xryus-inno-dropper
Overview
Inno Setup 6.7.0 installer family masquerading as EasySuiteer Setup by SuperPlus MegaPacker. Authenticode-signed with a Microsoft ID Verified code-signing chain (leaf CN Xryus Technologies LLC, Delaware, 72-hour validity). The outer binary is a legitimate installer framework; threat logic lives in a 55.7 MB encrypted LZMA overlay that is invisible to static tools without the embedded decryption key. First confirmed sample in this knowledge base.
Confidence: low — single observed sample. Structurally aligned with the broader Inno Setup abuse cluster (poabu-inno-dropper, netsupport-inno-dropper, tofsee) but carrying a distinct certificate chain, masquerade identity, and no observed payload extraction.
Build Stack
- Toolchain: Inno Setup 6.7.0 (Delphi / Object Pascal compiler) ^[sample 45002243/strings.txt:7552]
- Arch: PE32 (x86), Windows GUI subsystem ^[sample 45002243/file.txt]
- Import Table: Standard IAT intact; delay-imports for
kernel32.dllanduser32.dll^[sample 45002243/pefile.txt:DelayImport] - Overlay: 55.7 MB encrypted LZMA-compressed Inno Setup archive at offset
0xDA400^[sample 45002243/binwalk.txt] - Signing: Authenticode-signed (
signed=true); Microsoft ID Verified chain with leaf CNXryus Technologies LLC^[sample 45002243/certificate-chain.txt] - Masquerade: Fabricated version info claiming
EasySuiteer SetupbySuperPlus MegaPacker, ProductVersion3.9.9^[sample 45002243/exiftool.json]
Capabilities
inno-setup-legitimate-installer-abuselzma-encrypted-overlay-archivemicrosoft-id-verified-code-signingversion-info-masqueradedelay-import-anti-vmeasy-suite-social-engineering
Deploy / TTPs
| Technique | ID | Evidence |
|---|---|---|
| Masquerading | T1036.002 | EasySuiteer Setup by SuperPlus MegaPacker ^[sample 45002243/exiftool.json] |
| Software Packing | T1027.002 | Encrypted LZMA-compressed Inno Setup archive (55.7 MB) ^[sample 45002243/binwalk.txt] |
| Code Signing | T1553.002 | Valid Authenticode with Microsoft ID Verified chain ^[sample 45002243/certificate-chain.txt] |
| Ingress Tool Transfer | T1105 | Drops unknown payload via Inno Setup NumFileEntries/NumRunEntries ^[sample 45002243/strings.txt:7151-7158] |
| Virtualization/Sandbox Evasion | T1497.001 | Delay-imported GetLogicalProcessorInformation for CPU-feature anti-VM ^[sample 45002243/pefile.txt:630] |
Variants / Aliases
xryus-inno-dropper— this wiki labelEasySuiteer Setup— observed masquerade product nameSuperPlus MegaPacker— observed masquerade company nameXryus Technologies LLC— certificate subject CN- Inner payload family unconfirmed (encrypted overlay unextracted)
Notable Analyses
- /intel/analyses/450022431a5d5d5589895b878420747c860a85928d560f48355acbc8825ba744.html — 45002243, static-only, no CAPE detonation
Related
- poabu-inno-dropper — structurally similar Inno Setup 6.7.0 installer family (Sectigo-signed, Tim Kosse cert, contact-service masquerade)
- netsupport-inno-dropper — structurally similar Inno Setup 6.7.0 installer family (unsigned, Intel driver masquerade)
- tofsee — structurally similar Inno Setup 6.7.0 installer family (unsigned, Blacker LLC masquerade, spam-botnet payload)
- inno-setup-legitimate-installer-abuse — concept page for Inno Setup abuse in malware distribution
- version-info-masquerade — generic masquerade technique
- stolen-certificate-signing — concept page for certificate abuse (note: this cert may be attacker-provisioned rather than stolen; Microsoft ID Verified has low identity-assurance barriers)