typeanalysisfamilygh0stratconfidencelowperatloaderc2persistenceevasionmalware-family
SHA-256: fdaabbf7b7585cc473502c21a1471f95de45d5492216e8e6c035e1856d6af9b1

gh0strat: fdaabbf7 — Inno Setup 6.5.7.1 dropper masquerading as ByteDance Doubao AI assistant

Executive Summary

PE32 Inno Setup 6.5.7.1 installer (Delphi 36.0) with a 4.6 MB encrypted LZMA overlay. VersionInfo claims "Engine Direct Turbo Setup" by "Microsoft Corpora" (truncated) while the on-disk filename is 豆包.exe (ByteDance Doubao AI assistant). No code signing. Two Inno Setup data headers present at offsets 0xAF794 and 0x43BABB. Capa flagged installer limitation. CAPE skipped — no Windows guest. Payload is opaque to static analysis; family attribution (gh0strat, silverfox, valleyrat) is preliminary and unverified by payload extraction.

What It Is

Attribute Detail
SHA-256 fdaabbf7b7585cc473502c21a1471f95de45d5492216e8e6c035e1856d6af9b1
Size 5,426,135 bytes (5.4 MB) ^[triage.json]
Type PE32 executable (GUI) Intel 80386, 11 sections ^[file.txt]
Compiler Embarcadero Delphi for Win32 compiler version 36.0 (29.0.53571.9782) ^[strings.txt:725528]
Installer Inno Setup 6.5.7.1 (two data headers) ^[strings.txt:7488] ^[terminal:xxd]
Entry point 0xACFD4 (in .itext section) ^[exiftool.json:22]
Signed No — certificate directory empty ^[rabin2-info.txt:27] ^[pefile.txt:312]
Overlay LZMA zlb stream at 0xC7200, ~4.61 MB ^[terminal:pefile]
Filename lure 豆包.exe (ByteDance Doubao AI assistant product) ^[triage.json]
VersionInfo masquerade CompanyName Microsoft Corpora (truncated), FileDescription Engine Direct Turbo Setup, FileVersion 11.1.18245.0 ^[pefile.txt:382] ^[exiftool.json:36]
OpenCTI labels gh0strat, silverfox, valleyrat ^[triage.json]

The binary is a legitimate Inno Setup installer stub compiled with Delphi. The malicious payload is embedded inside the compressed overlay and is not recoverable without runtime extraction or a compatible Inno Setup unpacker. innoextract failed with "Stream error while parsing setup headers" (version 6.5.7.1 not fully supported), and 7z refused the archive. ^[terminal:innoextract] ^[terminal:7z]

How It Works

The Inno Setup stub performs standard installation workflow: decompress the LZMA overlay, write files to the target directory, and execute any [Run] entries defined in the compiled script. The setup script itself is compiled into the overlay and not visible statically.

Two Inno Setup Setup Data (6.5.7.1) headers were found:

  • 0xAF794 (718,740) — inside the PE file, before the overlay. This is the setup loader's own header. ^[strings.txt:7488]
  • 0x43BABB (4,438,715) — deep inside the overlay. This is the compressed archive header. ^[terminal:strings]

The stub imports only standard KERNEL32 APIs (heap, file, thread, process, resource, version, and critical-section functions). ^[pefile.txt:431-521] No network, crypto, or registry APIs are visible in the IAT — any malicious behaviour is delegated to the payload extracted at install time.

Given the ValleyRAT entity already documents an Inno Setup 7.0.0.1 Delphi dropper (480c184e) with similar characteristics (encrypted overlay, expired signing, printer-driver masquerade), this sample may belong to the same distribution pipeline. ^[entities/valleyrat.md] The SilverFox cluster also uses Inno Setup and Delphi droppers. ^[entities/silverfox.md] However, without payload extraction, the link is speculative.

Decompiled Behavior

Ghidra / radare2 not invoked — the binary is a standard Inno Setup stub with no custom code of interest. The entry point is the Inno Setup loader, not attacker-authored logic. Analysis value is in the overlay payload, which is opaque.

C2 Infrastructure

Unknown. No C2 strings, IPs, domains, or network APIs are visible in the PE IAT or static strings. Any C2 is embedded in the encrypted overlay or configured by the extracted payload at runtime. ^[dynamic-analysis.md]

Interesting Tidbits

  • Dual masquerade: The VersionInfo impersonates Microsoft while the filename impersonates ByteDance's Doubao AI — a Chinese domestic product. This suggests the target audience is Chinese-speaking users who would trust both brands. ^[triage.json] ^[pefile.txt:382]
  • Truncated CompanyName: Microsoft Corpora with 43 trailing spaces before the null terminator. This is likely a copy-paste error from a template or a deliberate attempt to pad the field to a fixed width. ^[pefile.txt:383]
  • Empty OriginalFileName: The OriginalFileName field in VersionInfo is 51 spaces, then null. Another template artefact. ^[pefile.txt:387]
  • Inno Setup 6.5.7.1: This is a relatively recent Inno Setup version (2023-2024 era). The builder may be using an up-to-date toolchain to avoid detection by older unpackers. ^[strings.txt:7488]
  • Two data headers: The presence of two setup headers suggests a multi-part archive or a self-extracting installer with a secondary payload block. This is consistent with Inno Setup's ability to split large installations.

How To Mess With It (Homelab Replication)

To reproduce a comparable installer dropper:

  1. Download Inno Setup 6.5.7.1 from jrsoftware.org
  2. Write a standard .iss script with [Files] and [Run] sections
  3. Compile with iscc.exe (default settings use LZMA compression)
  4. The output is a single PE32 with Delphi stub + LZMA overlay
  5. Modify VersionInfo in the script to match the target masquerade
  6. Verify with file, strings, and binwalk — should show Inno Setup Setup Data and zlb signature

What you'll learn: how commodity installers become effective dropper vehicles, and why AV/EDR often whitelists Inno Setup stubs.

Deployable Signatures

YARA rule

rule gh0strat_inno_dropper_doubao_masquerade
{
    meta:
        description = "Inno Setup dropper with Doubao/ByteDance filename masquerade"
        author = "triage-pipeline"
        date = "2026-09-07"
        sha256 = "fdaabbf7b7585cc473502c21a1471f95de45d5492216e8e6c035e1856d6af9b1"
        family = "gh0strat"
    strings:
        $inno = "Inno Setup Setup Data (6.5.7.1)" ascii
        $doubao = "豆包" wide
        $engine = "Engine Direct Turbo" wide
        $microsoft = "Microsoft Corpora" wide
        $zlb = { 7a 6c 62 } // LZMA stream signature
    condition:
        uint16(0) == 0x5A4D and
        $inno and
        ($doubao or $engine or $microsoft) and
        $zlb
}

Sigma rule

title: Inno Setup Dropper Execution with Suspicious Filename
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        Image|endswith:
            - '\豆包.exe'
            - '\doubao.exe'
        Description|contains:
            - 'Engine Direct Turbo'
            - 'Inno Setup'
    condition: selection
falsepositives:
    - Legitimate Inno Setup installers (rare with this specific filename)
level: high

IOC list

Indicator Type Value Source
SHA-256 Hash fdaabbf7b7585cc473502c21a1471f95de45d5492216e8e6c035e1856d6af9b1 triage.json
Filename String 豆包.exe triage.json
VersionInfo CompanyName String Microsoft Corpora (padded) pefile.txt
VersionInfo FileDescription String Engine Direct Turbo Setup pefile.txt
VersionInfo FileVersion String 11.1.18245.0 pefile.txt
Inno Setup version String 6.5.7.1 strings.txt
Overlay signature Bytes zlb at 0xC7200 terminal:xxd

Behavioral fingerprint statement

This binary is a PE32 GUI executable compiled with Embarcadero Delphi 36.0, containing a standard Inno Setup 6.5.7.1 loader stub with an LZMA-compressed overlay of approximately 4.6 MB. The VersionInfo masquerades as a Microsoft product (Engine Direct Turbo Setup) while the on-disk filename impersonates ByteDance's Doubao AI assistant (豆包.exe). No code signing is present. The IAT contains only KERNEL32 imports. The payload is encrypted/compressed within the overlay and not statically recoverable. Family attribution is preliminary (gh0strat, silverfox, valleyrat co-tags) and unverified by payload extraction or dynamic analysis.

Detection Signatures

Capa Rule Status Note
installer file limitation Triggered Capa flagged as installer; cannot analyse created files without extraction. ^[capa.txt]

References

  • Artifact ID: 145ac401-cebc-4076-a43d-c8799a74b932 (OpenCTI)
  • MalwareBazaar: tagged gh0strat, silverfox, valleyrat
  • Related entity: gh0strat — tentative family page
  • Related entity: valleyrat — Inno Setup dropper cluster with co-tags
  • Related entity: silverfox — multi-variant loader/RAT cluster
  • Related entity: gh0st — historic Chinese RAT family; possible parent of gh0strat tag
  • Schema: SCHEMA.md

Provenance

Analysis derived from file.txt, pefile.txt, exiftool.json, strings.txt, triage.json, capa.txt, binwalk.txt, rabin2-info.txt, dynamic-analysis.md, and terminal commands (innoextract, 7z, strings, xxd, python/pefile). No Ghidra/radare2 decompilation performed — the stub is standard Inno Setup with no custom attacker code. CAPE dynamic analysis skipped (no Windows guest). Payload remains opaque.