meshcentral-agent-dropper
Go-based MeshCentral agent installer/dropper that downloads the legitimate MeshCentral remote-access agent from an attacker-controlled server, validates the PE, installs it as a Windows service, and launches it. Abuses the open-source MeshCentral project for unauthorized remote access. Distributed via the gcleaner multi-payload dropper pipeline.
Build Stack
- Language: Go 1.26.2
- Build flags:
CGO_ENABLED=0,-trimpath=true - Module path:
meshdrop(devel) - Source files:
meshdrop/main.go,meshdrop/exec_windows.go,meshdrop/install_windows.go - Binary: PE32+ executable (GUI) x86-64, ~6.1 MB, 8 sections, no
.rsrc, no code signing - IAT: Minimal — only
kernel32.dll(48 imports). All networking via Go stdlib. - Anti-analysis: None — no packing, no obfuscation, no VM/debug checks. Relies on masquerading as legitimate software.
Deployment / TTPs
- T1105 — Ingress Tool Transfer: HTTPS GET to
azurenetfiles.net/meshagentswith embedded mesh ID - T1543.003 — Create or Modify System Process: Windows Service: installs
MeshAgent.exeas a service via SCM APIs - T1036.005 — Masquerading: installs to
C:\Program Files\Mesh Agent\MeshAgent.exe - T1219 — Abuse Legitimate Remote Access Software: repurposes MeshCentral agent
Variants / Siblings
| SHA-256 prefix | OpenCTI label | Size | Notes | |
|---|---|---|---|---|
90989061 |
bb5.file |
6,099,968 bytes | First observed sibling — bare installer, no anti-debug ^[/intel/analyses/9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91.html] | |
d65f14e5 |
uniq.file |
6,115,328 bytes | Hardened sibling — adds harden_windows.go with IsDebuggerPresent, CheckRemoteDebuggerPresent, PEB.BeingDebugged, debug-port enumeration, parent-process name checks against 13 RE tools, and 60-second watchdog respawn. Same C2 URL, same meshdrop module. Builder evolution observed. ^[/intel/analyses/d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1.html] |
Capabilities
https-payload-downloadpe-validation-before-executionwindows-service-installationsc-manager-api-abuselegitimate-remote-access-tool-abusebrand-typosquat-c2-domaingo-buildinfo-leakageisdebuggerpresent-checkcheckremotedebuggerpresent-checkpeb-beingdebugged-readdebug-port-enumerationparent-process-re-tool-blacklistwatchdog-respawn-60spost-install-hardening
Related Entities / Concepts
- gcleaner — Distribution infrastructure
- legitimate-remote-access-tool-abuse — Cross-family concept
- meshcentral-agent-dropper — This page
References
- MeshCentral (legitimate project): https://github.com/Ylianst/MeshCentral
- OpenCTI labels:
bb5.file,dropped-by-gcleaner,uniq.file