typeanalysisfamilyunclassified-dotnet-bitmap-stego-loaderconfidencemediumcreated2026-08-19updated2026-08-19dotnetobfuscationloaderbitmap-steganographyunclassifiedmasquerade
SHA-256: 0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb

unclassified-dotnet-bitmap-stego-loader: 0becdb662b66 — "FlashQuiz" vessel-document masquerade with 180×180 BMP + 650×698 PNG carriers

Executive Summary

.NET Framework 4.5 PE32 GUI executable masquerading as a "Flashcard Quiz" Windows Forms application. Distributed under maritime shipping-document filename MV_Lila_Houston_Vessel_Information_Particulars.exe. Contains two embedded image carriers (BMP 180×180×32 and PNG 650×698 RGBA) and an ExtractPixelBytes method consistent with the bitmap-steganography payload-delivery pattern. No network APIs, no persistence, no anti-analysis — threat logic is payload-dependent and not recoverable statically. Eleventh confirmed sibling of the unclassified-dotnet-bitmap-stego-loader cluster.

What It Is

Field Value
SHA-256 0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb
Size 1,099,264 bytes (1.05 MB)
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Build .NET Framework 4.5, compiled Fri May 29 03:02:57 2026 UTC ^[pefile.txt:34]
Internal name wBjo.exe ^[exiftool.json:40]
Product name FlashQuiz ^[exiftool.json:44]
Source filename MV_Lila_Houston_Vessel_Information_Particulars.exe ^[metadata.json:5]
Packing / obfuscation None observed ^[pefile.txt]
Authenticode Unsigned ^[rabin2-info.txt:27]
Import table Only mscoree.dll!_CorExeMain ^[pefile.txt:255]

How It Works

This sample follows the established bitmap-stego-loader template observed across ten prior siblings. The outer binary is a fully functional .NET Windows Forms application (Uzbek-language quiz GUI with FormViktorina, FormNatija, FormKategoriya forms) that serves as a carrier for an encrypted payload hidden in embedded image resources ^[strings.txt:35].

At runtime, the loader likely:

  1. Extracts raw pixel bytes from embedded images via ExtractPixelBytes ^[strings.txt:535]
  2. Reconstructs an encrypted buffer from pixel data
  3. Decrypts via symmetric cipher (no cipher strings recovered in this sample; siblings use RijndaelManaged or AesManaged)
  4. Reflectively loads the decrypted assembly via Activator.CreateInstance ^[strings.txt:515] or Assembly.Load

No network APIs (System.Net.Http, WebClient, TcpClient) are present in strings, suggesting the payload is fully self-contained within the images. No persistence mechanisms or anti-analysis checks observed.

Decompiled Behavior

Static CIL analysis via radare2 shows 514 functions with standard .NET WinForms/ADO.NET DataSet patterns. Notable method names:

  • ExtractPixelBytes — pixel extraction for steganographic payload reconstruction ^[strings.txt:535]
  • NatijalarniYuklash — "load results" in Uzbek; likely UI method or payload staging hook ^[strings.txt:7]
  • SavolniKorsatish — "show question" in Uzbek ^[strings.txt:297]
  • KeyingiSavolgaOtish — "go to next question" ^[strings.txt:294]

The GetPixel and Bitmap references confirm System.Drawing usage for image manipulation ^[strings.txt:365] ^[strings.txt:455].

C2 Infrastructure

None recoverable statically. No IP addresses, domains, URLs, mutexes, or named pipes in strings. C2 is either inside the encrypted image payload or the sample is a stage-1 self-contained dropper.

Interesting Tidbits

  • Uzbek-language UI — forms, labels, and DataSet columns use Uzbek terms (Savollar=questions, Javoblar=answers, Kategoriyalar=categories, Natijalar=results, TogriJavob=correct answer). This is consistent with the FormViktorina ("Quiz Form") educational-app masquerade ^[strings.txt:36].
  • Two image carriers of different formats — one BMP (180×180×32) and one large PNG (650×698 RGBA). The PNG is significantly larger than typical 76×76×24 BMP carriers in prior siblings, suggesting either higher-resolution payload encoding or a different steganographic scheme ^[binwalk.txt].
  • Shared builder template — ExtractPixelBytes method name and FormViktorina / FormNatija / FormKategoriya form names are byte-for-byte identical across at least three other corpus samples (0cfbc10a, 1d3e20ae, 27ce11b6), confirming a common builder or source-code template. OpenCTI mislabels these siblings as spamita and agenttesla respectively, demonstrating that outer-loader attribution does not imply inner-payload attribution.
  • VS_VERSIONINFO masquerade — "Flashcard Quiz Windows Forms Application" with empty CompanyName, generic Copyright © 2026. Consistent with the cluster's pattern of plausible but unverifiable version info ^[exiftool.json].

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2019+, .NET Framework 4.5, C# WinForms

  1. Create a standard WinForms app with FormViktorina, FormNatija, FormKategoriya
  2. Add System.Drawing.Bitmap resources (BMP/PNG) to .rsrc
  3. Implement ExtractPixelBytes(Bitmap bmp) using LockBits to read raw ARGB
  4. Concatenate pixel bytes into a MemoryStream
  5. Encrypt with RijndaelManaged + hardcoded key
  6. Decrypt at runtime and Assembly.Load
  7. Verification: Run capa on the reproducer — expect load-code/dotnet, access .NET resource, and generate random numbers in .NET hits matching this sample's capa.txt

Deployable Signatures

YARA rule

rule dotnet_bitmap_stego_loader_flashquiz {
    meta:
        description = ".NET bitmap stego loader with FlashQuiz masquerade and ExtractPixelBytes"
        author = "PacketPursuit"
        date = "2026-08-19"
        sha256 = "0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb"
    strings:
        $a = "ExtractPixelBytes" ascii wide
        $b = "FormViktorina" ascii wide
        $c = "FormNatija" ascii wide
        $d = "FlashQuiz" ascii wide
        $e = "System.Drawing.Bitmap" ascii wide
        $f = "SavollarDataset" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        4 of ($a,$b,$c,$d,$e,$f)
}

Sigma rule

title: .NET Bitmap Stego Loader Execution
logsource:
    product: windows
    category: process_creation
detection:
    selection_filename:
        CommandLine|contains:
            - 'MV_Lila_Houston_Vessel_Information_Particulars'
            - 'wBjo.exe'
    selection_hash:
        Hashes|contains:
            - '0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb'
    condition: selection_filename or selection_hash
falsepositives:
    - Unknown
level: high

IOC list

Indicator Value Type
SHA-256 0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb Hash
Filename MV_Lila_Houston_Vessel_Information_Particulars.exe Filename
Internal name wBjo.exe PE metadata
Product name FlashQuiz PE metadata
Build timestamp 2026-05-29 03:02:57 UTC Timestamp

Behavioral fingerprint

This binary is a .NET Framework 4.5 WinForms GUI executable with Uzbek-language quiz UI masquerade. It embeds a BMP (180×180×32) and PNG (650×698 RGBA) image in its .text section. At runtime it extracts pixel bytes from these images via ExtractPixelBytes, reconstructs an encrypted payload, and reflectively loads it. No network IAT, no persistence, no anti-analysis. The inner payload family is indeterminate from static analysis.

Detection Signatures

  • capa: compiled to the .NET platform, load .NET assembly, access .NET resource, generate random numbers in .NET, reference analysis tools strings (false positive — debug attributes trigger T1620/T1059/T1083/B0013.001), delete file, check if file exists, manipulate console buffer ^[capa.txt]
  • ATT&CK: T1620 (Reflective Code Loading — inferred from Activator.CreateInstance and Assembly.Load pattern), T1083 (File and Directory Discovery — false positive from debug-build capa noise)

References

Provenance

  • file.txt, pefile.txt, strings.txt, exiftool.json, binwalk.txt, capa.txt, rabin2-info.txt from triage pipeline
  • radare2 v5.9.4 CIL analysis (514 functions, aa + afva)
  • Python pefile analysis for resource enumeration and COM descriptor inspection
  • Manual string inspection and cross-sample correlation against 0cfbc10a, 1d3e20ae, 27ce11b6
  • capa v9.1.2 static analysis