0b839fc7c31163b315c74c53e3e86cb997397ba4ea756e839b4fd053fd947420unattributed: 0b839fc7 — MSVC 14.0 custom-packer PE32+ with encrypted .9;t payload
Executive Summary
A 4.1 MB PE32+ x64 GUI executable compiled May 19 2026 with MSVC 14.0. The binary employs a custom section-reconstruction packer: the first seven PE sections (.text, .rdata, .data, .pdata, .gfids, .tls, _RDATA) are entirely empty on disk (SizeOfRawData=0, entropy 0.0) and will be rebuilt in memory at runtime by the stub residing in the high-entropy .9;t section. A minimal but functional IAT sits in .#)e, importing anti-debug, cryptographic RNG, filesystem, privilege-escalation, and certificate-manipulation APIs. No plaintext C2 indicators, no runtime strings, and no CAPE detonation (no Windows guest). Static-only inference.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 0b839fc7c31163b315c74c53e3e86cb997397ba4ea756e839b4fd053fd947420 |
| Filename | new_agrm_19_may_timo.exe |
| Size | 4,327,424 bytes |
| File type | PE32+ executable (GUI) x86-64, 11 sections ^[file.txt] |
| Compiler | MSVC 14.0 (Visual Studio 2015/2017) ^[exiftool.json:18] |
| Linker | MajorLinkerVersion 0xE, MinorLinkerVersion 0x0 ^[pefile.txt:49] |
| Compiled | Tue May 19 08:54:38 2026 UTC ^[pefile.txt:38] |
| Base address | 0x140000000 ^[pefile.txt:56] |
| Entry point | 0x1407CB826 (inside .9;t) ^[pefile.txt:54] |
| Signed | No ^[rabin2-info.txt:27] |
| Stripped | No ^[rabin2-info.txt:30] |
| PIC | Yes ^[rabin2-info.txt:25] |
| NX | Yes ^[rabin2-info.txt:21] |
| Canary | Yes ^[rabin2-info.txt:6] |
The filename abbreviation "agrm" strongly suggests a social-engineering lure targeting an "agreement" document, consistent with May 2026 compilation.
How It Works
Section Reconstruction Packer
The PE header declares 11 sections, but the first seven have SizeOfRawData=0 and PointerToRawData=0 in the on-disk image ^[pefile.txt:81-220]:
| Section | VirtualSize | SizeOfRawData | Entropy | Notes |
|---|---|---|---|---|
| .text | 0xFE4B6 | 0 | 0.000 | Empty on disk |
| .rdata | 0x805BC | 0 | 0.000 | Empty on disk |
| .data | 0x5040 | 0 | 0.000 | Empty on disk |
| .pdata | 0xA11C | 0 | 0.000 | Empty on disk |
| .gfids | 0xB4 | 0 | 0.000 | Empty on disk |
| .tls | 0x221 | 0 | 0.000 | Empty on disk |
| _RDATA | 0x1F4 | 0 | 0.000 | Empty on disk |
| .bD[ | 0x25E4BE | 0 | 0.000 | Empty on disk (name is junk) |
| .#)e | 0x558 | 0x600 | 1.053 | IAT / import thunks |
| .9;t | 0x41FBD4 | 0x41FC00 | 7.949 | Encrypted payload stub |
| .reloc | 0xB4 | 0x200 | 1.934 | Relocations |
The entry point (0x1407CB826) falls inside .9;t, confirming the packer stub decrypts/decompresses the original sections into allocated memory, fixes up the IAT via LoadLibraryA/GetProcAddress, applies relocations, and transfers control to the reconstructed OEP. This is a classic in-memory PE reconstruction pattern.
The .9;t section shows near-maximum entropy (7.949/8.0) with no recoverable ASCII strings in the first 64 KB ^[strings.txt], confirming strong encryption rather than simple compression.
Import Surface
Despite the packer, the IAT in .#)e is not stripped to zero. Forty-six imports across fourteen DLLs are exposed, including several high-signal APIs:
Anti-analysis / Evasion
IsDebuggerPresent(api-ms-win-core-debug-l1-1-0) ^[pefile.txt:6903]QueryPerformanceCounter(api-ms-win-core-profile-l1-1-0) ^[pefile.txt:407]Sleep(api-ms-win-core-synch-l1-2-0) ^[pefile.txt]GetTickCount— not directly imported, butQueryPerformanceCounter+Sleepstrongly implies timing-based anti-emulation
Privilege escalation / Token manipulation
AdjustTokenPrivileges(api-ms-win-security-base-l1-1-0) ^[pefile.txt]
Certificate / Crypto
BCryptGenRandom(bcrypt.dll) ^[pefile.txt:5790]SystemFunction036a.k.a. RtlGenRandom (CRYPTBASE.dll) ^[strings.txt:253]ProcessPrng(bcryptprimitives.dll) ^[strings.txt:330]CertAddCertificateContextToStore(CRYPT32.dll) ^[pefile.txt]
Process / filesystem staging
CreateProcessW(api-ms-win-core-processthreads-l1-1-0) ^[pefile.txt:6508]CopyFileExW(api-ms-win-core-file-l2-1-0) ^[pefile.txt:696]CreateDirectoryW(api-ms-win-core-file-l1-1-0) ^[pefile.txt:6611]GetTempPathW(api-ms-win-core-file-l1-2-0) ^[pefile.txt:6409]CloseHandle(api-ms-win-core-handle-l1-1-0) ^[pefile.txt:6555]
System fingerprinting
GetComputerNameExW(api-ms-win-core-sysinfo-l1-1-0) ^[pefile.txt:7085]GetUserNameW(ADVAPI32.dll) ^[pefile.txt:6896]IsWow64Process2(api-ms-win-core-wow64-l1-1-1) ^[pefile.txt]GetPhysicallyInstalledSystemMemory(api-ms-win-core-sysinfo-l1-2-1) ^[pefile.txt]
Network / IPC
WSACleanup(WS2_32.dll) — winsock initialization implies subsequent socket usage ^[pefile.txt]NtCancelIoFileEx(ntdll.dll) — native async I/O cancellation ^[pefile.txt]
Other notable
AcceptSecurityContext(SspiCli.dll) — SSPI/Kerberos credential handling ^[pefile.txt]SHGetKnownFolderPath(SHELL32.dll) — resolves AppData, Temp, Startup, etc. ^[pefile.txt]SetupDiDestroyDeviceInfoList(SETUPAPI.dll) — device enumeration, potential VM detection ^[pefile.txt]BuildCommDCBAndTimeoutsA(KERNEL32.dll) — obscure serial-port API; possibly CRT bloat or anti-analysis noise ^[pefile.txt]
Decompiled Behavior
Radare2 analysis (level 3) identifies 10,664 functions with entry point at 0x1407CB826 inside .9;t ^[rabin2-info.txt]. The decompiled entry stub is heavily obfuscated and does not resolve to readable C-like pseudocode; the initial bytes at the EP offset are high-entropy encrypted data rather than clear instructions ^[r2:entry0]. This is consistent with a packer that decrypts its own stub before executing.
No meaningful xrefs or call-graph edges can be extracted from the encrypted blob without first emulating or dumping the decrypted payload.
C2 Infrastructure
No static C2 indicators recovered. No URLs, domains, IP addresses, mutex names, named pipes, or hardcoded registry keys appear in the strings output ^[strings.txt]. The WSACleanup import confirms network capability but the actual C2 endpoints are likely decrypted at runtime from the .9;t payload. Dynamic execution or memory dumping would be required to recover them.
Interesting Tidbits
- Triple RNG surface: The binary imports three distinct Windows RNG APIs —
BCryptGenRandom(CNG),SystemFunction036(RtlGenRandom), andProcessPrng(bcryptprimitives). This is unusual and may indicate cryptographic key generation, payload decryption, or polymorphic stub mutation. ^[pefile.txt], ^[strings.txt:253], ^[strings.txt:330] - SSPI + certificate APIs together:
AcceptSecurityContextplusCertAddCertificateContextToStoresuggests the inner payload may manipulate the certificate store or abuse SSPI for credential relay — a pattern seen in some post-exploitation toolkits. ^[pefile.txt] - Recent compilation: May 19 2026 is within 80 days of analysis (August 7 2026). Fresh build, not a historical sample. ^[exiftool.json:15]
- No version info resource: No VS_VERSIONINFO, no company name, no product description. Clean social-engineering shell. ^[pefile.txt:310-311]
- No CAPE detonation: Skipped because no Windows guest exists in the lab. All behavior here is static inference. ^[dynamic-analysis.md]
How To Mess With It (Homelab Replication)
Replicating the packer would require:
- Build a benign PE32+ x64 GUI app in MSVC 14.0 (VS 2015/2017).
- Strip its sections, place encrypted payload in a high-entropy last section.
- Write a small PE loader stub that
VirtualAllocs memory, decrypts sections, resolves imports viaLoadLibraryA/GetProcAddress, applies relocations, and jumps to OEP. - Set the PE entry point to the stub.
Verification: The resulting binary should show SizeOfRawData=0 for all non-payload sections and entropy >7.8 in the payload section. Compare with this sample's rabin2 -S output.
Deployable Signatures
YARA Rule
rule Unclassified_PE32plus_CustomPacker_2026
{
meta:
description = "MSVC 14.0 PE32+ with empty on-disk sections and encrypted .9;t payload"
author = "pp-hermes"
date = "2026-08-07"
sha256 = "0b839fc7c31163b315c74c53e3e86cb997397ba4ea756e839b4fd053fd947420"
confidence = "medium"
strings:
// MZ + PE signature at expected offsets
$mz = { 4D 5A }
$pe = { 50 45 00 00 }
// Triple RNG imports
$bcrypt = "BCryptGenRandom" ascii wide
$rtlgen = "SystemFunction036" ascii wide
$prng = "ProcessPrng" ascii wide
// High-signal APIs
$isdebug = "IsDebuggerPresent" ascii wide
$qpc = "QueryPerformanceCounter" ascii wide
$createproc = "CreateProcessW" ascii wide
$adjusttok = "AdjustTokenPrivileges" ascii wide
$certadd = "CertAddCertificateContextToStore" ascii wide
$sspi = "AcceptSecurityContext" ascii wide
condition:
$mz at 0 and
$pe at 120 and
filesize > 4MB and filesize < 5MB and
// At least two of the three RNG APIs
(2 of ($bcrypt, $rtlgen, $prng)) and
// Anti-debug and high-privilege indicators
$isdebug and
($adjusttok or $certadd or $sspi) and
// High entropy in last section (heuristic; requires section parsing)
// Static condition: PE32+ with 11 sections and empty SizeOfRawData on first several
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550
}
Sigma Rule (process creation — speculative, static-only)
title: Suspicious Process Spawn After Encrypted PE Execution
status: experimental
description: Detects child process creation by a PE32+ with minimal on-disk sections and high entropy payload. Static-only inference.
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith:
- '\\new_agrm_19_may_timo.exe'
- '\\new_agrm_*.exe'
CommandLine|contains:
- 'powershell'
- 'cmd.exe'
- 'certutil'
- 'rundll32'
condition: selection
falsepositives:
- Unknown
level: medium
IOC List
| Type | Indicator | Note |
|---|---|---|
| SHA-256 | 0b839fc7c31163b315c74c53e3e86cb997397ba4ea756e839b4fd053fd947420 |
Primary sample |
| Filename | new_agrm_19_may_timo.exe |
Social-engineering lure |
| Compile time | 2026-05-19 08:54:38 UTC |
Very recent |
| Size | 4,327,424 bytes |
Fingerprintable |
| Toolchain | MSVC 14.0 | Visual Studio 2015/2017 |
| Section names | .9;t, .#)e, .bD[ |
Non-standard, junk names |
| Section entropy | .9;t ≈ 7.95 |
Encrypted payload |
| Anti-debug | IsDebuggerPresent |
Static import |
| RNG imports | BCryptGenRandom + SystemFunction036 + ProcessPrng | Triple surface |
Behavioral Fingerprint
This binary is a custom-packed PE32+ x64 GUI executable. At rest, its first seven PE sections are empty on disk (SizeOfRawData=0, entropy 0.0) while a ~4.3 MB encrypted payload resides in the .9;t section (entropy 7.95). The entry point falls inside .9;t, indicating an in-memory section-reconstruction packer. The minimal but exposed IAT imports anti-debug (IsDebuggerPresent), timing (QueryPerformanceCounter), three distinct cryptographic RNGs (BCryptGenRandom, SystemFunction036, ProcessPrng), privilege escalation (AdjustTokenPrivileges), certificate store manipulation (CertAddCertificateContextToStore), SSPI credential handling (AcceptSecurityContext), and Winsocket cleanup (WSACleanup). On execution, the stub is expected to decrypt its payload, reconstruct the original PE sections in RWX or RW memory, resolve remaining APIs dynamically, and transfer control to the reconstructed OEP. No static C2 indicators are present; network targets are likely embedded in the encrypted payload.
Detection Signatures
| Capability | ATT&CK Technique | Evidence |
|---|---|---|
| Debugger Detection | T1622 | IsDebuggerPresent imported statically ^[pefile.txt] |
| Timing-based anti-emulation | T1497 | QueryPerformanceCounter + Sleep in IAT ^[pefile.txt] |
| Obfuscated Files / Information | T1027 | All original sections empty on disk; payload encrypted in .9;t ^[pefile.txt] |
| Software Packing | T1027.002 | Custom in-memory section reconstruction ^[pefile.txt] |
| Process Injection (inferred) | T1055 | CreateProcessW + packer stub behavior ^[pefile.txt] |
| Native API | T1106 | NtCancelIoFileEx in IAT ^[pefile.txt] |
| System Information Discovery | T1082 | GetComputerNameExW, GetUserNameW, IsWow64Process2, GetPhysicallyInstalledSystemMemory ^[pefile.txt] |
| File and Directory Discovery | T1083 | GetTempPathW, CreateDirectoryW, CopyFileExW ^[pefile.txt] |
| Token Impersonation/Theft | T1134.001 | AdjustTokenPrivileges ^[pefile.txt] |
| Install Root Certificate | T1553.004 | CertAddCertificateContextToStore ^[pefile.txt] |
| Use Alternate Authentication Material | T1550.002 | AcceptSecurityContext (SSPI) ^[pefile.txt] |
References
- Artifact ID:
3b11bb73-18a4-4cc6-9d3b-4f6834159349 - OpenCTI labels:
exe,malware-bazaar - Triage:
new_agrm_19_may_timo.exe, tierdeep, no family attribution
Provenance
Static analysis conducted 2026-08-07 on pp-hermes. Tools: file v5.45, exiftool v12.76, pefile (Python), rabin2 (radare2 5.9.8), strings (GNU binutils), xxd, grep. Capa v9 ran but failed due to missing signatures directory. FLOSS failed with CLI argument error. CAPE skipped (no Windows guest). No dynamic execution performed; all TTPs are inferred from static artifacts.