fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbcunclassified-dotnet-bee-themed-rasterizer: fc944b54 — shipping-document masquerade, bee-themed internal naming, static-only analysis
Executive Summary
A .NET Framework 4.7.2 PE32 GUI executable distributed as TOMPS_209645_MV W TRADER_ORDER.exe, masquerading as a 3D software rasterizer ("SoftwareRasterizer3D" v1.0.9.0). Static analysis reveals no malicious APIs — the binary is a genuine 3D renderer (OBJ loader, Matrix4x4 math, wireframe toggle) wrapped in bee-themed internal naming (Extract_Hive_Comb, swarmReversed, apiaryFrame, etc.). It belongs to a nine-sibling cluster sharing identical code, build artifacts, and a hardcoded 32-byte hex string. Threat is social-engineering: a benign-appearing executable delivered under a business-document filename to exploit Windows extension-hiding. No CAPE detonation available.
What It Is
- SHA-256:
fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc - Filename:
TOMPS_209645_MV W TRADER_ORDER.exe^[triage.json] - File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
- Size: 1,060,352 bytes (1.06 MB) ^[triage.json]
- Build timestamp: 2026-05-27 01:24:18 UTC ^[pefile.txt]
- Compiler: .NET Framework 4.7.2 (CLR v4.0.30319) ^[rabin2-info.txt]
- Linker: Standard Mono/.NET PE32 linker, version 48.0 ^[exiftool.json]
- Signing: Unsigned (no certificate directory, no Authenticode) ^[pefile.txt]
- Packing / obfuscation: None. No ConfuserEx, SmartAssembly, Xenocode, UPX, or Themida. ^[capa.txt]
- YARA:
PE_File_Genericonly ^[yara.txt]
How It Works
The binary is a compiled .NET Framework WinForms application presenting a functional 3D software rasterizer. On launch it opens a MainForm with PictureBox render surface, TrackBar rotation controls (X/Y/Z), CheckBox toggles for wireframe mode and backface culling, and an OpenFileDialog to load .obj 3D model files. A Timer drives the RenderFrame loop.
Key components observed in #Strings metadata:
SoftwareRasterizer3D.Engine.Mesh— stores triangle list (Tris), loads.objviaLoadFromObjFile^[strings.txt:77]SoftwareRasterizer3D.Engine.Rasterizer—RenderFrame, projection matrix, camera/light vectors ^[strings.txt:82]SoftwareRasterizer3D.Math.Matrix4x4/Vector3D— full 3D math pipeline (rotation, translation, projection, cross/dot product, normalization) ^[strings.txt:34,150]SoftwareRasterizer3D.UI.MainForm— WinForms GUI withapiaryFrame,btnLoadObj,chkWireframe,chkCulling,chkAutoRotate^[strings.txt:83,87,134]
The bee-themed naming (swarmReversed, colonyBrand, broodCycles, nectarFlow, combReserve) appears to be the original author's internal naming convention — possibly a joke, a project codename, or an intentional obfuscation layer. No evidence these fields are used for malicious logic.
Decompiled Behavior
Radare2 analysis (CIL mode, level 3) recovered 198 functions. The entry point is a standard _CorExeMain via mscoree.dll. Notable functions include:
method.SoftwareRasterizer3D.UI.MainForm.Extract_Hive_Comb@0x00403580— stub-like CIL method, immediately returns. The name is thematic, not functional. ^[r2:fcn.00403580]method.SoftwareRasterizer3D.UI.MainForm.RenderTimer_Tick@0x00403c38— timer callback for frame rendering loopmethod.SoftwareRasterizer3D.Engine.Rasterizer.RenderFrame@0x00402888— core rasterization routinemethod.SoftwareRasterizer3D.Engine.ObjLoader.LoadFromObjFile@0x00402164— parses Wavefront OBJ vertex/face data
No P/Invoke, no DllImport, no unsafe blocks, no Assembly.Load or Reflection.Emit calls detected. The import table has only mscoree.dll._CorExeMain. ^[pefile.txt:254]
C2 Infrastructure
None observed. No network APIs, no HTTP/HTTPS/TCP/SMTP/FTP strings, no hardcoded IPs, domains, or URLs. No Discord webhook tokens, Telegram bot tokens, or paste-site URLs. No mutex or named-pipe names. No registry persistence keys. ^[strings.txt]
Interesting Tidbits
- Shared 32-byte hex string: All nine siblings contain the identical 64-char hex string
BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7in#Strings. Purpose unknown — not a known hash, key fingerprint, or blockchain address. ^[strings.txt:24] oYzoresource: Theget_oYzoaccessor suggests a custom manifest resource, but theManifestResourcetable in the#~stream is malformed/incomplete (row 0 reports offset135200768, which is nonsensical for a 1 MB file). Likely a pefile/dotnet parser limitation on CIL metadata. ^[parse_clr.py]- Builder pipeline evidence: Siblings show per-sample randomized internal EXE names (
PRUu.exe,cXBI.exe,sqkk.exe,JlXC.exe, etc.) while sharing identical code. Some siblings have empty VS_VERSIONINFO (0.0.0.0), others have the full masquerade — suggesting selective metadata injection in a repackaging tool. - CAPE skipped: No Windows guest available. Dynamic behavior unverified. ^[dynamic-analysis.md]
How To Mess With It (Homelab Replication)
- Build a similar .NET Framework 4.7.2 WinForms app with a 3D software rasterizer in C#.
- Use bee-themed variable names (
apiaryFrame,nectarFlow,broodCycles) as a naming convention. - Embed a 64-char hex string in a
const stringfield to match the cluster fingerprint. - Compile with
csc.exe /target:winexe /platform:x86and verify withfile→ should showPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections. - Compare capa output: should hit only
compiled to the .NET platform,access .NET resource, andreference analysis tools strings(debug-build false positives). ^[capa.txt]
Deployable Signatures
YARA Rule
rule UnclassifiedDotnetBeeRasterizer
{
meta:
description = "Detects .NET Framework PE32 GUI executables with SoftwareRasterizer3D namespace and bee-themed internal naming"
author = "PacketPursuit SOC"
date = "2026-08-04"
sha256 = "fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc"
family = "unclassified-dotnet-bee-themed-rasterizer"
strings:
$a = "SoftwareRasterizer3D" wide ascii
$b = "Extract_Hive_Comb" wide ascii
$c = "apiaryFrame" wide ascii
$d = "swarmReversed" wide ascii
$e = "colonyBrand" wide ascii
$f = "nectarFlow" wide ascii
$g = "broodCycles" wide ascii
$h = "BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7" ascii
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
filesize < 2MB and
4 of ($a,$b,$c,$d,$e,$f,$g,$h)
}
IOC List
| Indicator | Value | Type | Confidence |
|---|---|---|---|
| SHA-256 | fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc |
Hash | High |
| Filename | TOMPS_209645_MV W TRADER_ORDER.exe |
Filename | High |
| Internal name | PRUu.exe |
Version info | High |
| Hex string | BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7 |
String | High |
| Namespace | SoftwareRasterizer3D |
Build artifact | High |
Behavioral Fingerprint
This .NET Framework PE32 WinForms GUI executable opens a single main window with 3D rasterizer controls (rotation trackbars, wireframe/culling toggles, OBJ file loader). It has no network traffic, no child processes, no registry writes, no file drops outside the user-selected .obj file, and no credential access. Any deviation from this profile (e.g., spawning powershell.exe, writing to %TEMP%, or making HTTP requests) would indicate a runtime-loaded secondary payload not visible statically.
Detection Signatures
| capa Capability | Namespace | ATT&CK |
|---|---|---|
| compiled to the .NET platform | runtime/dotnet | — |
| access .NET resource | executable/resource | — |
| reference analysis tools strings | anti-analysis | B0013.001 |
Note: The reference analysis tools strings hit is a false positive common to Debug-build .NET binaries — DebuggableAttribute and DebuggerNonUserCodeAttribute trigger capa's B0013.001 despite no actual anti-analysis intent. ^[capa.txt]
References
- Artifact ID:
14355f6b-9777-47ab-a61c-bb4b8c620e9b^[metadata.json] - Triage:
fc944b5465a41ab46b5ddaddd499c84170e2454ca6e5fce9987914aa8dba1cbc^[triage.json] - Entity page: unclassified-dotnet-bee-themed-rasterizer
Provenance
file.txt—filecommand output (file v5.44)pefile.txt— pefile Python library header dumpexiftool.json— ExifTool 12.76 VS_VERSIONINFO extractionstrings.txt—strings -n 6(GNU binstrings 2.40)capa.txt— Mandiant capa v7.1.1 (static analysis, dotnet format)rabin2-info.txt— radare2 5.9.2rabin2 -Ibinwalk.txt— Binwalk v2.3.4 embedded-artifact scandynamic-analysis.md— CAPEv2 report (skipped, no Windows guest)