0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacbunclassified-dotnet-bitmap-stego-loader: 0becdb662b66 — "FlashQuiz" vessel-document masquerade with 180×180 BMP + 650×698 PNG carriers
Executive Summary
.NET Framework 4.5 PE32 GUI executable masquerading as a "Flashcard Quiz" Windows Forms application. Distributed under maritime shipping-document filename MV_Lila_Houston_Vessel_Information_Particulars.exe. Contains two embedded image carriers (BMP 180×180×32 and PNG 650×698 RGBA) and an ExtractPixelBytes method consistent with the bitmap-steganography payload-delivery pattern. No network APIs, no persistence, no anti-analysis — threat logic is payload-dependent and not recoverable statically. Eleventh confirmed sibling of the unclassified-dotnet-bitmap-stego-loader cluster.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb |
| Size | 1,099,264 bytes (1.05 MB) |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Build | .NET Framework 4.5, compiled Fri May 29 03:02:57 2026 UTC ^[pefile.txt:34] |
| Internal name | wBjo.exe ^[exiftool.json:40] |
| Product name | FlashQuiz ^[exiftool.json:44] |
| Source filename | MV_Lila_Houston_Vessel_Information_Particulars.exe ^[metadata.json:5] |
| Packing / obfuscation | None observed ^[pefile.txt] |
| Authenticode | Unsigned ^[rabin2-info.txt:27] |
| Import table | Only mscoree.dll!_CorExeMain ^[pefile.txt:255] |
How It Works
This sample follows the established bitmap-stego-loader template observed across ten prior siblings. The outer binary is a fully functional .NET Windows Forms application (Uzbek-language quiz GUI with FormViktorina, FormNatija, FormKategoriya forms) that serves as a carrier for an encrypted payload hidden in embedded image resources ^[strings.txt:35].
At runtime, the loader likely:
- Extracts raw pixel bytes from embedded images via
ExtractPixelBytes^[strings.txt:535] - Reconstructs an encrypted buffer from pixel data
- Decrypts via symmetric cipher (no cipher strings recovered in this sample; siblings use
RijndaelManagedorAesManaged) - Reflectively loads the decrypted assembly via
Activator.CreateInstance^[strings.txt:515] orAssembly.Load
No network APIs (System.Net.Http, WebClient, TcpClient) are present in strings, suggesting the payload is fully self-contained within the images. No persistence mechanisms or anti-analysis checks observed.
Decompiled Behavior
Static CIL analysis via radare2 shows 514 functions with standard .NET WinForms/ADO.NET DataSet patterns. Notable method names:
ExtractPixelBytes— pixel extraction for steganographic payload reconstruction ^[strings.txt:535]NatijalarniYuklash— "load results" in Uzbek; likely UI method or payload staging hook ^[strings.txt:7]SavolniKorsatish— "show question" in Uzbek ^[strings.txt:297]KeyingiSavolgaOtish— "go to next question" ^[strings.txt:294]
The GetPixel and Bitmap references confirm System.Drawing usage for image manipulation ^[strings.txt:365] ^[strings.txt:455].
C2 Infrastructure
None recoverable statically. No IP addresses, domains, URLs, mutexes, or named pipes in strings. C2 is either inside the encrypted image payload or the sample is a stage-1 self-contained dropper.
Interesting Tidbits
- Uzbek-language UI — forms, labels, and DataSet columns use Uzbek terms (
Savollar=questions,Javoblar=answers,Kategoriyalar=categories,Natijalar=results,TogriJavob=correct answer). This is consistent with theFormViktorina("Quiz Form") educational-app masquerade ^[strings.txt:36]. - Two image carriers of different formats — one BMP (180×180×32) and one large PNG (650×698 RGBA). The PNG is significantly larger than typical 76×76×24 BMP carriers in prior siblings, suggesting either higher-resolution payload encoding or a different steganographic scheme ^[binwalk.txt].
- Shared builder template —
ExtractPixelBytesmethod name andFormViktorina/FormNatija/FormKategoriyaform names are byte-for-byte identical across at least three other corpus samples (0cfbc10a,1d3e20ae,27ce11b6), confirming a common builder or source-code template. OpenCTI mislabels these siblings asspamitaandagentteslarespectively, demonstrating that outer-loader attribution does not imply inner-payload attribution. - VS_VERSIONINFO masquerade — "Flashcard Quiz Windows Forms Application" with empty
CompanyName, genericCopyright © 2026. Consistent with the cluster's pattern of plausible but unverifiable version info ^[exiftool.json].
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2019+, .NET Framework 4.5, C# WinForms
- Create a standard WinForms app with
FormViktorina,FormNatija,FormKategoriya - Add
System.Drawing.Bitmapresources (BMP/PNG) to.rsrc - Implement
ExtractPixelBytes(Bitmap bmp)usingLockBitsto read raw ARGB - Concatenate pixel bytes into a
MemoryStream - Encrypt with
RijndaelManaged+ hardcoded key - Decrypt at runtime and
Assembly.Load - Verification: Run
capaon the reproducer — expectload-code/dotnet,access .NET resource, andgenerate random numbers in .NEThits matching this sample's capa.txt
Deployable Signatures
YARA rule
rule dotnet_bitmap_stego_loader_flashquiz {
meta:
description = ".NET bitmap stego loader with FlashQuiz masquerade and ExtractPixelBytes"
author = "PacketPursuit"
date = "2026-08-19"
sha256 = "0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb"
strings:
$a = "ExtractPixelBytes" ascii wide
$b = "FormViktorina" ascii wide
$c = "FormNatija" ascii wide
$d = "FlashQuiz" ascii wide
$e = "System.Drawing.Bitmap" ascii wide
$f = "SavollarDataset" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
4 of ($a,$b,$c,$d,$e,$f)
}
Sigma rule
title: .NET Bitmap Stego Loader Execution
logsource:
product: windows
category: process_creation
detection:
selection_filename:
CommandLine|contains:
- 'MV_Lila_Houston_Vessel_Information_Particulars'
- 'wBjo.exe'
selection_hash:
Hashes|contains:
- '0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb'
condition: selection_filename or selection_hash
falsepositives:
- Unknown
level: high
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb | Hash |
| Filename | MV_Lila_Houston_Vessel_Information_Particulars.exe | Filename |
| Internal name | wBjo.exe | PE metadata |
| Product name | FlashQuiz | PE metadata |
| Build timestamp | 2026-05-29 03:02:57 UTC | Timestamp |
Behavioral fingerprint
This binary is a .NET Framework 4.5 WinForms GUI executable with Uzbek-language quiz UI masquerade. It embeds a BMP (180×180×32) and PNG (650×698 RGBA) image in its .text section. At runtime it extracts pixel bytes from these images via ExtractPixelBytes, reconstructs an encrypted payload, and reflectively loads it. No network IAT, no persistence, no anti-analysis. The inner payload family is indeterminate from static analysis.
Detection Signatures
- capa:
compiled to the .NET platform,load .NET assembly,access .NET resource,generate random numbers in .NET,reference analysis tools strings(false positive — debug attributes trigger T1620/T1059/T1083/B0013.001),delete file,check if file exists,manipulate console buffer^[capa.txt] - ATT&CK: T1620 (Reflective Code Loading — inferred from
Activator.CreateInstanceandAssembly.Loadpattern), T1083 (File and Directory Discovery — false positive from debug-build capa noise)
References
- unclassified-dotnet-bitmap-stego-loader — Cluster entity page
- bitmap-steganography-payload-delivery — Cross-family concept
- Sample
0cfbc10a(spamitalabel) — confirmed sibling with identicalExtractPixelBytes+FormViktorina - Sample
1d3e20ae(agentteslalabel) — confirmed sibling with identical builder template
Provenance
file.txt,pefile.txt,strings.txt,exiftool.json,binwalk.txt,capa.txt,rabin2-info.txtfrom triage pipeline- radare2 v5.9.4 CIL analysis (514 functions,
aa+afva) - Python pefile analysis for resource enumeration and COM descriptor inspection
- Manual string inspection and cross-sample correlation against
0cfbc10a,1d3e20ae,27ce11b6 - capa v9.1.2 static analysis