typeentityconfidencehighcreated2026-08-08updated2026-08-18malware-familydownloaderinstallerpegolangc2persistencedefense-evasion

meshcentral-agent-dropper

Go-based MeshCentral agent installer/dropper that downloads the legitimate MeshCentral remote-access agent from an attacker-controlled server, validates the PE, installs it as a Windows service, and launches it. Abuses the open-source MeshCentral project for unauthorized remote access. Distributed via the gcleaner multi-payload dropper pipeline.

Build Stack

  • Language: Go 1.26.2
  • Build flags: CGO_ENABLED=0, -trimpath=true
  • Module path: meshdrop (devel)
  • Source files: meshdrop/main.go, meshdrop/exec_windows.go, meshdrop/install_windows.go
  • Binary: PE32+ executable (GUI) x86-64, ~6.1 MB, 8 sections, no .rsrc, no code signing
  • IAT: Minimal — only kernel32.dll (48 imports). All networking via Go stdlib.
  • Anti-analysis: None — no packing, no obfuscation, no VM/debug checks. Relies on masquerading as legitimate software.

Deployment / TTPs

  • T1105 — Ingress Tool Transfer: HTTPS GET to azurenetfiles.net/meshagents with embedded mesh ID
  • T1543.003 — Create or Modify System Process: Windows Service: installs MeshAgent.exe as a service via SCM APIs
  • T1036.005 — Masquerading: installs to C:\Program Files\Mesh Agent\MeshAgent.exe
  • T1219 — Abuse Legitimate Remote Access Software: repurposes MeshCentral agent

Variants / Siblings

SHA-256 prefix OpenCTI label Size Notes
90989061 bb5.file 6,099,968 bytes First observed sibling — bare installer, no anti-debug ^[/intel/analyses/9098906159e0e4c845eb918886fadc2723f2a321281b8003e471f09140321f91.html]
d65f14e5 uniq.file 6,115,328 bytes Hardened sibling — adds harden_windows.go with IsDebuggerPresent, CheckRemoteDebuggerPresent, PEB.BeingDebugged, debug-port enumeration, parent-process name checks against 13 RE tools, and 60-second watchdog respawn. Same C2 URL, same meshdrop module. Builder evolution observed. ^[/intel/analyses/d65f14e5652a4330354826925dc56937334163656f24dd10f112c15bc7559de1.html]

Capabilities

  • https-payload-download
  • pe-validation-before-execution
  • windows-service-installation
  • sc-manager-api-abuse
  • legitimate-remote-access-tool-abuse
  • brand-typosquat-c2-domain
  • go-buildinfo-leakage
  • isdebuggerpresent-check
  • checkremotedebuggerpresent-check
  • peb-beingdebugged-read
  • debug-port-enumeration
  • parent-process-re-tool-blacklist
  • watchdog-respawn-60s
  • post-install-hardening

Related Entities / Concepts

References

  • MeshCentral (legitimate project): https://github.com/Ylianst/MeshCentral
  • OpenCTI labels: bb5.file, dropped-by-gcleaner, uniq.file