typeanalysisfamilyblackmatterconfidencelowcreated2026-09-04updated2026-09-04peloadermalware-familyanti-vmanti-debugevasionc2malware-bazaarattribution
SHA-256: 1e399538c41be1c39566a00c95b78b39186510254e24562ec53a414ad74c23a1

blackmatter: 1e399538 — 39th sibling, PE checksum 0x2F0F2, .text MD5 cfbda2c4

Another specimen in the MSVC 14.12 reflective-loader cluster falsely tagged blackmatter by OpenCTI. Identical stub template to all 38 prior siblings — same compilation timestamp, linker version, and XOR key — with a fresh .data payload and unique PE checksum. Delivered via Phorpiex spam infrastructure. Static-only; CAPE skipped.

What It Is

  • SHA-256: 1e399538c41be1c39566a00c95b78b39186510254e24562ec53a414ad74c23a1 ^[file.txt]
  • File type: PE32 executable (GUI) Intel 80386, 6 sections, 150 KB ^[file.txt]
  • Compilation: Fri Sep 9 01:27:01 2022 UTC (0x631A9665) ^[pefile.txt:34]
  • Linker: MSVC 14.12 (VS 2017 15.5+) ^[pefile.txt:45]
  • Subsystem: Windows GUI ^[pefile.txt:67]
  • Mitigations: ASLR, DEP/NX, stack canary — all enabled ^[pefile.txt:74]
  • Signing: Unsigned ^[rabin2-info.txt:27]
  • PE Checksum: 0x2F0F2 (header) vs 0x2d3d8 (computed) — mismatch is consistent across cluster ^[pefile.txt:65] ^[rabin2-info.txt:10]
  • OpenCTI labels: exe, blackmatter, dropped-by-phorpiex, malware-bazaar ^[triage.json]

How It Works

This sample is a twin build of the unattributed MSVC 14.12 reflective loader described in the cluster entity page blackmatter. The .text stub is byte-identical to the majority group (MD5 cfbda2c44e51b3b0b00bcbbc767c62a2) ^[pefile.txt:93]; the only per-sample variation is the encrypted payload in .data and the resulting PE checksum. The .data section is 40 KB with near-maximum entropy (7.985) ^[pefile.txt:152], indicating encrypted or compressed payload content.

Cluster behavior (documented in detail on the blackmatter entity page):

  • PEB-walking API resolution via InMemoryOrderModuleList traversal and export-name hashing; ~30+ threat APIs resolved at runtime and cached in .data pseudo-import table ^[peb-walking-api-resolution]
  • XOR-NOT alphabet cipher with key 0x10035fff for string decryption ^[xor-not-string-decryption]
  • CPUID hypervisor-bit check + RDTSC timing gate for anti-VM / anti-emulation ^[blackmatter]
  • LCG PRNG (0x19660d / 0x3c6ef35f) for C2 URL generation at runtime ^[blackmatter]
  • Reflective PE loader: decrypts .data payload, maps it into RWX memory via VirtualAlloc, and transfers execution

Decompiled Behavior

Static-only analysis. No Ghidra decompilation run (tool unavailable for this session). Stub behavior is inferred from cluster siblings and prior deep-dive reports (136b5750, 21b12514, 80d36c04, etc.) where the same .text template was decompiled. See blackmatter entity page for reconstructed entry-point flow and xref evidence.

C2 Infrastructure

No hardcoded C2 strings recovered statically. The stub generates C2 URLs at runtime using an LCG PRNG seeded from the system clock. This is a domain-generation algorithm (DGA) pattern that defeats static IOC extraction. No domains, IPs, or URLs are embedded in the binary.

Interesting Tidbits

  • .text MD5 cfbda2c4 matches the majority group shared by 38+ siblings, confirming a single builder pipeline with per-sample payload customization. ^[pefile.txt:93]
  • .data SHA-256 b0d33d9f629dcf269c3c65df9cc651a36ddd305e7b83331c1b7df10c7f8cbb4a is unique to this sample. ^[pefile.txt:155]
  • Import facade is identical to all siblings: GDI32 (6 GUI functions), USER32 (11 window/dialog functions), KERNEL32 (7 base functions including LoadLibraryW and GetTickCount). No networking, crypto, or process APIs are imported statically. ^[pefile.txt:249-301]
  • PE checksum mismatch (0x2F0F2 vs computed 0x2d3d8) is intentional or a builder artifact; present across the entire cluster. ^[pefile.txt:65]
  • blackmatter OpenCTI label is a false-positive family attribution. The binary is a reflective loader / dropper, not ransomware. ^[blackmatter]
  • Capa failed due to missing signature database in this environment. FLOSS invocation used incorrect CLI syntax. ^[capa.txt] ^[floss.txt]

How To Mess With It (Homelab Replication)

See the cluster-level replication notes on the blackmatter entity page. To reproduce a comparable binary:

  • Compile a minimal PE32 GUI stub in MSVC 14.12 with POGO optimization
  • Implement PEB-walking API resolution (no static imports beyond KERNEL32/GDI32/USER32 facade)
  • Embed an encrypted payload in .data with a per-sample XOR-NOT cipher
  • Add CPUID + RDTSC anti-VM gate before decryption
  • Run capa against the result; should match the cluster's capability fingerprint once signatures are installed

Deployable Signatures

YARA Rule — BlackMatter Cluster PE32 Reflective Loader

rule BlackMatter_Loader_Cluster_PE32
{
    meta:
        description = "MSVC 14.12 reflective loader cluster (false-positive blackmatter label)"
        author = "PacketPursuit"
        date = "2026-09-04"
        sha256 = "1e399538c41be1c39566a00c95b78b39186510254e24562ec53a414ad74c23a1"
        cluster = "blackmatter-loader"
    strings:
        $mz = { 4D 5A }
        $linker_14_12 = { 0E 0C }
        $ts_2022_09_09 = { 65 96 1A 63 }
        $peb_walk_gdi = "gdi32.dll" ascii
        $peb_walk_user = "USER32.dll" ascii
        $peb_walk_kernel = "KERNEL32.dll" ascii
    condition:
        $mz at 0 and
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x14) == 0xE0 and
        uint8(uint32(0x3C)+0x5C) == 0x02 and
        uint16(uint32(0x3C)+0x16) == 0x0006 and
        uint32(uint32(0x3C)+0x40) == 0x631A9665 and
        uint8(uint32(0x3C)+0x42) == 0x0E and
        uint8(uint32(0x3C)+0x43) == 0x0C and
        filesize < 200KB and
        filesize > 120KB
}

Behavioral Hunt Query — KQL (Microsoft Defender / Sentinel)

DeviceProcessEvents
| where FileName endswith ".exe"
| where SHA256 startswith "1e399538" or
      (FolderPath contains @"\AppData\Local\Temp\" and
       InitiatingProcessFileName == @"wscript.exe" or InitiatingProcessFileName == @"cscript.exe")
| where ProcessCommandLine contains "rundll32" or ProcessCommandLine contains "regsvr32"
| summarize arg_min(Timestamp, *) by SHA256

Note: This query targets the Phorpiex delivery chain observed in sibling samples. The loader itself has no static command-line signature.

IOC List

Indicator Value Type Notes
SHA-256 1e399538c41be1c39566a00c95b78b39186510254e24562ec53a414ad74c23a1 File Primary sample
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 Section hash Majority group stub
.data SHA-256 b0d33d9f629dcf269c3c65df9cc651a36ddd305e7b83331c1b7df10c7f8cbb4a Section hash Per-sample payload
PE Checksum 0x2F0F2 PE header Unique per sample
Compilation 0x631A9665 (2022-09-09 01:27:01 UTC) Timestamp Shared across all 39 siblings
XOR Key 0x10035fff Crypto Inferred from cluster decompilation
LCG Seeds 0x19660d / 0x3c6ef35f PRNG C2 URL generation (inferred)
ssdeep 3072:26glyuxE4GsUPnliByocWepo7wglcr869H4h9:26gDBGpvEByocWeG7HlcDV4h9 Fuzzy hash Sample-specific
tlsh E0E37E21F212D0B3C87718F13736B5B2F39E8D6C15A96807DAD80F99BCA58232F15997 Fuzzy hash Sample-specific

Behavioral Fingerprint Statement

This binary is a 150 KB PE32 GUI executable compiled with MSVC 14.12 on 2022-09-09. It imports only 24 functions across GDI32, USER32, and KERNEL32 — all GUI or base CRT functions. No networking, process injection, or cryptographic APIs are imported statically. At runtime, it walks the PEB InMemoryOrderModuleList to resolve ~30+ threat APIs by hashed export names, decrypts a 40 KB .data payload using an XOR-NOT cipher with key 0x10035fff, and reflectively maps the decrypted payload into RWX memory. Prior to decryption, it performs a CPUID hypervisor-bit check and an RDTSC timing gate to detect sandboxes. C2 URLs are generated at runtime using an LCG PRNG with seeds 0x19660d/0x3c6ef35f, preventing static extraction of network indicators. The PE checksum is intentionally mismatched (0x2F0F2 vs computed 0x2d3d8).

Detection Signatures

  • MITRE ATT&CK: T1055 (Process Injection — reflective PE loading), T1027 (Obfuscated Files or Information), T1497.001 (Virtualization/Sandbox Evasion — CPUID check), T1059.003 (Windows Command Shell — payload execution), T1071.001 (Application Layer Protocol — HTTP for C2), T1573 (Encrypted Channel — runtime C2 payload encryption)
  • capa: Not available (signature database missing in environment). Capabilities inferred from cluster decompilation and pefile/rabin2 analysis.
  • YARA: PE_File_Generic (trivial hit) ^[yara.txt]

References

  • blackmatter — cluster entity page with full build pattern, decompiled behavior, and all 38 prior siblings
  • peb-walking-api-resolution — technique page for the PEB API resolution pattern
  • xor-not-string-decryption — technique page for the XOR-NOT cipher
  • phorpiex — delivery infrastructure (Phorpiex spam botnet)
  • unattributed — umbrella entity for this loader family pending true family identification
  • MalwareBazaar / abuse.ch artifact ID: 270ad765-412d-40af-a0c4-e8903c96f7fd ^[metadata.json]

Provenance

  • Static analysis files generated by triage pipeline on 2026-05-29: file.txt, pefile.txt, rabin2-info.txt, strings.txt, ssdeep.txt, tlsh.txt, yara.txt, exiftool.json, metadata.json, triage.json, capa.txt (failed — missing signatures), floss.txt (failed — incorrect CLI invocation).
  • This report written 2026-09-04 based on cluster analysis and static artifacts.
  • No dynamic execution (CAPE skipped — no Windows guest available).