typeentityconfidencemediumcreated2026-08-04updated2026-08-04dotnetmalware-familysocial-engineering-filename-lureversion-info-masquerade

unclassified-dotnet-bee-themed-rasterizer

A cluster of .NET Framework 4.x PE32 GUI executables masquerading as a "Procedural 3D Software Rasterizer" (internal name PRUu.exe, version 1.0.9.0). The binaries share a distinctive bee-themed internal nomenclature and a hardcoded 64-character hex string, but exhibit no observable malicious APIs statically — no network, credential, persistence, injection, or anti-analysis surfaces. Threat is purely social-engineering: distribution under business-document filenames to exploit Windows "Hide extensions" default.

Build Stack

  • Compiler: Microsoft .NET Framework 4.7.2 (CLR v4.0.30319) ^[file.txt]
  • Linker: Mono/.NET assembly, PE32 GUI, 3 sections ^[pefile.txt]
  • Timestamp: 2026-05-27 01:24:18 UTC (sample fc944b5465a4) ^[exiftool.json]
  • Version Info: "Procedural 3D Software Rasterizer" / "Native C# 3D Graphics Engine" / PRUu.exe v1.0.9.0 ^[exiftool.json]
  • Signing: Unsigned (no Authenticode certificate directory) ^[rabin2-info.txt]
  • Obfuscation: None detected. No ConfuserEx, SmartAssembly, Xenocode, or PyArmor signatures. No control-flow flattening, string encryption, or anti-debug checks. ^[capa.txt]
  • Packing: None. Standard .NET PE with .text, .rsrc, .reloc sections. No UPX, Themida, or custom packer. ^[pefile.txt]

Cluster Membership

Nine confirmed siblings as of 2026-08-04:

SHA-256 Prefix Size Filename / Notes
04cfb265 1.06 MB No version-info masquerade (empty 0.0.0.0, cXBI.exe)
4c41eeda 1.06 MB Empty version info, sqkk.exe internal name
5488fa3d 1.07 MB Empty version info, JlXC.exe internal name
91953ec6 1.06 MB Full masquerade (Procedural 3D Software Rasterizer, hYGV.exe)
91a77246 1.06 MB Full masquerade, yRmz.exe internal name
a6c4f4b0 1.06 MB Full masquerade, KtnP.exe internal name
bd34f901 1.06 MB Full masquerade, ATDQ.exe internal name
f0f11a79 1.06 MB Full masquerade, HgVN.exe internal name
fc944b54 1.06 MB Primary deep-dive sample. Shipping-document lure (TOMPS_209645_MV W TRADER_ORDER.exe) ^[triage.json]

All nine share the complete bee-themed string set and the identical 64-char hex string BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7 in #Strings metadata. ^[strings.txt:24]

Notable Strings (Cluster-Wide)

Bee-themed identifiers embedded in #Strings and method names:

  • Extract_Hive_Comb — method name ^[strings.txt:41]
  • swarmReversed — field / property name ^[strings.txt:51]
  • colonyBrand — field / property name ^[strings.txt:59]
  • apiaryFrame — field / property name ^[strings.txt:83]
  • broodCycles — field / property name ^[strings.txt:235]
  • nectarFlow — field / property name ^[strings.txt:278]
  • combReserve — field / property name ^[strings.txt:124]
  • ring_pos, ring_cap, ring_store — rasterizer state variables ^[strings.txt:247,196,92]
  • fl_sum1, fl_sum2 — label / field names ^[strings.txt:19,21]

These names are thematic, not functional threat indicators. They decorate a genuine 3D software rasterizer implementation (OBJ loader, Matrix4x4 math, triangle rasterization, wireframe/backface-culling UI toggles). The bee theme appears to be the original developer's naming convention.

Shared Hardcoded Value

Every sibling contains the identical 64-character hexadecimal string in the #Strings metadata stream:

BA06A06B07F69E88E2C96EE27F21D7668F9983E74DABAF7517BB91F0E12C4FC7

This is 32 bytes (256 bits) of opaque data. It does not match any known hash prefix, public-key fingerprint, or Bitcoin/Ethereum address format. Purpose unknown — possibly a resource integrity check, build artifact, or license watermark. Not per-sample randomized. ^[strings.txt:24]

Capabilities

  • social-engineering-filename-lure
  • version-info-masquerade
  • dotnet-winforms-gui-masquerade

No malicious capabilities observed statically. No network APIs, no credential harvesting, no persistence, no injection, no anti-analysis, no encryption, no C2.

Distinguishing Features

  • SoftwareRasterizer3D namespace with Engine and Math sub-namespaces
  • Full 3D pipeline: OBJ file loading, Matrix4x4 transforms, Vector3D operations, backface culling, wireframe toggle
  • WinForms UI: MainForm, TrackBar rotation controls, PictureBox render surface, OpenFileDialog for .obj files
  • Timer-driven RenderFrame loop
  • Standard Win32 resources: RT_ICON (PNG 256×256), RT_GROUP_ICON, RT_VERSION

Related Pages

Notes

The cluster shows hallmarks of a builder or repackaging pipeline: identical code with per-sample randomized internal EXE names (PRUu.exe, cXBI.exe, sqkk.exe, JlXC.exe, etc.) and selective version-info masquerade (some siblings have empty VS_VERSIONINFO, others have the full "Procedural 3D Software Rasterizer" metadata). The distribution filenames are business-document themed (TOMPS_209645_MV W TRADER_ORDER.exe), consistent with phishing or spam-dropper infrastructure.

Whether the binary itself is benignware repackaged by a threat actor, or an intentionally crafted decoy application, cannot be determined from static analysis alone. Dynamic execution would be required to confirm absence of runtime-loaded secondary payloads. CAPE detonation is not currently available for this sample type.