typeanalysisfamilyunattributedconfidencelowcreated2026-08-07updated2026-08-07pecompilerpackerobfuscationanti-debugevasionunattributedmsvccpp
SHA-256: 0b839fc7c31163b315c74c53e3e86cb997397ba4ea756e839b4fd053fd947420

unattributed: 0b839fc7 — MSVC 14.0 custom-packer PE32+ with encrypted .9;t payload

Executive Summary

A 4.1 MB PE32+ x64 GUI executable compiled May 19 2026 with MSVC 14.0. The binary employs a custom section-reconstruction packer: the first seven PE sections (.text, .rdata, .data, .pdata, .gfids, .tls, _RDATA) are entirely empty on disk (SizeOfRawData=0, entropy 0.0) and will be rebuilt in memory at runtime by the stub residing in the high-entropy .9;t section. A minimal but functional IAT sits in .#)e, importing anti-debug, cryptographic RNG, filesystem, privilege-escalation, and certificate-manipulation APIs. No plaintext C2 indicators, no runtime strings, and no CAPE detonation (no Windows guest). Static-only inference.

What It Is

Field Value
SHA-256 0b839fc7c31163b315c74c53e3e86cb997397ba4ea756e839b4fd053fd947420
Filename new_agrm_19_may_timo.exe
Size 4,327,424 bytes
File type PE32+ executable (GUI) x86-64, 11 sections ^[file.txt]
Compiler MSVC 14.0 (Visual Studio 2015/2017) ^[exiftool.json:18]
Linker MajorLinkerVersion 0xE, MinorLinkerVersion 0x0 ^[pefile.txt:49]
Compiled Tue May 19 08:54:38 2026 UTC ^[pefile.txt:38]
Base address 0x140000000 ^[pefile.txt:56]
Entry point 0x1407CB826 (inside .9;t) ^[pefile.txt:54]
Signed No ^[rabin2-info.txt:27]
Stripped No ^[rabin2-info.txt:30]
PIC Yes ^[rabin2-info.txt:25]
NX Yes ^[rabin2-info.txt:21]
Canary Yes ^[rabin2-info.txt:6]

The filename abbreviation "agrm" strongly suggests a social-engineering lure targeting an "agreement" document, consistent with May 2026 compilation.

How It Works

Section Reconstruction Packer

The PE header declares 11 sections, but the first seven have SizeOfRawData=0 and PointerToRawData=0 in the on-disk image ^[pefile.txt:81-220]:

Section VirtualSize SizeOfRawData Entropy Notes
.text 0xFE4B6 0 0.000 Empty on disk
.rdata 0x805BC 0 0.000 Empty on disk
.data 0x5040 0 0.000 Empty on disk
.pdata 0xA11C 0 0.000 Empty on disk
.gfids 0xB4 0 0.000 Empty on disk
.tls 0x221 0 0.000 Empty on disk
_RDATA 0x1F4 0 0.000 Empty on disk
.bD[ 0x25E4BE 0 0.000 Empty on disk (name is junk)
.#)e 0x558 0x600 1.053 IAT / import thunks
.9;t 0x41FBD4 0x41FC00 7.949 Encrypted payload stub
.reloc 0xB4 0x200 1.934 Relocations

The entry point (0x1407CB826) falls inside .9;t, confirming the packer stub decrypts/decompresses the original sections into allocated memory, fixes up the IAT via LoadLibraryA/GetProcAddress, applies relocations, and transfers control to the reconstructed OEP. This is a classic in-memory PE reconstruction pattern.

The .9;t section shows near-maximum entropy (7.949/8.0) with no recoverable ASCII strings in the first 64 KB ^[strings.txt], confirming strong encryption rather than simple compression.

Import Surface

Despite the packer, the IAT in .#)e is not stripped to zero. Forty-six imports across fourteen DLLs are exposed, including several high-signal APIs:

Anti-analysis / Evasion

  • IsDebuggerPresent (api-ms-win-core-debug-l1-1-0) ^[pefile.txt:6903]
  • QueryPerformanceCounter (api-ms-win-core-profile-l1-1-0) ^[pefile.txt:407]
  • Sleep (api-ms-win-core-synch-l1-2-0) ^[pefile.txt]
  • GetTickCount — not directly imported, but QueryPerformanceCounter + Sleep strongly implies timing-based anti-emulation

Privilege escalation / Token manipulation

  • AdjustTokenPrivileges (api-ms-win-security-base-l1-1-0) ^[pefile.txt]

Certificate / Crypto

  • BCryptGenRandom (bcrypt.dll) ^[pefile.txt:5790]
  • SystemFunction036 a.k.a. RtlGenRandom (CRYPTBASE.dll) ^[strings.txt:253]
  • ProcessPrng (bcryptprimitives.dll) ^[strings.txt:330]
  • CertAddCertificateContextToStore (CRYPT32.dll) ^[pefile.txt]

Process / filesystem staging

  • CreateProcessW (api-ms-win-core-processthreads-l1-1-0) ^[pefile.txt:6508]
  • CopyFileExW (api-ms-win-core-file-l2-1-0) ^[pefile.txt:696]
  • CreateDirectoryW (api-ms-win-core-file-l1-1-0) ^[pefile.txt:6611]
  • GetTempPathW (api-ms-win-core-file-l1-2-0) ^[pefile.txt:6409]
  • CloseHandle (api-ms-win-core-handle-l1-1-0) ^[pefile.txt:6555]

System fingerprinting

  • GetComputerNameExW (api-ms-win-core-sysinfo-l1-1-0) ^[pefile.txt:7085]
  • GetUserNameW (ADVAPI32.dll) ^[pefile.txt:6896]
  • IsWow64Process2 (api-ms-win-core-wow64-l1-1-1) ^[pefile.txt]
  • GetPhysicallyInstalledSystemMemory (api-ms-win-core-sysinfo-l1-2-1) ^[pefile.txt]

Network / IPC

  • WSACleanup (WS2_32.dll) — winsock initialization implies subsequent socket usage ^[pefile.txt]
  • NtCancelIoFileEx (ntdll.dll) — native async I/O cancellation ^[pefile.txt]

Other notable

  • AcceptSecurityContext (SspiCli.dll) — SSPI/Kerberos credential handling ^[pefile.txt]
  • SHGetKnownFolderPath (SHELL32.dll) — resolves AppData, Temp, Startup, etc. ^[pefile.txt]
  • SetupDiDestroyDeviceInfoList (SETUPAPI.dll) — device enumeration, potential VM detection ^[pefile.txt]
  • BuildCommDCBAndTimeoutsA (KERNEL32.dll) — obscure serial-port API; possibly CRT bloat or anti-analysis noise ^[pefile.txt]

Decompiled Behavior

Radare2 analysis (level 3) identifies 10,664 functions with entry point at 0x1407CB826 inside .9;t ^[rabin2-info.txt]. The decompiled entry stub is heavily obfuscated and does not resolve to readable C-like pseudocode; the initial bytes at the EP offset are high-entropy encrypted data rather than clear instructions ^[r2:entry0]. This is consistent with a packer that decrypts its own stub before executing.

No meaningful xrefs or call-graph edges can be extracted from the encrypted blob without first emulating or dumping the decrypted payload.

C2 Infrastructure

No static C2 indicators recovered. No URLs, domains, IP addresses, mutex names, named pipes, or hardcoded registry keys appear in the strings output ^[strings.txt]. The WSACleanup import confirms network capability but the actual C2 endpoints are likely decrypted at runtime from the .9;t payload. Dynamic execution or memory dumping would be required to recover them.

Interesting Tidbits

  • Triple RNG surface: The binary imports three distinct Windows RNG APIs — BCryptGenRandom (CNG), SystemFunction036 (RtlGenRandom), and ProcessPrng (bcryptprimitives). This is unusual and may indicate cryptographic key generation, payload decryption, or polymorphic stub mutation. ^[pefile.txt], ^[strings.txt:253], ^[strings.txt:330]
  • SSPI + certificate APIs together: AcceptSecurityContext plus CertAddCertificateContextToStore suggests the inner payload may manipulate the certificate store or abuse SSPI for credential relay — a pattern seen in some post-exploitation toolkits. ^[pefile.txt]
  • Recent compilation: May 19 2026 is within 80 days of analysis (August 7 2026). Fresh build, not a historical sample. ^[exiftool.json:15]
  • No version info resource: No VS_VERSIONINFO, no company name, no product description. Clean social-engineering shell. ^[pefile.txt:310-311]
  • No CAPE detonation: Skipped because no Windows guest exists in the lab. All behavior here is static inference. ^[dynamic-analysis.md]

How To Mess With It (Homelab Replication)

Replicating the packer would require:

  1. Build a benign PE32+ x64 GUI app in MSVC 14.0 (VS 2015/2017).
  2. Strip its sections, place encrypted payload in a high-entropy last section.
  3. Write a small PE loader stub that VirtualAllocs memory, decrypts sections, resolves imports via LoadLibraryA/GetProcAddress, applies relocations, and jumps to OEP.
  4. Set the PE entry point to the stub.

Verification: The resulting binary should show SizeOfRawData=0 for all non-payload sections and entropy >7.8 in the payload section. Compare with this sample's rabin2 -S output.

Deployable Signatures

YARA Rule

rule Unclassified_PE32plus_CustomPacker_2026
{
    meta:
        description = "MSVC 14.0 PE32+ with empty on-disk sections and encrypted .9;t payload"
        author = "pp-hermes"
        date = "2026-08-07"
        sha256 = "0b839fc7c31163b315c74c53e3e86cb997397ba4ea756e839b4fd053fd947420"
        confidence = "medium"

    strings:
        // MZ + PE signature at expected offsets
        $mz = { 4D 5A }
        $pe = { 50 45 00 00 }

        // Triple RNG imports
        $bcrypt = "BCryptGenRandom" ascii wide
        $rtlgen = "SystemFunction036" ascii wide
        $prng = "ProcessPrng" ascii wide

        // High-signal APIs
        $isdebug = "IsDebuggerPresent" ascii wide
        $qpc = "QueryPerformanceCounter" ascii wide
        $createproc = "CreateProcessW" ascii wide
        $adjusttok = "AdjustTokenPrivileges" ascii wide
        $certadd = "CertAddCertificateContextToStore" ascii wide
        $sspi = "AcceptSecurityContext" ascii wide

    condition:
        $mz at 0 and
        $pe at 120 and
        filesize > 4MB and filesize < 5MB and
        // At least two of the three RNG APIs
        (2 of ($bcrypt, $rtlgen, $prng)) and
        // Anti-debug and high-privilege indicators
        $isdebug and
        ($adjusttok or $certadd or $sspi) and
        // High entropy in last section (heuristic; requires section parsing)
        // Static condition: PE32+ with 11 sections and empty SizeOfRawData on first several
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550
}

Sigma Rule (process creation — speculative, static-only)

title: Suspicious Process Spawn After Encrypted PE Execution
status: experimental
description: Detects child process creation by a PE32+ with minimal on-disk sections and high entropy payload. Static-only inference.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        ParentImage|endswith:
            - '\\new_agrm_19_may_timo.exe'
            - '\\new_agrm_*.exe'
        CommandLine|contains:
            - 'powershell'
            - 'cmd.exe'
            - 'certutil'
            - 'rundll32'
    condition: selection
falsepositives:
    - Unknown
level: medium

IOC List

Type Indicator Note
SHA-256 0b839fc7c31163b315c74c53e3e86cb997397ba4ea756e839b4fd053fd947420 Primary sample
Filename new_agrm_19_may_timo.exe Social-engineering lure
Compile time 2026-05-19 08:54:38 UTC Very recent
Size 4,327,424 bytes Fingerprintable
Toolchain MSVC 14.0 Visual Studio 2015/2017
Section names .9;t, .#)e, .bD[ Non-standard, junk names
Section entropy .9;t ≈ 7.95 Encrypted payload
Anti-debug IsDebuggerPresent Static import
RNG imports BCryptGenRandom + SystemFunction036 + ProcessPrng Triple surface

Behavioral Fingerprint

This binary is a custom-packed PE32+ x64 GUI executable. At rest, its first seven PE sections are empty on disk (SizeOfRawData=0, entropy 0.0) while a ~4.3 MB encrypted payload resides in the .9;t section (entropy 7.95). The entry point falls inside .9;t, indicating an in-memory section-reconstruction packer. The minimal but exposed IAT imports anti-debug (IsDebuggerPresent), timing (QueryPerformanceCounter), three distinct cryptographic RNGs (BCryptGenRandom, SystemFunction036, ProcessPrng), privilege escalation (AdjustTokenPrivileges), certificate store manipulation (CertAddCertificateContextToStore), SSPI credential handling (AcceptSecurityContext), and Winsocket cleanup (WSACleanup). On execution, the stub is expected to decrypt its payload, reconstruct the original PE sections in RWX or RW memory, resolve remaining APIs dynamically, and transfer control to the reconstructed OEP. No static C2 indicators are present; network targets are likely embedded in the encrypted payload.

Detection Signatures

Capability ATT&CK Technique Evidence
Debugger Detection T1622 IsDebuggerPresent imported statically ^[pefile.txt]
Timing-based anti-emulation T1497 QueryPerformanceCounter + Sleep in IAT ^[pefile.txt]
Obfuscated Files / Information T1027 All original sections empty on disk; payload encrypted in .9;t ^[pefile.txt]
Software Packing T1027.002 Custom in-memory section reconstruction ^[pefile.txt]
Process Injection (inferred) T1055 CreateProcessW + packer stub behavior ^[pefile.txt]
Native API T1106 NtCancelIoFileEx in IAT ^[pefile.txt]
System Information Discovery T1082 GetComputerNameExW, GetUserNameW, IsWow64Process2, GetPhysicallyInstalledSystemMemory ^[pefile.txt]
File and Directory Discovery T1083 GetTempPathW, CreateDirectoryW, CopyFileExW ^[pefile.txt]
Token Impersonation/Theft T1134.001 AdjustTokenPrivileges ^[pefile.txt]
Install Root Certificate T1553.004 CertAddCertificateContextToStore ^[pefile.txt]
Use Alternate Authentication Material T1550.002 AcceptSecurityContext (SSPI) ^[pefile.txt]

References

  • Artifact ID: 3b11bb73-18a4-4cc6-9d3b-4f6834159349
  • OpenCTI labels: exe, malware-bazaar
  • Triage: new_agrm_19_may_timo.exe, tier deep, no family attribution

Provenance

Static analysis conducted 2026-08-07 on pp-hermes. Tools: file v5.45, exiftool v12.76, pefile (Python), rabin2 (radare2 5.9.8), strings (GNU binutils), xxd, grep. Capa v9 ran but failed due to missing signatures directory. FLOSS failed with CLI argument error. CAPE skipped (no Windows guest). No dynamic execution performed; all TTPs are inferred from static artifacts.