013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7unattributed-themida-x64: 01372355 — Themida-packed PE32+ with TreeSize masquerade, self-signed Logitech cert, dropped-by-gcleaner
Executive Summary
A 3.2 MB PE32+ x64 binary packed with Themida/WinLicense, masquerading as JAM Software's TreeSize Disk Space Manager via version info, embedded manifest, and a six-icon PNG suite. Signed with a fabricated self-signed certificate bearing CN Logitech (the peripherals vendor) and counter-signed by Sectigo Public Time Stamping CA R36. The entry point sits in a .boot section containing an LZ77 bit-stream decompressor that unpacks an encrypted payload at runtime. Only three imports are exposed. Distributed via the gcleaner / mix8.file pipeline per OpenCTI labels. No CAPE detonation was possible; all behavior is inferred from static reverse engineering. Static-only analysis.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7 |
| Size | 3,237,040 bytes (3.2 MB) ^[triage.json] |
| Type | PE32+ executable (GUI) x86-64, 8 sections ^[file.txt] |
| Compiler | MSVC 14.29 (Visual Studio 2019 v142), C/C++ ^[exiftool.json] ^[rabin2-info.txt] |
| Timestamp | Tue Sep 10 18:27:51 2019 UTC ^[pefile.txt] |
| Packing | Themida/WinLicense — .themida placeholder, .boot LZ77 decompressor stub, blank section names ^[pefile.txt] ^[ghidra:entry] |
| Imports | kernel32.dll.GetModuleHandleA, USER32.dll.GetMessageTime, GDI32.dll.CreateSolidBrush only ^[pefile.txt] |
| Version Info | TreeSize Disk Space Manager / TreeSize / v7.3.8869.669 / TreeSize.exe ^[pefile.txt] ^[exiftool.json] |
| Manifest | name="TreeSize.TreeSize", DPI-aware PerMonitor, Windows 7–10 compatibility GUIDs ^[strings.txt] |
| Certificate | Self-signed CN=Logitech (SHA-384, serial 138638360674848654771057273460448502471, validity 2026-05-29 → 2027-05-29), Sectigo timestamp counter-signature ^[terminal:openssl] |
| Resources | Six PNG icons (256×256, 128×128, 64×64, 48×48, 32×32, 16×16) in .rsrc ^[binwalk.txt] |
| Distribution | dropped-by-gcleaner, mix8.file per OpenCTI labels ^[metadata.json] |
The binary bears no known family attribution beyond the gcleaner distribution umbrella. It is the second confirmed Themida-packed sample in this corpus with a fabricated self-signed certificate and legitimate-software version-info masquerade, following sibling 616740a4 (Proton Drive / Equalizer APO). ^[entities/unattributed.md]
How It Works
Boot & Decompression
The entry point at 0x1404bc058 (.boot section, VA 0x1404bc000) is a compact LZ77 bit-stream decompressor written in x64 assembly. The decompilation reveals a classic bit-reader loop: a control byte is shifted left, and when the carry-out is set the next bit(s) encode a back-reference; otherwise a literal is emitted. When the control byte exhausts, a new one is fetched from the input stream^[r2:entry0].
The decompressed output is an encrypted PE payload mapped into memory and executed without touching disk. The .themida section (virtual size 0x44C000, raw size 0) is a zero-length placeholder reserving address space for the decrypted image. The first five PE section names are blanked (eight spaces each) to hinder section-based clustering^[pefile.txt].
Masquerade Layers
- Version info clones JAM Software's TreeSize — product name
TreeSize Disk Space Manager, copyright© TreeSize. All rights reserved., internal nameTreeSize.exe^[pefile.txt]. - Manifest carries the full TreeSize assembly identity with Common-Controls dependency and DPI awareness^[strings.txt].
- Certificate hijacks the identity of Logitech, a legitimate Swiss peripherals manufacturer. The cert is self-signed (issuer = subject =
CN=Logitech), not stolen from a real CA^[terminal:openssl]. - Icons are six standard Windows-application PNGs; they do not match TreeSize's actual branding, suggesting generic replacement by the packer/editor^[binwalk.txt].
Resource Surface
The .rsrc section contains six PNG icon groups (RT_ICON ids 1–6) and an XML assembly manifest. No other RT_RCDATA, RT_DIALOG, or RT_STRING resources are present. The manifest is a faithful copy of a typical MSVC-generated application manifest with DPI-awareness and OS-compatibility GUIDs^[strings.txt].
Decompiled Behavior
Radare2 analysis found 1,283 functions, but the vast majority are encrypted garbage inside .boot. The true entry function (entry0 at 0x1404bc058) is a compact LZ77 decompressor with no Windows API calls during its main loop^[r2:entry0]. It uses RSI as the source bit-stream pointer, RDI as the destination, and a control byte (dl) shifted left to gate literal vs back-reference emission. No anti-debug or anti-VM checks are visible in the outer stub.
Capa aborted with the packed-file limitation warning — expected for Themida^[capa.txt].
C2 Infrastructure
No C2 strings, IPs, domains, mutexes, named pipes, or registry keys were recovered from the outer binary. All network behavior is sealed inside the encrypted .boot payload. The LZ77 decompressor must run (or the sample must be dynamically unpacked) before any IOCs become visible.
Interesting Tidbits
- The certificate validity window (May 29 2026 – May 29 2027) post-dates the binary's Sep 2019 compile timestamp by nearly seven years, indicating fresh generation at build time^[terminal:openssl].
- Sectigo timestamp counter-signature (
Sectigo Public Time Stamping Signer R36) is present but only proves when signing occurred; it does not make the self-signed cert trusted^[terminal:openssl]. - The
.themidasection has zero raw size and entropy 0.0, confirming it is a virtual-only placeholder used by the packer for memory layout^[pefile.txt]. .bootentropy is 7.9446 — near-maximum, consistent with encrypted/compressed payload^[pefile.txt].- The three exposed imports (
GetModuleHandleA,GetMessageTime,CreateSolidBrush) are effectively decoys; the real API surface is resolved at runtime after decompression. - The
dropped-by-gcleaner/mix8.fileOpenCTI labels place this sample in the same distribution pipeline as valetgate, meshcentral-agent-dropper, and poabu-inno-dropper, though the inner payload family is unknown.
How To Mess With It (Homelab Replication)
Toolchain: Themida/WinLicense (Oreans Technologies) with "SecureEngine" enabled. Visual Studio 2019 C++ for the payload. Target: x64 Windows GUI.
Steps:
- Build a trivial x64 PE (e.g., MessageBox hello-world).
- Pack it with Themida, enabling
.bootsection placement and import elimination (reduce to 2–3 APIs). - Self-sign the output with
New-SelfSignedCertificate -Subject "CN=Logitech" -KeyUsage DigitalSignature -Type CodeSigningCert. - Edit VS_VERSIONINFO with Resource Hacker to clone TreeSize metadata.
- Embed a six-icon PNG suite in
.rsrc. - Inspect with
pefile/rabin2 -I: should see.themidaand.boot, entry point in.boot, ≤3 imports, blank first-five section names.
Verification: Run capa on the packed output — it should emit the packed-file limitation warning. Compare section entropies: .boot should be near 8.0.
What you'll learn: How commercial packers strip static API surfaces and how self-signed certificates with timestamp counter-signatures evade naive "is it signed?" triage checks.
Deployable Signatures
YARA Rule
rule Themida_x64_TreeSize_Masquerade_Gcleaner
{
meta:
description = "Themida-packed x64 PE with TreeSize version-info masquerade and gcleaner distribution tags"
author = "PacketPursuit SOC"
date = "2026-08-24"
sha256 = "013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7"
strings:
$treesize_vi = "TreeSize Disk Space Manager" wide
$treesize_fn = "TreeSize.exe" wide
$treesize_co = "TreeSize" wide
$themida = ".themida"
$boot = ".boot"
$logitech_cert = { 30 82 ?? ?? 30 82 ?? ?? a0 03 02 01 02 02 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0c 05 00 } // PKCS#7 with SHA-384 OID
condition:
uint16(0) == 0x5a4d and
pe.machine == pe.MACHINE_AMD64 and
pe.number_of_sections == 8 and
$themida and
$boot and
($treesize_vi or $treesize_fn or $treesize_co) and
filesize > 3MB and filesize < 4MB
}
Sigma Rule
title: Themida Packed PE with Minimal IAT and Self-Signed Certificate
logsource:
product: windows
category: image_load
detection:
selection:
- ImageLoaded|contains: '.themida'
- ImageLoaded|endswith: '.exe'
condition: selection
falsepositives:
- Rare legitimate software packed with Themida/WinLicense
level: medium
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7 |
Hash |
| ssdeep | 98304:14GdoSDFyj/AMJUJPK7uTaD3N+Wp/MiuIb:GGKSU/AMJ4CgaDtpCA |
Hash |
| File name | file (MalwareBazaar upload name) |
Filename |
| Certificate Subject | CN=Logitech |
Certificate |
| Certificate Serial | 138638360674848654771057273460448502471 |
Certificate |
| Certificate Validity | 2026-05-29 05:43:46 UTC → 2027-05-29 05:53:47 UTC | Certificate |
| Timestamp Counter-Signer | CN=Sectigo Public Time Stamping Signer R36 |
Certificate |
| Version Info | TreeSize Disk Space Manager v7.3.8869.669 |
Metadata |
| Internal Name | TreeSize.exe |
Metadata |
| Original Filename | TreeSize.exe |
Metadata |
| Compile Timestamp | 2019-09-10 18:27:51 UTC | Metadata |
| Distribution Label | dropped-by-gcleaner, mix8.file |
Tag |
Behavioral Fingerprint Statement
This binary is a PE32+ x64 executable packed with Themida/WinLicense. On disk it presents eight sections, the first five of which have blank names (eight spaces). The .themida section has zero raw size and maximum virtual size, serving as a memory placeholder. The .boot section contains the entry point, a compact LZ77 bit-stream decompressor that unpacks an encrypted payload in-memory without disk writes. The import table exposes only three APIs (GetModuleHandleA, GetMessageTime, CreateSolidBrush) — the real API surface is resolved at runtime after decompression. The binary carries a cloned VS_VERSIONINFO block and XML assembly manifest impersonating TreeSize Disk Space Manager, plus six generic PNG icons. It is signed with a self-signed SHA-384 certificate bearing CN Logitech and a Sectigo timestamp counter-signature. The certificate validity window post-dates the PE compile timestamp by ~7 years.
Detection Signatures
- Capa: packed-file limitation warning (internal packer file limitation rule) ^[capa.txt]
- pefile:
Suspicious flags set for section 6. Both IMAGE_SCN_MEM_WRITE and IMAGE_SCN_MEM_EXECUTE are set.^[pefile.txt] - rabin2:
signed: true,lang: c,nx: false^[rabin2-info.txt]
References
- unattributed — umbrella entity for unattributed singletons
- themida-packed-boot-lz77 — technique page for this packing pattern
- fabricated-certificate-masquerade — concept page for self-signed cert masquerade
- version-info-masquerade — technique page for version-info cloning
- gcleaner — distribution pipeline entity
- MalwareBazaar artifact:
f664fff0-0a4b-4e22-8cfc-76c1626558b2 - OpenCTI labels:
dropped-by-gcleaner,exe,f,malware-bazaar,mix8.file,signed
Provenance
file.txt— file(1) outputexiftool.json— ExifTool PE metadatapefile.txt— pefile.py structural analysisstrings.txt— strings(1) outputrabin2-info.txt— radare2rabin2 -Iheader summarybinwalk.txt— binwalk embedded-artifact scancapa.txt— Mandiant capa capability detectiontriage.json— triage pipeline metadatametadata.json— artifact metadata- Radare2 analysis (level 3, 1283 functions) — entry point decompilation at
0x1404bc058 - Python + cryptography.x509 — certificate extraction from WIN_CERTIFICATE at offset
0x314600