unclassified-dotnet-bee-themed-rasterizer
A cluster of .NET Framework 4.x PE32 GUI executables masquerading as a "Procedural 3D Software Rasterizer" (internal name PRUu.exe, version 1.0.9.0). The binaries share a distinctive bee-themed internal nomenclature and a hardcoded 64-character hex string, but exhibit no observable malicious APIs statically — no network, credential, persistence, injection, or anti-analysis surfaces. Threat is purely social-engineering: distribution under business-document filenames to exploit Windows "Hide extensions" default.
Build Stack
- Compiler: Microsoft .NET Framework 4.7.2 (CLR v4.0.30319) ^[file.txt]
- Linker: Mono/.NET assembly, PE32 GUI, 3 sections ^[pefile.txt]
- Timestamp: 2026-05-27 01:24:18 UTC (sample
fc944b5465a4) ^[exiftool.json] - Version Info: "Procedural 3D Software Rasterizer" / "Native C# 3D Graphics Engine" /
PRUu.exev1.0.9.0 ^[exiftool.json] - Signing: Unsigned (no Authenticode certificate directory) ^[rabin2-info.txt]
- Obfuscation: None detected. No ConfuserEx, SmartAssembly, Xenocode, or PyArmor signatures. No control-flow flattening, string encryption, or anti-debug checks. ^[capa.txt]
- Packing: None. Standard .NET PE with
.text,.rsrc,.relocsections. No UPX, Themida, or custom packer. ^[pefile.txt]
Cluster Membership
Nine confirmed siblings as of 2026-08-04:
| SHA-256 Prefix | Size | Filename / Notes |
|---|---|---|
04cfb265 |
1.06 MB | No version-info masquerade (empty 0.0.0.0, cXBI.exe) |
4c41eeda |
1.06 MB | Empty version info, sqkk.exe internal name |
5488fa3d |
1.07 MB | Empty version info, JlXC.exe internal name |
91953ec6 |
1.06 MB | Full masquerade (Procedural 3D Software Rasterizer, hYGV.exe) |
91a77246 |
1.06 MB | Full masquerade, yRmz.exe internal name |
a6c4f4b0 |
1.06 MB | Full masquerade, KtnP.exe internal name |
bd34f901 |
1.06 MB | Full masquerade, ATDQ.exe internal name |
f0f11a79 |
1.06 MB | Full masquerade, HgVN.exe internal name |
fc944b54 |
1.06 MB | Primary deep-dive sample. Shipping-document lure (TOMPS_209645_MV W TRADER_ORDER.exe) ^[triage.json] |
All nine share the complete bee-themed string set and the identical 64-char hex string BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7 in #Strings metadata. ^[strings.txt:24]
Notable Strings (Cluster-Wide)
Bee-themed identifiers embedded in #Strings and method names:
Extract_Hive_Comb— method name ^[strings.txt:41]swarmReversed— field / property name ^[strings.txt:51]colonyBrand— field / property name ^[strings.txt:59]apiaryFrame— field / property name ^[strings.txt:83]broodCycles— field / property name ^[strings.txt:235]nectarFlow— field / property name ^[strings.txt:278]combReserve— field / property name ^[strings.txt:124]ring_pos,ring_cap,ring_store— rasterizer state variables ^[strings.txt:247,196,92]fl_sum1,fl_sum2— label / field names ^[strings.txt:19,21]
These names are thematic, not functional threat indicators. They decorate a genuine 3D software rasterizer implementation (OBJ loader, Matrix4x4 math, triangle rasterization, wireframe/backface-culling UI toggles). The bee theme appears to be the original developer's naming convention.
Shared Hardcoded Value
Every sibling contains the identical 64-character hexadecimal string in the #Strings metadata stream:
BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7
This is 32 bytes (256 bits) of opaque data. It does not match any known hash prefix, public-key fingerprint, or Bitcoin/Ethereum address format. Purpose unknown — possibly a resource integrity check, build artifact, or license watermark. Not per-sample randomized. ^[strings.txt:24]
Capabilities
social-engineering-filename-lureversion-info-masqueradedotnet-winforms-gui-masquerade
No malicious capabilities observed statically. No network APIs, no credential harvesting, no persistence, no injection, no anti-analysis, no encryption, no C2.
Distinguishing Features
SoftwareRasterizer3Dnamespace withEngineandMathsub-namespaces- Full 3D pipeline: OBJ file loading, Matrix4x4 transforms, Vector3D operations, backface culling, wireframe toggle
- WinForms UI:
MainForm,TrackBarrotation controls,PictureBoxrender surface,OpenFileDialogfor.objfiles - Timer-driven
RenderFrameloop - Standard Win32 resources: RT_ICON (PNG 256×256), RT_GROUP_ICON, RT_VERSION
Related Pages
- social-engineering-filename-lure — the actual threat mechanism
- version-info-masquerade — falsified benign metadata
- unattributed — umbrella entity for singletons pending cluster confirmation
- unclassified-dotnet — broader umbrella for .NET Framework binaries lacking crimeware signatures
Notes
The cluster shows hallmarks of a builder or repackaging pipeline: identical code with per-sample randomized internal EXE names (PRUu.exe, cXBI.exe, sqkk.exe, JlXC.exe, etc.) and selective version-info masquerade (some siblings have empty VS_VERSIONINFO, others have the full "Procedural 3D Software Rasterizer" metadata). The distribution filenames are business-document themed (TOMPS_209645_MV W TRADER_ORDER.exe), consistent with phishing or spam-dropper infrastructure.
Whether the binary itself is benignware repackaged by a threat actor, or an intentionally crafted decoy application, cannot be determined from static analysis alone. Dynamic execution would be required to confirm absence of runtime-loaded secondary payloads. CAPE detonation is not currently available for this sample type.