typeentityfamily9d2ca3confidencemediumcreated2026-06-01updated2026-09-05loadermalware-familypemingwgolangobfuscationdefense-evasionsigningc2

9d2ca3

Amadey-downloader-dropped second-stage payload cluster. OpenCTI internal family label; co-tagged dropped-by-amadey across 20+ corpus samples.

Contested: The label covers at least two distinct build clusters: (1) MinGW-w64 PE32+ droppers with encrypted .data payloads, and (2) Go 1.25.4 PE64 infostealers with randomized module paths and fabricated Authenticode. Sample a7b9f3dd belongs to cluster (2) but carries the same OpenCTI label. ^[/intel/analyses/a7b9f3dda435b7f2d0dfbd1e0c8d50cb824cb60fe3343a61a5fd6aa643763c4e.html]

Also contested: Sample 1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd was tagged 9d2ca3 by OpenCTI but is actually a Quasar/xRAT rebrand (.NET Framework 4.0 Client Profile, xClient.Core namespace, v1.3.0.0). It shares zero build artefacts with the MinGW/Go/.NET dropper cluster. See quasar entity page.

Overview

The 9d2ca3 label groups a class of Windows x64 droppers dropped by the Amadey downloader botnet. Every observed sample follows the same build template: a MinGW-w64 PE32+ with a tiny .text section (< 50 KB) and an oversized .data section (2–3 MB) that carries the encrypted secondary payload. The import table is stripped to C runtime imports plus VirtualProtect and Sleep. No .rsrc section, no signing, no embedded icons.

All samples in this cluster have been static-only in this corpus: no CAPE Windows guest is available, and capa/floss tooling is not configured. The inner payload and C2 infrastructure remain opaque until dynamic detonation.

Build Stack

  • Toolchain: MinGW-w64, LinkVersion 14.0 (GCC 14.x era).
  • Format: PE32+ x86-64, 7 sections (.text, .rdata, .data, .pdata, .00cfg, .tls, .reloc).
  • Linker flags: ASLR + DEP + High Entropy VA enabled; no Control Flow Guard (.00cfg near-empty).
  • Resource: Absent — no icon masquerade, no version-info masquerade.
  • Signing: Unsigned across all observed samples.
  • Import table: ~36 imports. Only msvcrt.dll (CRT) and KERNEL32.dll (VirtualProtect, Sleep, SetUnhandledExceptionFilter, TlsGetValue).
  • Anti-analysis: Mild. __set_app_type gate present but is standard MinGW CRT behavior. The real defense is structural: near-zero imports and an encrypted .data magazine.

Deploy / TTPs

Technique ID Evidence
Software Packing T1027.002 Encrypted payload in .data section, decrypted at runtime
Process Injection (inferred) T1055 Dropper resolves payload then likely injects/hollows a child process
Reflective Code Loading (inferred) T1620 No embedded PE in static; payload shape unknown until runtime
Persistence (inferred) T1547.001 Registry Run keys used by final payload after decryption (not visible in static)
Sandbox Evasion (structural) T1497.001

.NET 4.6.2 stage-1 stager variant (sample 8f288492 — fifth distinct morph)

A completely different build under the same opaque OpenCTI label. This is a lightweight .NET Framework 4.6.2 PE32 (~17 KB) with no packing, no obfuscation, and plaintext method names (DisableDefender, AddExclusions, DownloadPayload, AddToStartup, ExecutePayload). It does not share the MinGW, Go, or .NET 4.0 WMI fingerprints.

Key traits:

  • Toolchain: .NET Framework 4.6.2 / CLR v4.0.30319, ILONLY flag, TargetFrameworkAttribute = .NETFramework,Version=v4.6.2.
  • Namespace: X7Y9Z.Q8W4K — trivially randomized, not ConfuserEx/SmartAssembly.
  • Build path: D:\desktop\PROJECT MODIFY\build\bin\Debug\net462\Stub\obj\Release\net462\Stub.pdb — suggests active development, not a polished builder kit.
  • Anti-AV: Aggressive 11-vendor AV exclusion registry spray (ESET, AVG, Bitdefender, Kaspersky, Norton, McAfee, Tencent, Avast, 360Safe, Huorong, Windows Defender). Also disables Defender real-time monitoring via PowerShell cradle.
  • Persistence: Dual — HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (SysCore) + schtasks.exe /create /tn "SysCoreUpdate" /sc onlogon /rl highest /f.
  • Payload delivery: Downloads AES-encrypted payload via System.Net.WebClient with Chrome User-Agent, decrypts via AesManaged, writes core.exe to staging directory.
  • Execution: ShellExecute with runas verb for UAC elevation attempt.
  • Signing: Unsigned.
  • C2: Payload URL runtime-resolved/encrypted; no static C2 strings.
  • Dynamic: CAPE skipped (no Windows guest). All behavior inferred from static imports + strings + capa + IL inspection.

This confirms the 9d2ca3 OpenCTI label is a grab-bag covering at least five unrelated build morphs: MinGW-w64 encrypted droppers, Go 1.25.4 infostealers, .NET Framework 4.0 AES WMI hollowing dropper, and now a .NET Framework 4.6.2 lightweight anti-AV stager.

See full analysis at /intel/analyses/8f28849296f4c10a3271aec35441bc7421be693be966f749cf50120730adb348.html.

Rust wreq/boring2 engagement bot variant (sample d7c9efe8 — eighth distinct morph)

A Rust-built PE32+ x64 engagement bot for the Korean live-streaming platform SpoonCast. Uses wreq 6.0.0-rc.28 (custom HTTP client fork) backed by boring2 5.0.0-alpha.13 (BoringSSL) for TLS 1.3, with a library of ~100+ rotated browser User-Agent strings and full header/cipher-suite masquerade. No payload delivery, no persistence, no process injection — purely an HTTP worker designed to inflate viewership metrics.

Key traits:

  • Toolchain: Rust stable x86_64-pc-windows-msvc, compiled May 29 2026 ^[/intel/analyses/d7c9efe83a46acea1c8a012e0ac0b697c3b6bc282d192d2b07cf2361d8fd8345.html]
  • Format: PE32+ x64, 5 sections, 7.3 MB
  • Dependencies: tokio-1.52.3, wreq-6.0.0-rc.28, http2-0.5.17, boring2-5.0.0-alpha.13, tokio-boring2-5.0.0, flate2-1.1.9, url-2.5.8, idna-1.1.0, icu_normalizer-2.2.0
  • Target endpoint: https://kr-hana-live.spooncast.net/cast/
  • Masquerade: Chrome/Edge/Firefox/Opera/Safari UA rotation across Windows, macOS, Linux, Android, iOS; TLS 1.3 with post-quantum hybrid X25519MLKEM768 key exchange
  • Proxy support: Reads standard *_PROXY environment variables; CONNECT tunnel capability
  • Signing: Unsigned
  • Dynamic: CAPE skipped (no Windows guest)

This confirms 9d2ca3 now spans at least eight distinct morphs.

See full analysis at /intel/analyses/d7c9efe83a46acea1c8a012e0ac0b697c3b6bc282d192d2b07cf2361d8fd8345.html.

MinGW-w64 reflective downloader variant (sample 022fe01a — sixth distinct morph)

A pure MinGW-w64 x64 downloader/loader with no embedded payload. Instead of decrypting a local .data section, it hardcodes an XOR-obfuscated C2 URL, downloads the secondary stage over HTTP, and maps it reflectively into RWX memory.

Key traits:

  • Toolchain: MinGW-w64 GCC 15.2.0 (MSYS2 Rev8), compiled May 28 2026 ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html]
  • Architecture check: Resolves IsWow64Process dynamically via GetModuleHandleA + GetProcAddress, aborts on mismatch ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html]
  • C2 decode: Five movabs qword constants XOR-decoded with key 0xAA in main() → http://89.125.188.171/nah11/file.exe ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html]
  • Download: WinHTTP with hardcoded User-Agent "Lak2oes", plain HTTP GET, streams response into malloc'd buffer ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html]
  • Reflective load: Hand-written PE mapper (LoadPERaw) validates MZ/PE/AMD64, allocates RWX memory, copies sections, resolves imports via LoadLibraryA/GetProcAddress, applies relocations, and jumps to entry point ^[/intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html]
  • No persistence, no registry — fire-and-forget downloader stub
  • Signing: Unsigned
  • Dynamic: CAPE skipped (no Windows guest)

See full analysis at /intel/analyses/022fe01a4fb8855747a4068de2131ceb7486cf846df6c18adbefe7564482adb5.html.

Rust ureq/rustls downloader variant (sample 4c25af57 — seventh distinct morph)

The first Rust-built sibling in the cluster. A stripped PE32+ x64 downloader using the ureq 2.12.1 HTTP client backed by rustls 0.23.36 and ring 0.17.14 for TLS 1.3 payload retrieval. Hardcodes a single HTTPS C2 URL (https://cloud.white-monster.xyz/cat.jpg) and a SHA-256 payload integrity hash. No embedded payload, no persistence, no process injection visible statically.

Key traits:

  • Toolchain: Rust ~1.92.0 stable (rustc commit 59807616, 2026-04-14), LLD 2.44 ^[/intel/analyses/4c25af5791f7cad042fbfc6dca3ae78b7344c66f9f3a35853e76565bae0890f3.html]
  • Format: PE32+ x64, 10 sections (.text, .data, .rdata, .pdata, .xdata, .bss, .idata, .tls, .rsrc, .reloc)
  • Dependencies: ureq 2.12.1, rustls 0.23.36, ring 0.17.14, flate2 1.1.8, base64 0.22.1, url 2.5.8, idna 1.1.0, once_cell 1.21.3, smallvec 1.15.1, crc32fast 1.5.0
  • C2: https://cloud.white-monster.xyz/cat.jpg — hardcoded in .rdata
  • Payload integrity: SHA-256 867fbc90e07b14f8b5884fdc2993bfefd900a635e08ae5bfccc42e4b9ae59398 hardcoded in .rdata
  • TLS: TLS 1.3 capable via rustls; ECH strings present but configuration unknown statically
  • Signing: Unsigned
  • Dynamic: CAPE skipped (no Windows guest)

This confirms 9d2ca3 now spans at least seven distinct morphs.

See full analysis at /intel/analyses/4c25af5791f7cad042fbfc6dca3ae78b7344c66f9f3a35853e76565bae0890f3.html.

Go cluster variant (sample a7b9f3dd)

A distinct second-stager under the same label. Build fingerprint:

  • Toolchain: Go 1.25.4, CGO_ENABLED=0, trimpath=true
  • Module path: randomized per-build (e.g. uyiUNvZdvAGQnhv)
  • Function names: ~28 randomized main-package symbols visible in .symtab
  • Signing: Fabricated Authenticode (PE security dir with leaf CN=askart.com, issuer=WE1)
  • Anti-analysis: No static C2, no .rsrc, junk delay loops in main.Jtruwhtr
  • Behaviour: VirtualAlloc resolved via Go syscall._LazyProc_; probable in-memory payload staging

See full analysis at /intel/analyses/a7b9f3dda435b7f2d0dfbd1e0c8d50cb824cb60fe3343a61a5fd6aa643763c4e.html.

Go cluster variant (sample 29149758 — newer sibling)

Second observed Go infostealer under the same label, with significant builder drift:

  • Toolchain: Go 1.25.4, CGO_ENABLED=0, trimpath=true
  • Module path: wqeHivEQWBGOQgj (randomized)
  • Function names: 39 randomized main-package symbols (up from 28 in a7b9f3dd)
  • Signing: Same fabricated Authenticode serial as sibling cc4aa789 (CDDA1164C88E40890E189788E7C9F32B, CN=askart.com, issuer=WE1)
  • Anti-analysis: Fused-string API decoding — DLL/API names are concatenated into .rdata blobs and sliced at runtime via syscall._LazyProc_; no standalone VirtualAlloc string in static output
  • Behaviour: Custom in-memory PE export walker (main.fvcmychoeu), PRNG-seeded delay loops (main.Wqmcsrfqooezj), host fingerprinting (hostname, PID, pagesize), then enters an idle GUI loop
  • Size: 12 MB (vs ~2.5 MB for a7b9f3dd) — suggests embedded payload or expanded string tables

See full analysis at /intel/analyses/2914975816372d0dc79b777915f66955d312213ea036b84ff16ad5ab0bcfdd66.html.

Go cluster variant (sample 389e1ccf — third sibling)

Third Go infostealer under the same label, confirming the cluster build pipeline:

  • Toolchain: Go 1.25.4, CGO_ENABLED=0, trimpath=true, GOARCH=amd64, GOAMD64=v1
  • Module path: LUOegnbUmXZeMZT (randomized)
  • Function names: 43 randomized main.* identifiers (upward trend in symbol count)
  • Signing: Fabricated Authenticode with godaddy.com string and WE1 marker in certificate blob; malformed ASN.1 blocks direct parsing — consistent with fabricated certs in siblings
  • Anti-analysis: Same fused-string API decoding pattern (advapi32.dllGetUserNameAVirtualAllocrandautoseedsweepWaiters...)
  • Behaviour: PRNG seed from system clock → sequential dispatch of 24 worker functions → hostname/PID/pagesize read → idle GUI loop
  • Size: 2.48 MB (typical for this cluster)
  • Filename: EclipseV2.exe (masquerade)

See full analysis at /intel/analyses/389e1ccf072f134de9d3b007df0952f43f2dc0c3a4f55fbe6f3035d1d0c14dc0.html.

.NET dropper variant (sample 2bf8e65c — fourth distinct morph)

A completely different build under the same opaque OpenCTI label. This is a .NET Framework 4.0 x64 PE compiled May 22 2026, internal name popit.exe, with a 2.1 MB IL-only .text section and a tiny .rsrc containing only the manifest. It does not share the MinGW or Go fingerprints observed in every prior sibling.

Key traits:

  • Toolchain: .NET Framework 4.0 / CLR v4.0.30319, ILONLY flag, EntryPointToken 0x06000001.
  • Payload delivery: Base64 + AES (RijndaelManaged + Rfc2898DeriveBytes) encrypted ZIP, extracted in-memory via System.IO.Compression.ZipArchive. No embedded RCData or secondary PE in .rsrc.
  • Injection: P/Invoke imports for CreateProcess, VirtualAllocEx, WriteProcessMemory, ZwUnmapViewOfSection, SetThreadContext, ResumeThread — textbook process hollowing.
  • Process targeting: WMI ManagementObjectSearcher queries Win32_Process for candidate host processes to hollow.
  • Privilege elevation: Manifest requests requireAdministrator.
  • Network hardening: Enforces TLS 1.2 via ServicePointManager.SecurityProtocol.
  • Obfuscation: Garbage identifiers (flecduep, knzhwyemdmfotslhxivggphauaduuuzem, etc.) in metadata; no ConfuserEx / SmartAssembly name mangling.
  • Signing: Unsigned.
  • C2: None in static; C2 config is runtime-decrypted by the inner payload.
  • Dynamic: CAPE skipped (no Windows guest). All behavior inferred from static imports + strings + capa.

This sample confirms the 9d2ca3 OpenCTI label is a grab-bag covering at least three unrelated build morphs: MinGW-w64 encrypted droppers, Go 1.25.4 infostealers, and now a .NET Framework 4.0 AES dropper with WMI hollowing.

See full analysis at /intel/analyses/2bf8e65cde6c51c07492255eb11f9ef2d7f02c5bd0337c1e7b1c9266d73843ce.html.

Notable Analyses

  • /intel/analyses/2d39ed5ea7f2547233f534c4e78edef047051c26c115ac120663705be96b8e5d.html — Deep-dive on the MinGW-w64 shell, oversized .data decryption, and structural anomalies.

Capabilities

  • oversized-encrypted-data-section
  • mingw-w64-build-artifacts
  • minimal-import-table
  • virtualprotect-memory-remapping
  • sleep-delay-anti-sandbox
  • data-section-payload-decryption
  • go-lazyproc-virtualalloc-runtime-resolution
  • fused-string-api-decoding
  • go-custom-pe-export-walker
  • prng-seeded-sandbox-delay
  • host-fingerprinting-idle-loop
  • dotnet-aes-base64-resource-decryption
  • wmi-process-enumeration
  • process-hollowing-via-pinvoke
  • tls-1.2-enforcement
  • manifest-admin-elevation
  • dotnet-stub-no-obfuscation
  • av-registry-exclusion-spray
  • defender-disable-powershell
  • webclient-aes-payload-download
  • schtasks-onlogon-persistence
  • shellexecute-runas-elevation
  • chrome-ua-masquerade
  • xor-movabs-c2-url-decode
  • winhttp-plain-http-get
  • hardcoded-user-agent-masquerade
  • iswow64process-arch-check
  • reflective-pe-loader-in-rwx
  • rust-ureq-rustls-downloader
  • rust-wreq-boring2-engagement-bot
  • spooncast-viewbot-ua-rotation
  • tls-1.3-post-quantum-hybrid
  • proxy-env-var-tunnel
  • tls-1.3-ech-capable
  • hardcoded-sha256-payload-integrity
  • jpg-masquerade-payload-delivery

Related

  • peb-walking-api-resolution — Some Amadey payloads use PEB export-hash walking for API resolution, though this stub relies on the import table.
  • Amadey downloader (external, Malpedia win.amadey) — the upstream delivery mechanism for this cluster.