21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2cunattributed: 21b12514 — third confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster
Executive Summary
Third confirmed sibling in a cluster of MSVC 14.12 PE32 GUI reflective loaders compiled Sep 9 2022 (timestamp 0x631A9665). Shares the same stub template as siblings 136b5750 and 3b42403b: PEB-walking API resolution, XOR-NOT alphabet cipher (0x10035fff), CPUID anti-VM, and LCG PRNG (0x19660d/0x3c6ef35f). This hash differs in PE checksum, section hashes, and .data content — it carries an individualized encrypted payload in .data, confirming per-sample customization rather than identical replication. Static-only analysis (CAPE skipped — no Windows guest). See /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html for full structural analysis of the cluster stub.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c |
| SHA-1 | 23765c717e1f163d91faf20b827c9a55f8727829 ^[pefile.txt:163] |
| MD5 | e96b16aa390ee3888bbcfa87e3a73f9f ^[pefile.txt:163] |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5 or newer ^[pefile.txt:18] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal surface: GDI32 (6), USER32 (11), KERNEL32 (8) ^[pefile.txt:249] |
| YARA | Generic PE only; no family-specific hits ^[yara.txt] |
PE checksum differs from sibling 136b5750 (0x2F55C vs 0x2BC5A), and .text/.data section MD5/SHA-256 hashes differ, confirming this is not a hash collision but a distinct build with individualized payload. ^[pefile.txt]
Build / RE
Toolchain & Stub Structure
Identical to sibling 136b5750 — see that report for full decompilation. Key confirmations for this hash:
- XOR-NOT decrypt at
0x401240uses key0x10035fff, called from0x40d4b0(alphabet builder) and0x40d55a(POST verb decrypt). ^[r2:fcn.00401240] - Alphabet table decrypts to
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789via 16-DWORD array at0x40d4c9. ^[r2:fcn.0040d4b0] - POST verb decrypted from
0xef8fa025 0xefd9a03d 0xeffca073(3 DWORDs) at0x40d543. ^[r2:fcn.0040d543] - LCG PRNG at
0x40110c:seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. ^[r2:fcn.0040110c] - Anti-VM gate at
0x4010bc: CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 differential timing. ^[r2:fcn.004010bc] - PEB-walker at
0x417034loads kernel32 via PEB InMemoryOrderModuleList, spawns file-system thread (0x407468) and C2 thread (0x40782c), with reflective mapper at0x406668. ^[r2:fcn.00417034]
Per-Sample Delta
| Attribute | 21b12514 (this) | 136b5750 (sibling) |
|---|---|---|
| PE Checksum | 0x2F55C |
0x2BC5A |
.text MD5 |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
299ed0bc52def60ad9927e69f2bba088 |
.text SHA-256 |
000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
be2dc068760039090865f3696066df5249a7601a1cf9be26bcb7096af81ef121 |
.data MD5 |
299ed0bc52def60ad9927e69f2bba088 |
991090a0e1f6d5368522abda010b3fba |
.data SHA-256 |
be2dc068760039090865f3696066df5249a7601a1cf9be26bcb7096af81ef121 |
f2e9b4366a834733f0f70dc638c2b4d41e966577b23ddea199787e52f112a45f |
The .text section hash difference is small (~0.5% of bytes changed), consistent with recompiled payload data or individualized embedded config. The .data hash differs substantially, confirming individualized encrypted payload content. ^[pefile.txt]
Deploy / ATT&CK
TTPs are identical to sibling 136b5750; this hash-specific entry does not add new ATT&CK techniques. See the sibling report for full TTP mapping. Condensed:
| Technique | Implementation |
|---|---|
| T1055 — Process Injection | Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation ^[r2:fcn.00406668] |
| T1071.001 — Application Layer Protocol: Web Protocols | HTTP POST C2 with encrypted body; WinInet API resolution ^[r2:fcn.0040cfcc] |
| T1027 — Obfuscated Files or Information | XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation ^[r2:fcn.00401240] ^[r2:fcn.0040d4b0] |
| T1497.001 — Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) ^[r2:fcn.004010bc] |
| T1497.002 — Virtualization/Sandbox Evasion: User Activity Based | RDTSC differential timing gate ^[r2:fcn.004010bc] |
| T1083 — File and Directory Discovery | Recursive "*" enumeration via FindFirstFile / FindNextFile ^[r2:fcn.00407468] |
| T1573.001 — Encrypted Channel: Symmetric Cryptography | CryptEncrypt / CryptDecrypt for C2 payload body ^[r2:fcn.0040782c] |
| T1105 — Ingress Tool Transfer | Downloader / payload retrieval via HTTP POST response handling ^[r2:fcn.0040782c] |
IOCs
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | 21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c |
Primary |
| SHA-1 | 23765c717e1f163d91faf20b827c9a55f8727829 |
^[pefile.txt:163] |
| MD5 | e96b16aa390ee3888bbcfa87e3a73f9f |
^[pefile.txt:163] |
| Compilation | Sep 9 2022 01:27:01 UTC | Timestamp 0x631A9665 (shared with siblings) |
| Linker | 14.12 | VS 2017 15.5+ |
| PE Checksum | 0x2F55C |
Differs from 136b5750 (0x2BC5A) |
| XOR Key | 0x10035fff |
Shared with siblings |
| LCG multiplier | 0x19660d |
Shared with siblings |
| LCG increment | 0x3c6ef35f |
Shared with siblings |
| Anti-VM | CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 | Shared with siblings |
| Pseudo-import region | 0x425000–0x425fff (.data VA) |
Decrypted at runtime; content individualized |
Cluster Membership
| Hash | Role | Notes |
|---|---|---|
136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51 |
First observed sibling | Deep structural analysis (report reference) |
3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde |
Second confirmed sibling | Individualized .data payload, same stub template ^[/intel/analyses/3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde.html] |
21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c |
Third confirmed sibling (this) | Individualized .data payload, new section hashes, same stub template |
References
- Deep structural analysis of cluster stub: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
- Second sibling: /intel/analyses/3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde.html
- OpenCTI artifact labels:
dropped-by-phorpiex,exe,malware-bazaar^[metadata.json] - Entity page: unattributed
- Technique pages: peb-walking-api-resolution, prng-seeded-c2-url-decoding
Provenance
Analysis produced from static triage inputs and radare2 decompilation (analysis level 3) of the binary at <sample 21b12514e8d7.bin>. CAPE dynamic analysis skipped — no Windows guest available. All behavioral claims are statically inferred and marked accordingly. Sibling relationship verified via PE metadata (timestamp, linker version, size) and section-hash comparison.