typeanalysisfamily54e64econfidencemediumcreated2026-08-26updated2026-08-26
SHA-256: 018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a

018ef44b — 54e64e Morph 12

Build / RE

Toolchain

  • Go 1.25.4, CGO_ENABLED=0, trimpath=true, GOOS=windows, GOARCH=amd64 ^[strings.txt:1510]
  • Module path RAwSPJDqREzkxCz (randomized) ^[strings.txt:1512]
  • GUI subsystem, PE32+ x86-64 ^[file.txt]

Packing / Obfuscation

  • No packer. Eight standard sections (.text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab). No strip. ^[pefile.txt]
  • Function name randomization: 55 main.* functions with 10–20 char garbage names (e.g. main.bjlkfhfvo, main.xdxcgzmbebtz) ^[r2:main.* list]
  • Overlay: Security directory certificate only; no trailing data. Certificate ends at exact EOF. ^[binwalk.txt] ^[pefile.txt: certificate directory]

Signing

  • Self-signed Authenticode, CN=xxx.com, issuer E7, 4096-bit RSA, 3-month validity. ^[binwalk.txt] ^[pefile.txt]
  • Chain fails validation (untrusted root).

Anti-Analysis

  • Minimal IAT: Only kernel32.dll imported statically. ^[pefile.txt]
  • Runtime API resolution: All other APIs invoked via Go syscall.SyscallN / syscall.Syscall — no net/http or crypto/tls symbols recovered. ^[r2:main.vwhubhlxgr] ^[r2:main.lhtbglfiqdcosne]
  • PRNG obfuscation: math/rand seeded with time.Now().UnixNano() and fixed constants; generates parameters fed to the decryptor. ^[r2:main.xdxcgzmbebtz]

Notable Functions

  • main.chdldv — PE header parser: validates MZ/PE signatures, walks section table, extracts RVA/size. ^[r2:0x14008bf20]
  • main.sensmww — Custom multi-stage decryptor: modular arithmetic (0x35, 0x61), XOR, byte shuffle on a buffer. ^[r2:0x14008bc20]
  • main.vwhubhlxgr — VirtualAlloc wrapper via syscall.SyscallN with MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE (0x40). ^[r2:0x14008c2a0]
  • main.lhtbglfiqdcosne — Runtime DLL loader + export resolver: calls syscall.LoadLibrary then syscall.GetProcAddress via syscall.Syscall, stores resolved addresses in a table. ^[r2:0x14008b780]
  • main.osmiofar — Raw syscall dispatcher (syscall.SyscallN). ^[r2:0x14008be60]
  • main.xdxcgzmbebtz — Orchestrator: seeds PRNG, allocates buffers, calls decryptor → PE parser → VirtualAlloc → memmove, then invokes main.bjlkfhfvo (execution transfer) and main.lhtbglfiqdcosne (API resolution). ^[r2:0x14008cf40]

Deploy / ATT&CK

Dynamic analysis skipped — no Windows CAPE guest available. All TTPs inferred from static evidence.

Technique ID Evidence
Reflective Code Loading T1620 main.chdldv parses PE headers; main.vwhubhlxgr allocates RWX memory; reconstructed flow maps decrypted payload into memory and resolves imports. ^[r2:main.xdxcgzmbebtz]
Command and Scripting Interpreter T1059 Go runtime process spawning; loader architecture implies execution of embedded/decoded payload.
Native API T1106 syscall.SyscallN / syscall.Syscall direct Windows API invocation. ^[r2:main.osmiofar]
Masquerading T1036.005 Self-signed cert CN=xxx.com with no legitimate version info.
Deobfuscate/Decode Files or Information T1027 main.sensmww custom decryptor with PRNG-derived parameters. ^[r2:main.xdxcgzmbebtz]
Process Injection T1055 Reflective PE loader pattern implies injection into self or another process.
Virtualization/Sandbox Evasion T1497.001 PRNG seeding with time.Now().UnixNano() may act as time-based gate.

Attribution / Family Context

This is the twelfth confirmed build morph under the 54e64e OpenCTI umbrella. Unlike prior Go morphs (Morphs 3, 6, 9) which were infostealers with browser/crypto theft capabilities, this sample is a pure loader/injector with no credential-harvesting surface. The PE parser, RWX allocator, and runtime DLL resolver point to reflective loading of a second-stage payload. The PRNG-driven parameter generation is consistent with the 54e64e Go builder toolchain but applied here to payload decoding rather than C2 URL construction. No hardcoded network IOCs recovered.

IOCs

  • SHA-256: 018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a
  • Certificate CN: xxx.com
  • Certificate issuer: E7
  • Go module: RAwSPJDqREzkxCz