SHA-256:
018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a018ef44b — 54e64e Morph 12
Build / RE
Toolchain
- Go 1.25.4,
CGO_ENABLED=0,trimpath=true,GOOS=windows,GOARCH=amd64^[strings.txt:1510] - Module path
RAwSPJDqREzkxCz(randomized) ^[strings.txt:1512] - GUI subsystem, PE32+ x86-64 ^[file.txt]
Packing / Obfuscation
- No packer. Eight standard sections (
.text,.rdata,.data,.pdata,.xdata,.idata,.reloc,.symtab). No strip. ^[pefile.txt] - Function name randomization: 55
main.*functions with 10–20 char garbage names (e.g.main.bjlkfhfvo,main.xdxcgzmbebtz) ^[r2:main.* list] - Overlay: Security directory certificate only; no trailing data. Certificate ends at exact EOF. ^[binwalk.txt] ^[pefile.txt: certificate directory]
Signing
- Self-signed Authenticode, CN=
xxx.com, issuerE7, 4096-bit RSA, 3-month validity. ^[binwalk.txt] ^[pefile.txt] - Chain fails validation (untrusted root).
Anti-Analysis
- Minimal IAT: Only
kernel32.dllimported statically. ^[pefile.txt] - Runtime API resolution: All other APIs invoked via Go
syscall.SyscallN/syscall.Syscall— nonet/httporcrypto/tlssymbols recovered. ^[r2:main.vwhubhlxgr] ^[r2:main.lhtbglfiqdcosne] - PRNG obfuscation:
math/randseeded withtime.Now().UnixNano()and fixed constants; generates parameters fed to the decryptor. ^[r2:main.xdxcgzmbebtz]
Notable Functions
main.chdldv— PE header parser: validates MZ/PE signatures, walks section table, extracts RVA/size. ^[r2:0x14008bf20]main.sensmww— Custom multi-stage decryptor: modular arithmetic (0x35, 0x61), XOR, byte shuffle on a buffer. ^[r2:0x14008bc20]main.vwhubhlxgr—VirtualAllocwrapper viasyscall.SyscallNwithMEM_COMMIT|MEM_RESERVE,PAGE_EXECUTE_READWRITE(0x40). ^[r2:0x14008c2a0]main.lhtbglfiqdcosne— Runtime DLL loader + export resolver: callssyscall.LoadLibrarythensyscall.GetProcAddressviasyscall.Syscall, stores resolved addresses in a table. ^[r2:0x14008b780]main.osmiofar— Raw syscall dispatcher (syscall.SyscallN). ^[r2:0x14008be60]main.xdxcgzmbebtz— Orchestrator: seeds PRNG, allocates buffers, calls decryptor → PE parser →VirtualAlloc→memmove, then invokesmain.bjlkfhfvo(execution transfer) andmain.lhtbglfiqdcosne(API resolution). ^[r2:0x14008cf40]
Deploy / ATT&CK
Dynamic analysis skipped — no Windows CAPE guest available. All TTPs inferred from static evidence.
| Technique | ID | Evidence |
|---|---|---|
| Reflective Code Loading | T1620 | main.chdldv parses PE headers; main.vwhubhlxgr allocates RWX memory; reconstructed flow maps decrypted payload into memory and resolves imports. ^[r2:main.xdxcgzmbebtz] |
| Command and Scripting Interpreter | T1059 | Go runtime process spawning; loader architecture implies execution of embedded/decoded payload. |
| Native API | T1106 | syscall.SyscallN / syscall.Syscall direct Windows API invocation. ^[r2:main.osmiofar] |
| Masquerading | T1036.005 | Self-signed cert CN=xxx.com with no legitimate version info. |
| Deobfuscate/Decode Files or Information | T1027 | main.sensmww custom decryptor with PRNG-derived parameters. ^[r2:main.xdxcgzmbebtz] |
| Process Injection | T1055 | Reflective PE loader pattern implies injection into self or another process. |
| Virtualization/Sandbox Evasion | T1497.001 | PRNG seeding with time.Now().UnixNano() may act as time-based gate. |
Attribution / Family Context
This is the twelfth confirmed build morph under the 54e64e OpenCTI umbrella. Unlike prior Go morphs (Morphs 3, 6, 9) which were infostealers with browser/crypto theft capabilities, this sample is a pure loader/injector with no credential-harvesting surface. The PE parser, RWX allocator, and runtime DLL resolver point to reflective loading of a second-stage payload. The PRNG-driven parameter generation is consistent with the 54e64e Go builder toolchain but applied here to payload decoding rather than C2 URL construction. No hardcoded network IOCs recovered.
IOCs
- SHA-256:
018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a - Certificate CN:
xxx.com - Certificate issuer:
E7 - Go module:
RAwSPJDqREzkxCz