typetechniqueconfidencehighcreated2026-08-13updated2026-09-08defense-evasionmasqueradepedotnetanti-analysis

Version Info Masquerade

What It Does

Malware authors clone or fabricate VS_VERSIONINFO resource blocks in PE binaries to make their executables appear as legitimate, well-known software during superficial triage. By copying CompanyName, FileDescription, FileVersion, ProductName, LegalCopyright, and icon groups from popular applications (AnyDesk, Adobe Reader, Chrome, Microsoft Edge, etc.), the binary passes quick visual inspection in file managers, process explorers, and naive sandbox reports.

Detection / Fingerprint

  • Size mismatch: The masqueraded binary is often orders of magnitude smaller than the legitimate software it impersonates. Example: AnyDesk legitimate ~4 MB+; this masquerade was 32 KB. ^[/intel/analyses/2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2.html]
  • Metadata inconsistency: ProductVersion may be 0.0.0.0 while FileVersion is populated. ^[pefile.txt:202]
  • Empty or generic PE headers: MinorImageVersion = 0, MajorImageVersion = 0, no debug directory. ^[pefile.txt:59-62]
  • Unsigned: Most masquerades lack Authenticode even when the impersonated product is typically signed. ^[rabin2-info.txt:27]
  • Icon group mismatch: The RT_ICON group may be borrowed but the binary contains no other product-specific resources (no manifests, no localisation tables, no XML config).

Implementation Patterns

  1. Direct clone: Copy the VS_VERSIONINFO block and icon group from a legitimate binary using a resource editor (Resource Hacker, CFF Explorer).
  2. Fabricated fields: Invent plausibly-sounding company names (e.g., "Erdman Group", "TransMock", "AnyDesk Software GmbH") with version numbers that track real releases.
  3. Borrowed strings only: Populate FileDescription and ProductName but leave other fields empty or generic.

Defensive Countermeasures

  • Weight version-info trust by Authenticode validity and publisher chain, not by string content alone.
  • Flag PEs where FileVersion / ProductVersion strings do not match the VS_FIXEDFILEINFO numeric fields.
  • Alert on PEs whose size is < 10% of the known-good baseline for the claimed product.
  • Correlate CompanyName against known threat-actor masquerade strings (e.g., "Mcrosoft").

Pages Where Observed

  • unclassified-batch-powershell-dropper 2232eb68 — AnyDesk 9.6.11 masquerade, 32 KB .NET PE32. ^[/intel/analyses/2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2.html]
  • unclassified-nsis-dropper cluster — Danish/French word-salad VS_VERSIONINFO with fabricated self-signed certs. ^[entities/unclassified-nsis-dropper.md]
  • unclassified-dotnet-native-aot-loader — Chromium/Edge ELF export masquerade with no payload resource. ^[entities/unclassified-dotnet-native-aot-loader.md]
  • bromechokucom — Delphi banking trojan with professional metadata. ^[entities/bromechokucom.md]
  • silverfox — "Aether Sync Agent" version-info masquerade. ^[entities/silverfox.md]
  • unclassified-pe32 — "Mcrosoft" version-info masquerade. ^[entities/unclassified-pe32.md]
  • unattributed 01372355 — TreeSize Disk Space Manager v7.3.8869.669 masquerade on Themida-packed x64 PE with self-signed Logitech cert. ^[/intel/analyses/013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7.html]
  • quasar 62f608d6 — Stock open-source Quasar RAT v1.4.1.0 with fabricated MICROSOFT PUBLISHING / NamCO / Latest_unreleased-v1.3.45 version-info. OriginalFilename and InternalName blanked. On-disk filename borrows XenoRAT branding (Xeno-v1.3.50.exe). ^[/intel/analyses/62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9a.html]

Related