fdaabbf7b7585cc473502c21a1471f95de45d5492216e8e6c035e1856d6af9b1gh0strat: fdaabbf7 — Inno Setup 6.5.7.1 dropper masquerading as ByteDance Doubao AI assistant
Executive Summary
PE32 Inno Setup 6.5.7.1 installer (Delphi 36.0) with a 4.6 MB encrypted LZMA overlay. VersionInfo claims "Engine Direct Turbo Setup" by "Microsoft Corpora" (truncated) while the on-disk filename is 豆包.exe (ByteDance Doubao AI assistant). No code signing. Two Inno Setup data headers present at offsets 0xAF794 and 0x43BABB. Capa flagged installer limitation. CAPE skipped — no Windows guest. Payload is opaque to static analysis; family attribution (gh0strat, silverfox, valleyrat) is preliminary and unverified by payload extraction.
What It Is
| Attribute | Detail |
|---|---|
| SHA-256 | fdaabbf7b7585cc473502c21a1471f95de45d5492216e8e6c035e1856d6af9b1 |
| Size | 5,426,135 bytes (5.4 MB) ^[triage.json] |
| Type | PE32 executable (GUI) Intel 80386, 11 sections ^[file.txt] |
| Compiler | Embarcadero Delphi for Win32 compiler version 36.0 (29.0.53571.9782) ^[strings.txt:725528] |
| Installer | Inno Setup 6.5.7.1 (two data headers) ^[strings.txt:7488] ^[terminal:xxd] |
| Entry point | 0xACFD4 (in .itext section) ^[exiftool.json:22] |
| Signed | No — certificate directory empty ^[rabin2-info.txt:27] ^[pefile.txt:312] |
| Overlay | LZMA zlb stream at 0xC7200, ~4.61 MB ^[terminal:pefile] |
| Filename lure | 豆包.exe (ByteDance Doubao AI assistant product) ^[triage.json] |
| VersionInfo masquerade | CompanyName Microsoft Corpora (truncated), FileDescription Engine Direct Turbo Setup, FileVersion 11.1.18245.0 ^[pefile.txt:382] ^[exiftool.json:36] |
| OpenCTI labels | gh0strat, silverfox, valleyrat ^[triage.json] |
The binary is a legitimate Inno Setup installer stub compiled with Delphi. The malicious payload is embedded inside the compressed overlay and is not recoverable without runtime extraction or a compatible Inno Setup unpacker. innoextract failed with "Stream error while parsing setup headers" (version 6.5.7.1 not fully supported), and 7z refused the archive. ^[terminal:innoextract] ^[terminal:7z]
How It Works
The Inno Setup stub performs standard installation workflow: decompress the LZMA overlay, write files to the target directory, and execute any [Run] entries defined in the compiled script. The setup script itself is compiled into the overlay and not visible statically.
Two Inno Setup Setup Data (6.5.7.1) headers were found:
- 0xAF794 (718,740) — inside the PE file, before the overlay. This is the setup loader's own header. ^[strings.txt:7488]
- 0x43BABB (4,438,715) — deep inside the overlay. This is the compressed archive header. ^[terminal:strings]
The stub imports only standard KERNEL32 APIs (heap, file, thread, process, resource, version, and critical-section functions). ^[pefile.txt:431-521] No network, crypto, or registry APIs are visible in the IAT — any malicious behaviour is delegated to the payload extracted at install time.
Given the ValleyRAT entity already documents an Inno Setup 7.0.0.1 Delphi dropper (480c184e) with similar characteristics (encrypted overlay, expired signing, printer-driver masquerade), this sample may belong to the same distribution pipeline. ^[entities/valleyrat.md] The SilverFox cluster also uses Inno Setup and Delphi droppers. ^[entities/silverfox.md] However, without payload extraction, the link is speculative.
Decompiled Behavior
Ghidra / radare2 not invoked — the binary is a standard Inno Setup stub with no custom code of interest. The entry point is the Inno Setup loader, not attacker-authored logic. Analysis value is in the overlay payload, which is opaque.
C2 Infrastructure
Unknown. No C2 strings, IPs, domains, or network APIs are visible in the PE IAT or static strings. Any C2 is embedded in the encrypted overlay or configured by the extracted payload at runtime. ^[dynamic-analysis.md]
Interesting Tidbits
- Dual masquerade: The VersionInfo impersonates Microsoft while the filename impersonates ByteDance's Doubao AI — a Chinese domestic product. This suggests the target audience is Chinese-speaking users who would trust both brands. ^[triage.json] ^[pefile.txt:382]
- Truncated CompanyName:
Microsoft Corporawith 43 trailing spaces before the null terminator. This is likely a copy-paste error from a template or a deliberate attempt to pad the field to a fixed width. ^[pefile.txt:383] - Empty OriginalFileName: The
OriginalFileNamefield in VersionInfo is 51 spaces, then null. Another template artefact. ^[pefile.txt:387] - Inno Setup 6.5.7.1: This is a relatively recent Inno Setup version (2023-2024 era). The builder may be using an up-to-date toolchain to avoid detection by older unpackers. ^[strings.txt:7488]
- Two data headers: The presence of two setup headers suggests a multi-part archive or a self-extracting installer with a secondary payload block. This is consistent with Inno Setup's ability to split large installations.
How To Mess With It (Homelab Replication)
To reproduce a comparable installer dropper:
- Download Inno Setup 6.5.7.1 from jrsoftware.org
- Write a standard
.issscript with[Files]and[Run]sections - Compile with
iscc.exe(default settings use LZMA compression) - The output is a single PE32 with Delphi stub + LZMA overlay
- Modify VersionInfo in the script to match the target masquerade
- Verify with
file,strings, andbinwalk— should showInno Setup Setup Dataandzlbsignature
What you'll learn: how commodity installers become effective dropper vehicles, and why AV/EDR often whitelists Inno Setup stubs.
Deployable Signatures
YARA rule
rule gh0strat_inno_dropper_doubao_masquerade
{
meta:
description = "Inno Setup dropper with Doubao/ByteDance filename masquerade"
author = "triage-pipeline"
date = "2026-09-07"
sha256 = "fdaabbf7b7585cc473502c21a1471f95de45d5492216e8e6c035e1856d6af9b1"
family = "gh0strat"
strings:
$inno = "Inno Setup Setup Data (6.5.7.1)" ascii
$doubao = "豆包" wide
$engine = "Engine Direct Turbo" wide
$microsoft = "Microsoft Corpora" wide
$zlb = { 7a 6c 62 } // LZMA stream signature
condition:
uint16(0) == 0x5A4D and
$inno and
($doubao or $engine or $microsoft) and
$zlb
}
Sigma rule
title: Inno Setup Dropper Execution with Suspicious Filename
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith:
- '\豆包.exe'
- '\doubao.exe'
Description|contains:
- 'Engine Direct Turbo'
- 'Inno Setup'
condition: selection
falsepositives:
- Legitimate Inno Setup installers (rare with this specific filename)
level: high
IOC list
| Indicator | Type | Value | Source |
|---|---|---|---|
| SHA-256 | Hash | fdaabbf7b7585cc473502c21a1471f95de45d5492216e8e6c035e1856d6af9b1 |
triage.json |
| Filename | String | 豆包.exe |
triage.json |
| VersionInfo CompanyName | String | Microsoft Corpora (padded) |
pefile.txt |
| VersionInfo FileDescription | String | Engine Direct Turbo Setup |
pefile.txt |
| VersionInfo FileVersion | String | 11.1.18245.0 |
pefile.txt |
| Inno Setup version | String | 6.5.7.1 |
strings.txt |
| Overlay signature | Bytes | zlb at 0xC7200 |
terminal:xxd |
Behavioral fingerprint statement
This binary is a PE32 GUI executable compiled with Embarcadero Delphi 36.0, containing a standard Inno Setup 6.5.7.1 loader stub with an LZMA-compressed overlay of approximately 4.6 MB. The VersionInfo masquerades as a Microsoft product (Engine Direct Turbo Setup) while the on-disk filename impersonates ByteDance's Doubao AI assistant (豆包.exe). No code signing is present. The IAT contains only KERNEL32 imports. The payload is encrypted/compressed within the overlay and not statically recoverable. Family attribution is preliminary (gh0strat, silverfox, valleyrat co-tags) and unverified by payload extraction or dynamic analysis.
Detection Signatures
| Capa Rule | Status | Note |
|---|---|---|
| installer file limitation | Triggered | Capa flagged as installer; cannot analyse created files without extraction. ^[capa.txt] |
References
- Artifact ID:
145ac401-cebc-4076-a43d-c8799a74b932(OpenCTI) - MalwareBazaar: tagged
gh0strat,silverfox,valleyrat - Related entity: gh0strat — tentative family page
- Related entity: valleyrat — Inno Setup dropper cluster with co-tags
- Related entity: silverfox — multi-variant loader/RAT cluster
- Related entity: gh0st — historic Chinese RAT family; possible parent of
gh0strattag - Schema: SCHEMA.md
Provenance
Analysis derived from file.txt, pefile.txt, exiftool.json, strings.txt, triage.json, capa.txt, binwalk.txt, rabin2-info.txt, dynamic-analysis.md, and terminal commands (innoextract, 7z, strings, xxd, python/pefile). No Ghidra/radare2 decompilation performed — the stub is standard Inno Setup with no custom attacker code. CAPE dynamic analysis skipped (no Windows guest). Payload remains opaque.