typeanalysisfamilyunclassified-dotnet-bitmap-stego-loaderconfidencemediumcreated2026-09-06updated2026-09-06dotnetobfuscationloaderbitmap-steganographyunclassifiedmasquerade
SHA-256: 0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0

unclassified-dotnet-bitmap-stego-loader: 0cfbc10a408c — MT103 SWIFT-transfer lure, FlashQuiz Uzbek quiz masquerade, 180×180 BMP + 622×670 PNG carriers

Executive Summary

.NET Framework 4.5 PE32 GUI executable masquerading as a SWIFT bank-transfer PDF (.bat extension) while internally presenting a fully functional Uzbek-language "FlashQuiz" Windows Forms quiz application. Contains embedded BMP and PNG image carriers with ExtractPixelBytes steganographic extraction logic, identical builder template to confirmed siblings 0becdb662b and 1d3e20ae. OpenCTI label spamita is a misattribution — static evidence places this firmly in the unclassified-dotnet-bitmap-stego-loader cluster. Twelfth confirmed sibling. No CAPE detonation (no Windows guest).

What It Is

Field Value
SHA-256 0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0
Size 987,136 bytes (964 KB)
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Build .NET Framework 4.5, compiled Fri May 29 03:57:59 2026 UTC ^[pefile.txt:34]
Internal name rmgW.exe ^[exiftool.json:40]
Source filename MT103_€162,024,40_Febeuary-May 2026_pdf.bat ^[metadata.json:5]
Packing / obfuscation None observed ^[pefile.txt]
Authenticode Unsigned ^[rabin2-info.txt:27]
Import table Only mscoree.dll!_CorExeMain ^[pefile.txt:255]
OpenCTI labels exe, malware-bazaar, spam-ita ^[triage.json:10]
Family attribution unclassified-dotnet-bitmap-stego-loader (cluster sibling n=12). spamita label contested — outer-loader misattribution does not reflect inner payload.

How It Works

This sample follows the established bitmap-stego-loader template. The outer binary is a functional .NET WinForms application (Uzbek quiz UI) serving as a carrier for an encrypted payload hidden in embedded image resources ^[strings.txt:468].

Runtime behavior (inferred from static cross-sibling correlation):

  1. Extracts raw pixel bytes from embedded images via ExtractPixelBytes ^[strings.txt:535]
  2. Reconstructs encrypted buffer from pixel data
  3. Decrypts via symmetric cipher (no cipher strings in this sample; siblings use RijndaelManaged or AesManaged)
  4. Reflectively loads decrypted assembly via Activator.CreateInstance ^[strings.txt:515] or Assembly.Load

No System.Net, WebClient, Socket, or HTTP references are present — payload is fully self-contained within the images. No persistence or anti-analysis checks observed.

Decompiled Behavior

radare2 CIL analysis finds 514 functions with standard .NET WinForms / ADO.NET DataSet patterns. Notable methods:

  • ExtractPixelBytes — steganographic payload reconstruction ^[strings.txt:535]
  • NatijalarniYuklash — "load results" in Uzbek; UI or staging hook ^[strings.txt:7]
  • KategoriyalarniYuklash — "load categories" ^[strings.txt:282]
  • SavolniKorsatish — "show question" ^[strings.txt:296]
  • JavobniTekshirish — "check answer" ^[strings.txt:291]
  • OyinBoshqaruvchi — "game controller" class ^[strings.txt:311]

System.Drawing.Bitmap and GetPixel references confirm image manipulation ^[strings.txt:455] ^[strings.txt:365].

Entry point (entry0 at 0x00402050) instantiates FormKategoriya, calls get_KILO and get_aWDu (resource accessors likely fetching embedded images), then enters the standard WinForms message loop ^[r2:entry0].

C2 Infrastructure

None recoverable statically. No IPs, domains, URLs, mutexes, or named pipes. C2 is either inside the encrypted image payload or the sample is a self-contained stage-1 dropper.

Interesting Tidbits

  • Banking SWIFT lure with typo — MT103_€162,024,40_Febeuary-May 2026_pdf.bat. "Febeuary" misspelling and .bat extension on a PE32 are both social-engineering pressure tactics ^[metadata.json:5].
  • Built 55 minutes after sibling 0becdb662b — Same day (May 29 2026), same template, different internal name (rmgW.exe vs wBjo.exe) and different lure (SWIFT transfer vs vessel particulars). Suggests automated builder pipeline with lure-swapping ^[pefile.txt:34].
  • PNG carrier dimensions differ slightly — 622×670 RGBA vs 650×698 in 0becdb662b ^[binwalk.txt]. Builder may scale images to fit payload size.
  • Empty VS_VERSIONINFO — All version fields are 0.0.0.0, empty CompanyName, empty LegalCopyright. Less fabricated than prior siblings but still unverifiable ^[exiftool.json].
  • No spamita malware artifacts — No SMTP, no mail libraries, no credential theft APIs. The spam-ita OpenCTI label is outer-loader misattribution.
  • Shared builder fingerprint — FormViktorina, FormNatija, FormKategoriya, ExtractPixelBytes, and FlashQuiz namespace are byte-for-byte identical across 0cfbc10a, 0becdb662b, and 1d3e20ae ^[strings.txt:468].

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2019+, .NET Framework 4.5, C# WinForms

  1. Create WinForms app with FormViktorina, FormNatija, FormKategoriya
  2. Add System.Drawing.Bitmap resources (BMP/PNG) to .rsrc
  3. Implement ExtractPixelBytes(Bitmap bmp) using LockBits to read raw ARGB
  4. Concatenate pixel bytes into MemoryStream
  5. Encrypt with RijndaelManaged + hardcoded key
  6. Decrypt at runtime and Assembly.Load / Activator.CreateInstance
  7. Verification: Run capa on reproducer — expect load-code/dotnet, access .NET resource, generate random numbers in .NET hits matching this sample's capa.txt

Deployable Signatures

YARA rule

rule dotnet_bitmap_stego_loader_flashquiz_mt103 {
    meta:
        description = ".NET bitmap stego loader with FlashQuiz masquerade, ExtractPixelBytes, and SWIFT/bank lure"
        author = "PacketPursuit"
        date = "2026-09-06"
        sha256 = "0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0"
    strings:
        $a = "ExtractPixelBytes" ascii wide
        $b = "FormViktorina" ascii wide
        $c = "FormNatija" ascii wide
        $d = "FlashQuiz" ascii wide
        $e = "System.Drawing.Bitmap" ascii wide
        $f = "SavollarDataset" ascii wide
        $g = "MT103" ascii wide
        $h = "OyinBoshqaruvchi" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        4 of ($a,$b,$c,$d,$e,$f,$g,$h)
}

Sigma rule

title: .NET Bitmap Stego Loader Execution — FlashQuiz SWIFT Lure
logsource:
    product: windows
    category: process_creation
detection:
    selection_filename:
        CommandLine|contains:
            - 'MT103_€162,024,40_Febeuary-May 2026_pdf.bat'
            - 'rmgW.exe'
    selection_hash:
        Hashes|contains:
            - '0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0'
    condition: selection_filename or selection_hash
falsepositives:
    - Unknown
level: high

IOC list

Indicator Value Type
SHA-256 0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0 Hash
Filename MT103_€162,024,40_Febeuary-May 2026_pdf.bat Filename
Internal name rmgW.exe PE metadata
Build timestamp 2026-05-29 03:57:59 UTC Timestamp
ssdeep 24576:xZLfdRAEFT0DZEOrEvcVkstDS7G+RaTVrbiDrLro:xZLb3FQeGrpS7G8ahiD Fuzzy hash
tlsh 5F250195261ECD06D4E64FF85960D2B817B49ED5E932E2039FDABDFFB87A3401805382 TLSH

Behavioral fingerprint

This binary is a .NET Framework 4.5 WinForms GUI executable with Uzbek-language quiz UI masquerade. It embeds a BMP (180×180×32) and PNG (622×670 RGBA) in its .text section. At runtime it extracts pixel bytes via ExtractPixelBytes, reconstructs an encrypted payload, and reflectively loads it via Activator.CreateInstance. No network IAT, no persistence, no anti-analysis. The inner payload family is indeterminate from static analysis. Distributed with banking/SWIFT-transfer social-engineering filenames and .bat extension masquerade.

Detection Signatures

  • capa: compiled to the .NET platform, load .NET assembly, access .NET resource, generate random numbers in .NET, reference analysis tools strings (false positive — debug attributes trigger anti-analysis noise), delete file, check if file exists, manipulate console buffer ^[capa.txt]
  • ATT&CK: T1620 (Reflective Code Loading — inferred from Activator.CreateInstance and Assembly.Load pattern), T1083 (File and Directory Discovery — false positive from debug-build capa noise)
  • MBC: C0021.003 Generate Pseudo-random Sequence, B0013.001 Analysis Tool Discovery, E1083 File and Directory Discovery, C0047 Delete File, C0033 Console ^[capa.txt]

References

Provenance

  • file.txt, pefile.txt, strings.txt, exiftool.json, binwalk.txt, capa.txt, rabin2-info.txt, ssdeep.txt, tlsh.txt, metadata.json, triage.json from triage pipeline
  • radare2 v5.9.4 CIL analysis (514 functions, aa + afva)
  • Python pefile analysis for resource enumeration
  • Manual string inspection and cross-sample correlation against 0becdb662b and 1d3e20ae
  • capa v9.1.2 static analysis