2 analysis (CIL mode, level 3) recovered 198 functions. The entry point is a standard _CorExeMain via mscoree.dll. Notable functions include:

  • method.SoftwareRasterizer3D.UI.MainForm.Extract_Hive_Comb @ 0x00403580 — stub-like CIL method, immediately returns. The name is thematic, not functional. ^[r2:fcn.00403580]
  • method.SoftwareRasterizer3D.UI.MainForm.RenderTimer_Tick @ 0x00403c38 — timer callback for frame rendering loop
  • method.SoftwareRasterizer3D.Engine.Rasterizer.RenderFrame @ 0x00402888 — core rasterization routine
  • method.SoftwareRasterizer3D.Engine.ObjLoader.LoadFromObjFile @ 0x00402164 — parses Wavefront OBJ vertex/face data

No P/Invoke, no DllImport, no unsafe blocks, no Assembly.Load or Reflection.Emit calls detected. The import table has only mscoree.dll._CorExeMain. ^[pefile.txt:254]

C2 Infrastructure

None observed. No network APIs, no HTTP/HTTPS/TCP/SMTP/FTP strings, no hardcoded IPs, domains, or URLs. No Discord webhook tokens, Telegram bot tokens, or paste-site URLs. No mutex or named-pipe names. No registry persistence keys. ^[strings.txt]

Interesting Tidbits

  • Shared 32-byte hex string: All nine siblings contain the identical 64-char hex string BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7 in #Strings. Purpose unknown — not a known hash, key fingerprint, or blockchain address. ^[strings.txt:24]
  • oYzo resource: The get_oYzo accessor suggests a custom manifest resource, but the ManifestResource table in the #~ stream is malformed/incomplete (row 0 reports offset 135200768, which is nonsensical for a 1 MB file). Likely a pefile/dotnet parser limitation on CIL metadata. ^[parse_clr.py]
  • Builder pipeline evidence: Siblings show per-sample randomized internal EXE names (PRUu.exe, cXBI.exe, sqkk.exe, JlXC.exe, etc.) while sharing identical code. Some siblings have empty VS_VERSIONINFO (0.0.0.0), others have the full masquerade — suggesting selective metadata injection in a repackaging tool.
  • CAPE skipped: No Windows guest available. Dynamic behavior unverified. ^[dynamic-analysis.md]

How To Mess With It (Homelab Replication)

  1. Build a similar .NET Framework 4.7.2 WinForms app with a 3D software rasterizer in C#.
  2. Use bee-themed variable names (apiaryFrame, nectarFlow, broodCycles) as a naming convention.
  3. Embed a 64-char hex string in a const string field to match the cluster fingerprint.
  4. Compile with csc.exe /target:winexe /platform:x86 and verify with file → should show PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections.
  5. Compare capa output: should hit only compiled to the .NET platform, access .NET resource, and reference analysis tools strings (debug-build false positives). ^[capa.txt]

Deployable Signatures

YARA Rule

rule UnclassifiedDotnetBeeRasterizer
{
    meta:
        description = "Detects .NET Framework PE32 GUI executables with SoftwareRasterizer3D namespace and bee-themed internal naming"
        author = "PacketPursuit SOC"
        date = "2026-08-04"
        sha256 = "fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc"
        family = "unclassified-dotnet-bee-themed-rasterizer"
    strings:
        $a = "SoftwareRasterizer3D" wide ascii
        $b = "Extract_Hive_Comb" wide ascii
        $c = "apiaryFrame" wide ascii
        $d = "swarmReversed" wide ascii
        $e = "colonyBrand" wide ascii
        $f = "nectarFlow" wide ascii
        $g = "broodCycles" wide ascii
        $h = "BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7" ascii
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        filesize < 2MB and
        4 of ($a,$b,$c,$d,$e,$f,$g,$h)
}

IOC List

Indicator Value Type Confidence
SHA-256 fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc Hash High
Filename TOMPS_209645_MV W TRADER_ORDER.exe Filename High
Internal name PRUu.exe Version info High
Hex string BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7 String High
Namespace SoftwareRasterizer3D Build artifact High

Behavioral Fingerprint

This .NET Framework PE32 WinForms GUI executable opens a single main window with 3D rasterizer controls (rotation trackbars, wireframe/culling toggles, OBJ file loader). It has no network traffic, no child processes, no registry writes, no file drops outside the user-selected .obj file, and no credential access. Any deviation from this profile (e.g., spawning powershell.exe, writing to %TEMP%, or making HTTP requests) would indicate a runtime-loaded secondary payload not visible statically.

Detection Signatures

capa Capability Namespace ATT&CK
compiled to the .NET platform runtime/dotnet —
access .NET resource executable/resource —
reference analysis tools strings anti-analysis B0013.001

Note: The reference analysis tools strings hit is a false positive common to Debug-build .NET binaries — DebuggableAttribute and DebuggerNonUserCodeAttribute trigger capa's B0013.001 despite no actual anti-analysis intent. ^[capa.txt]

References

  • Artifact ID: 14355f6b-9777-47ab-a61c-bb4b8c620e9b ^[metadata.json]
  • Triage: fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc ^[triage.json]
  • Entity page: unclassified-dotnet-bee-themed-rasterizer

Provenance

  • file.txt — file command output (file v5.44)
  • pefile.txt — pefile Python library header dump
  • exiftool.json — ExifTool 12.76 VS_VERSIONINFO extraction
  • strings.txt — strings -n 6 (GNU binstrings 2.40)
  • capa.txt — Mandiant capa v7.1.1 (static analysis, dotnet format)
  • rabin2-info.txt — radare2 5.9.2 rabin2 -I
  • binwalk.txt — Binwalk v2.3.4 embedded-artifact scan
  • dynamic-analysis.md — CAPEv2 report (skipped, no Windows guest)