typeanalysisfamilyunattributedconfidencelowcreated2026-08-24updated2026-08-24pepackerobfuscationevasionsigningdefense-evasionmasqueradingthemidagcleaner
SHA-256: 013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7

unattributed-themida-x64: 01372355 — Themida-packed PE32+ with TreeSize masquerade, self-signed Logitech cert, dropped-by-gcleaner

Executive Summary

A 3.2 MB PE32+ x64 binary packed with Themida/WinLicense, masquerading as JAM Software's TreeSize Disk Space Manager via version info, embedded manifest, and a six-icon PNG suite. Signed with a fabricated self-signed certificate bearing CN Logitech (the peripherals vendor) and counter-signed by Sectigo Public Time Stamping CA R36. The entry point sits in a .boot section containing an LZ77 bit-stream decompressor that unpacks an encrypted payload at runtime. Only three imports are exposed. Distributed via the gcleaner / mix8.file pipeline per OpenCTI labels. No CAPE detonation was possible; all behavior is inferred from static reverse engineering. Static-only analysis.

What It Is

Field Value
SHA-256 013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7
Size 3,237,040 bytes (3.2 MB) ^[triage.json]
Type PE32+ executable (GUI) x86-64, 8 sections ^[file.txt]
Compiler MSVC 14.29 (Visual Studio 2019 v142), C/C++ ^[exiftool.json] ^[rabin2-info.txt]
Timestamp Tue Sep 10 18:27:51 2019 UTC ^[pefile.txt]
Packing Themida/WinLicense — .themida placeholder, .boot LZ77 decompressor stub, blank section names ^[pefile.txt] ^[ghidra:entry]
Imports kernel32.dll.GetModuleHandleA, USER32.dll.GetMessageTime, GDI32.dll.CreateSolidBrush only ^[pefile.txt]
Version Info TreeSize Disk Space Manager / TreeSize / v7.3.8869.669 / TreeSize.exe ^[pefile.txt] ^[exiftool.json]
Manifest name="TreeSize.TreeSize", DPI-aware PerMonitor, Windows 7–10 compatibility GUIDs ^[strings.txt]
Certificate Self-signed CN=Logitech (SHA-384, serial 138638360674848654771057273460448502471, validity 2026-05-29 → 2027-05-29), Sectigo timestamp counter-signature ^[terminal:openssl]
Resources Six PNG icons (256×256, 128×128, 64×64, 48×48, 32×32, 16×16) in .rsrc ^[binwalk.txt]
Distribution dropped-by-gcleaner, mix8.file per OpenCTI labels ^[metadata.json]

The binary bears no known family attribution beyond the gcleaner distribution umbrella. It is the second confirmed Themida-packed sample in this corpus with a fabricated self-signed certificate and legitimate-software version-info masquerade, following sibling 616740a4 (Proton Drive / Equalizer APO). ^[entities/unattributed.md]

How It Works

Boot & Decompression

The entry point at 0x1404bc058 (.boot section, VA 0x1404bc000) is a compact LZ77 bit-stream decompressor written in x64 assembly. The decompilation reveals a classic bit-reader loop: a control byte is shifted left, and when the carry-out is set the next bit(s) encode a back-reference; otherwise a literal is emitted. When the control byte exhausts, a new one is fetched from the input stream^[r2:entry0].

The decompressed output is an encrypted PE payload mapped into memory and executed without touching disk. The .themida section (virtual size 0x44C000, raw size 0) is a zero-length placeholder reserving address space for the decrypted image. The first five PE section names are blanked (eight spaces each) to hinder section-based clustering^[pefile.txt].

Masquerade Layers

  1. Version info clones JAM Software's TreeSize — product name TreeSize Disk Space Manager, copyright © TreeSize. All rights reserved., internal name TreeSize.exe^[pefile.txt].
  2. Manifest carries the full TreeSize assembly identity with Common-Controls dependency and DPI awareness^[strings.txt].
  3. Certificate hijacks the identity of Logitech, a legitimate Swiss peripherals manufacturer. The cert is self-signed (issuer = subject = CN=Logitech), not stolen from a real CA^[terminal:openssl].
  4. Icons are six standard Windows-application PNGs; they do not match TreeSize's actual branding, suggesting generic replacement by the packer/editor^[binwalk.txt].

Resource Surface

The .rsrc section contains six PNG icon groups (RT_ICON ids 1–6) and an XML assembly manifest. No other RT_RCDATA, RT_DIALOG, or RT_STRING resources are present. The manifest is a faithful copy of a typical MSVC-generated application manifest with DPI-awareness and OS-compatibility GUIDs^[strings.txt].

Decompiled Behavior

Radare2 analysis found 1,283 functions, but the vast majority are encrypted garbage inside .boot. The true entry function (entry0 at 0x1404bc058) is a compact LZ77 decompressor with no Windows API calls during its main loop^[r2:entry0]. It uses RSI as the source bit-stream pointer, RDI as the destination, and a control byte (dl) shifted left to gate literal vs back-reference emission. No anti-debug or anti-VM checks are visible in the outer stub.

Capa aborted with the packed-file limitation warning — expected for Themida^[capa.txt].

C2 Infrastructure

No C2 strings, IPs, domains, mutexes, named pipes, or registry keys were recovered from the outer binary. All network behavior is sealed inside the encrypted .boot payload. The LZ77 decompressor must run (or the sample must be dynamically unpacked) before any IOCs become visible.

Interesting Tidbits

  • The certificate validity window (May 29 2026 – May 29 2027) post-dates the binary's Sep 2019 compile timestamp by nearly seven years, indicating fresh generation at build time^[terminal:openssl].
  • Sectigo timestamp counter-signature (Sectigo Public Time Stamping Signer R36) is present but only proves when signing occurred; it does not make the self-signed cert trusted^[terminal:openssl].
  • The .themida section has zero raw size and entropy 0.0, confirming it is a virtual-only placeholder used by the packer for memory layout^[pefile.txt].
  • .boot entropy is 7.9446 — near-maximum, consistent with encrypted/compressed payload^[pefile.txt].
  • The three exposed imports (GetModuleHandleA, GetMessageTime, CreateSolidBrush) are effectively decoys; the real API surface is resolved at runtime after decompression.
  • The dropped-by-gcleaner / mix8.file OpenCTI labels place this sample in the same distribution pipeline as valetgate, meshcentral-agent-dropper, and poabu-inno-dropper, though the inner payload family is unknown.

How To Mess With It (Homelab Replication)

Toolchain: Themida/WinLicense (Oreans Technologies) with "SecureEngine" enabled. Visual Studio 2019 C++ for the payload. Target: x64 Windows GUI.

Steps:

  1. Build a trivial x64 PE (e.g., MessageBox hello-world).
  2. Pack it with Themida, enabling .boot section placement and import elimination (reduce to 2–3 APIs).
  3. Self-sign the output with New-SelfSignedCertificate -Subject "CN=Logitech" -KeyUsage DigitalSignature -Type CodeSigningCert.
  4. Edit VS_VERSIONINFO with Resource Hacker to clone TreeSize metadata.
  5. Embed a six-icon PNG suite in .rsrc.
  6. Inspect with pefile / rabin2 -I: should see .themida and .boot, entry point in .boot, ≤3 imports, blank first-five section names.

Verification: Run capa on the packed output — it should emit the packed-file limitation warning. Compare section entropies: .boot should be near 8.0.

What you'll learn: How commercial packers strip static API surfaces and how self-signed certificates with timestamp counter-signatures evade naive "is it signed?" triage checks.

Deployable Signatures

YARA Rule

rule Themida_x64_TreeSize_Masquerade_Gcleaner
{
    meta:
        description = "Themida-packed x64 PE with TreeSize version-info masquerade and gcleaner distribution tags"
        author = "PacketPursuit SOC"
        date = "2026-08-24"
        sha256 = "013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7"
    strings:
        $treesize_vi = "TreeSize Disk Space Manager" wide
        $treesize_fn = "TreeSize.exe" wide
        $treesize_co = "TreeSize" wide
        $themida = ".themida"
        $boot = ".boot"
        $logitech_cert = { 30 82 ?? ?? 30 82 ?? ?? a0 03 02 01 02 02 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0c 05 00 } // PKCS#7 with SHA-384 OID
    condition:
        uint16(0) == 0x5a4d and
        pe.machine == pe.MACHINE_AMD64 and
        pe.number_of_sections == 8 and
        $themida and
        $boot and
        ($treesize_vi or $treesize_fn or $treesize_co) and
        filesize > 3MB and filesize < 4MB
}

Sigma Rule

title: Themida Packed PE with Minimal IAT and Self-Signed Certificate
logsource:
    product: windows
    category: image_load
detection:
    selection:
        - ImageLoaded|contains: '.themida'
        - ImageLoaded|endswith: '.exe'
    condition: selection
falsepositives:
    - Rare legitimate software packed with Themida/WinLicense
level: medium

IOC List

Indicator Value Type
SHA-256 013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7 Hash
ssdeep 98304:14GdoSDFyj/AMJUJPK7uTaD3N+Wp/MiuIb:GGKSU/AMJ4CgaDtpCA Hash
File name file (MalwareBazaar upload name) Filename
Certificate Subject CN=Logitech Certificate
Certificate Serial 138638360674848654771057273460448502471 Certificate
Certificate Validity 2026-05-29 05:43:46 UTC → 2027-05-29 05:53:47 UTC Certificate
Timestamp Counter-Signer CN=Sectigo Public Time Stamping Signer R36 Certificate
Version Info TreeSize Disk Space Manager v7.3.8869.669 Metadata
Internal Name TreeSize.exe Metadata
Original Filename TreeSize.exe Metadata
Compile Timestamp 2019-09-10 18:27:51 UTC Metadata
Distribution Label dropped-by-gcleaner, mix8.file Tag

Behavioral Fingerprint Statement

This binary is a PE32+ x64 executable packed with Themida/WinLicense. On disk it presents eight sections, the first five of which have blank names (eight spaces). The .themida section has zero raw size and maximum virtual size, serving as a memory placeholder. The .boot section contains the entry point, a compact LZ77 bit-stream decompressor that unpacks an encrypted payload in-memory without disk writes. The import table exposes only three APIs (GetModuleHandleA, GetMessageTime, CreateSolidBrush) — the real API surface is resolved at runtime after decompression. The binary carries a cloned VS_VERSIONINFO block and XML assembly manifest impersonating TreeSize Disk Space Manager, plus six generic PNG icons. It is signed with a self-signed SHA-384 certificate bearing CN Logitech and a Sectigo timestamp counter-signature. The certificate validity window post-dates the PE compile timestamp by ~7 years.

Detection Signatures

  • Capa: packed-file limitation warning (internal packer file limitation rule) ^[capa.txt]
  • pefile: Suspicious flags set for section 6. Both IMAGE_SCN_MEM_WRITE and IMAGE_SCN_MEM_EXECUTE are set. ^[pefile.txt]
  • rabin2: signed: true, lang: c, nx: false ^[rabin2-info.txt]

References

Provenance

  • file.txt — file(1) output
  • exiftool.json — ExifTool PE metadata
  • pefile.txt — pefile.py structural analysis
  • strings.txt — strings(1) output
  • rabin2-info.txt — radare2 rabin2 -I header summary
  • binwalk.txt — binwalk embedded-artifact scan
  • capa.txt — Mandiant capa capability detection
  • triage.json — triage pipeline metadata
  • metadata.json — artifact metadata
  • Radare2 analysis (level 3, 1283 functions) — entry point decompilation at 0x1404bc058
  • Python + cryptography.x509 — certificate extraction from WIN_CERTIFICATE at offset 0x314600