0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0unclassified-dotnet-bitmap-stego-loader: 0cfbc10a408c — MT103 SWIFT-transfer lure, FlashQuiz Uzbek quiz masquerade, 180×180 BMP + 622×670 PNG carriers
Executive Summary
.NET Framework 4.5 PE32 GUI executable masquerading as a SWIFT bank-transfer PDF (.bat extension) while internally presenting a fully functional Uzbek-language "FlashQuiz" Windows Forms quiz application. Contains embedded BMP and PNG image carriers with ExtractPixelBytes steganographic extraction logic, identical builder template to confirmed siblings 0becdb662b and 1d3e20ae. OpenCTI label spamita is a misattribution — static evidence places this firmly in the unclassified-dotnet-bitmap-stego-loader cluster. Twelfth confirmed sibling. No CAPE detonation (no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0 |
| Size | 987,136 bytes (964 KB) |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Build | .NET Framework 4.5, compiled Fri May 29 03:57:59 2026 UTC ^[pefile.txt:34] |
| Internal name | rmgW.exe ^[exiftool.json:40] |
| Source filename | MT103_€162,024,40_Febeuary-May 2026_pdf.bat ^[metadata.json:5] |
| Packing / obfuscation | None observed ^[pefile.txt] |
| Authenticode | Unsigned ^[rabin2-info.txt:27] |
| Import table | Only mscoree.dll!_CorExeMain ^[pefile.txt:255] |
| OpenCTI labels | exe, malware-bazaar, spam-ita ^[triage.json:10] |
| Family attribution | unclassified-dotnet-bitmap-stego-loader (cluster sibling n=12). spamita label contested — outer-loader misattribution does not reflect inner payload. |
How It Works
This sample follows the established bitmap-stego-loader template. The outer binary is a functional .NET WinForms application (Uzbek quiz UI) serving as a carrier for an encrypted payload hidden in embedded image resources ^[strings.txt:468].
Runtime behavior (inferred from static cross-sibling correlation):
- Extracts raw pixel bytes from embedded images via
ExtractPixelBytes^[strings.txt:535] - Reconstructs encrypted buffer from pixel data
- Decrypts via symmetric cipher (no cipher strings in this sample; siblings use
RijndaelManagedorAesManaged) - Reflectively loads decrypted assembly via
Activator.CreateInstance^[strings.txt:515] orAssembly.Load
No System.Net, WebClient, Socket, or HTTP references are present — payload is fully self-contained within the images. No persistence or anti-analysis checks observed.
Decompiled Behavior
radare2 CIL analysis finds 514 functions with standard .NET WinForms / ADO.NET DataSet patterns. Notable methods:
ExtractPixelBytes— steganographic payload reconstruction ^[strings.txt:535]NatijalarniYuklash— "load results" in Uzbek; UI or staging hook ^[strings.txt:7]KategoriyalarniYuklash— "load categories" ^[strings.txt:282]SavolniKorsatish— "show question" ^[strings.txt:296]JavobniTekshirish— "check answer" ^[strings.txt:291]OyinBoshqaruvchi— "game controller" class ^[strings.txt:311]
System.Drawing.Bitmap and GetPixel references confirm image manipulation ^[strings.txt:455] ^[strings.txt:365].
Entry point (entry0 at 0x00402050) instantiates FormKategoriya, calls get_KILO and get_aWDu (resource accessors likely fetching embedded images), then enters the standard WinForms message loop ^[r2:entry0].
C2 Infrastructure
None recoverable statically. No IPs, domains, URLs, mutexes, or named pipes. C2 is either inside the encrypted image payload or the sample is a self-contained stage-1 dropper.
Interesting Tidbits
- Banking SWIFT lure with typo —
MT103_€162,024,40_Febeuary-May 2026_pdf.bat. "Febeuary" misspelling and.batextension on a PE32 are both social-engineering pressure tactics ^[metadata.json:5]. - Built 55 minutes after sibling
0becdb662b— Same day (May 29 2026), same template, different internal name (rmgW.exevswBjo.exe) and different lure (SWIFT transfer vs vessel particulars). Suggests automated builder pipeline with lure-swapping ^[pefile.txt:34]. - PNG carrier dimensions differ slightly — 622×670 RGBA vs 650×698 in
0becdb662b^[binwalk.txt]. Builder may scale images to fit payload size. - Empty VS_VERSIONINFO — All version fields are
0.0.0.0, emptyCompanyName, emptyLegalCopyright. Less fabricated than prior siblings but still unverifiable ^[exiftool.json]. - No
spamitamalware artifacts — No SMTP, no mail libraries, no credential theft APIs. Thespam-itaOpenCTI label is outer-loader misattribution. - Shared builder fingerprint —
FormViktorina,FormNatija,FormKategoriya,ExtractPixelBytes, andFlashQuiznamespace are byte-for-byte identical across0cfbc10a,0becdb662b, and1d3e20ae^[strings.txt:468].
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2019+, .NET Framework 4.5, C# WinForms
- Create WinForms app with
FormViktorina,FormNatija,FormKategoriya - Add
System.Drawing.Bitmapresources (BMP/PNG) to.rsrc - Implement
ExtractPixelBytes(Bitmap bmp)usingLockBitsto read raw ARGB - Concatenate pixel bytes into
MemoryStream - Encrypt with
RijndaelManaged+ hardcoded key - Decrypt at runtime and
Assembly.Load/Activator.CreateInstance - Verification: Run
capaon reproducer — expectload-code/dotnet,access .NET resource,generate random numbers in .NEThits matching this sample's capa.txt
Deployable Signatures
YARA rule
rule dotnet_bitmap_stego_loader_flashquiz_mt103 {
meta:
description = ".NET bitmap stego loader with FlashQuiz masquerade, ExtractPixelBytes, and SWIFT/bank lure"
author = "PacketPursuit"
date = "2026-09-06"
sha256 = "0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0"
strings:
$a = "ExtractPixelBytes" ascii wide
$b = "FormViktorina" ascii wide
$c = "FormNatija" ascii wide
$d = "FlashQuiz" ascii wide
$e = "System.Drawing.Bitmap" ascii wide
$f = "SavollarDataset" ascii wide
$g = "MT103" ascii wide
$h = "OyinBoshqaruvchi" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
4 of ($a,$b,$c,$d,$e,$f,$g,$h)
}
Sigma rule
title: .NET Bitmap Stego Loader Execution — FlashQuiz SWIFT Lure
logsource:
product: windows
category: process_creation
detection:
selection_filename:
CommandLine|contains:
- 'MT103_€162,024,40_Febeuary-May 2026_pdf.bat'
- 'rmgW.exe'
selection_hash:
Hashes|contains:
- '0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0'
condition: selection_filename or selection_hash
falsepositives:
- Unknown
level: high
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0 | Hash |
| Filename | MT103_€162,024,40_Febeuary-May 2026_pdf.bat | Filename |
| Internal name | rmgW.exe | PE metadata |
| Build timestamp | 2026-05-29 03:57:59 UTC | Timestamp |
| ssdeep | 24576:xZLfdRAEFT0DZEOrEvcVkstDS7G+RaTVrbiDrLro:xZLb3FQeGrpS7G8ahiD | Fuzzy hash |
| tlsh | 5F250195261ECD06D4E64FF85960D2B817B49ED5E932E2039FDABDFFB87A3401805382 | TLSH |
Behavioral fingerprint
This binary is a .NET Framework 4.5 WinForms GUI executable with Uzbek-language quiz UI masquerade. It embeds a BMP (180×180×32) and PNG (622×670 RGBA) in its .text section. At runtime it extracts pixel bytes via ExtractPixelBytes, reconstructs an encrypted payload, and reflectively loads it via Activator.CreateInstance. No network IAT, no persistence, no anti-analysis. The inner payload family is indeterminate from static analysis. Distributed with banking/SWIFT-transfer social-engineering filenames and .bat extension masquerade.
Detection Signatures
- capa:
compiled to the .NET platform,load .NET assembly,access .NET resource,generate random numbers in .NET,reference analysis tools strings(false positive — debug attributes trigger anti-analysis noise),delete file,check if file exists,manipulate console buffer^[capa.txt] - ATT&CK: T1620 (Reflective Code Loading — inferred from
Activator.CreateInstanceandAssembly.Loadpattern), T1083 (File and Directory Discovery — false positive from debug-build capa noise) - MBC: C0021.003 Generate Pseudo-random Sequence, B0013.001 Analysis Tool Discovery, E1083 File and Directory Discovery, C0047 Delete File, C0033 Console ^[capa.txt]
References
- unclassified-dotnet-bitmap-stego-loader — Cluster entity page
- bitmap-steganography-payload-delivery — Cross-family concept
- Sample
0becdb662b(spamitalabel) — confirmed sibling with identical builder template, built 55 min earlier - Sample
1d3e20ae(agentteslalabel) — confirmed sibling with identical builder template
Provenance
file.txt,pefile.txt,strings.txt,exiftool.json,binwalk.txt,capa.txt,rabin2-info.txt,ssdeep.txt,tlsh.txt,metadata.json,triage.jsonfrom triage pipeline- radare2 v5.9.4 CIL analysis (514 functions,
aa+afva) - Python pefile analysis for resource enumeration
- Manual string inspection and cross-sample correlation against
0becdb662band1d3e20ae - capa v9.1.2 static analysis