typeanalysisfamilyunattributedconfidencemediumcreated2026-07-29updated2026-07-29pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c

unattributed: 21b12514 — third confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster

Executive Summary

Third confirmed sibling in a cluster of MSVC 14.12 PE32 GUI reflective loaders compiled Sep 9 2022 (timestamp 0x631A9665). Shares the same stub template as siblings 136b5750 and 3b42403b: PEB-walking API resolution, XOR-NOT alphabet cipher (0x10035fff), CPUID anti-VM, and LCG PRNG (0x19660d/0x3c6ef35f). This hash differs in PE checksum, section hashes, and .data content — it carries an individualized encrypted payload in .data, confirming per-sample customization rather than identical replication. Static-only analysis (CAPE skipped — no Windows guest). See /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html for full structural analysis of the cluster stub.

What It Is

Field Value
SHA-256 21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c
SHA-1 23765c717e1f163d91faf20b827c9a55f8727829 ^[pefile.txt:163]
MD5 e96b16aa390ee3888bbcfa87e3a73f9f ^[pefile.txt:163]
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5 or newer ^[pefile.txt:18] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal surface: GDI32 (6), USER32 (11), KERNEL32 (8) ^[pefile.txt:249]
YARA Generic PE only; no family-specific hits ^[yara.txt]

PE checksum differs from sibling 136b5750 (0x2F55C vs 0x2BC5A), and .text/.data section MD5/SHA-256 hashes differ, confirming this is not a hash collision but a distinct build with individualized payload. ^[pefile.txt]

Build / RE

Toolchain & Stub Structure

Identical to sibling 136b5750 — see that report for full decompilation. Key confirmations for this hash:

  • XOR-NOT decrypt at 0x401240 uses key 0x10035fff, called from 0x40d4b0 (alphabet builder) and 0x40d55a (POST verb decrypt). ^[r2:fcn.00401240]
  • Alphabet table decrypts to ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789 via 16-DWORD array at 0x40d4c9. ^[r2:fcn.0040d4b0]
  • POST verb decrypted from 0xef8fa025 0xefd9a03d 0xeffca073 (3 DWORDs) at 0x40d543. ^[r2:fcn.0040d543]
  • LCG PRNG at 0x40110c: seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. ^[r2:fcn.0040110c]
  • Anti-VM gate at 0x4010bc: CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 differential timing. ^[r2:fcn.004010bc]
  • PEB-walker at 0x417034 loads kernel32 via PEB InMemoryOrderModuleList, spawns file-system thread (0x407468) and C2 thread (0x40782c), with reflective mapper at 0x406668. ^[r2:fcn.00417034]

Per-Sample Delta

Attribute 21b12514 (this) 136b5750 (sibling)
PE Checksum 0x2F55C 0x2BC5A
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 299ed0bc52def60ad9927e69f2bba088
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 be2dc068760039090865f3696066df5249a7601a1cf9be26bcb7096af81ef121
.data MD5 299ed0bc52def60ad9927e69f2bba088 991090a0e1f6d5368522abda010b3fba
.data SHA-256 be2dc068760039090865f3696066df5249a7601a1cf9be26bcb7096af81ef121 f2e9b4366a834733f0f70dc638c2b4d41e966577b23ddea199787e52f112a45f

The .text section hash difference is small (~0.5% of bytes changed), consistent with recompiled payload data or individualized embedded config. The .data hash differs substantially, confirming individualized encrypted payload content. ^[pefile.txt]

Deploy / ATT&CK

TTPs are identical to sibling 136b5750; this hash-specific entry does not add new ATT&CK techniques. See the sibling report for full TTP mapping. Condensed:

Technique Implementation
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation ^[r2:fcn.00406668]
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution ^[r2:fcn.0040cfcc]
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation ^[r2:fcn.00401240] ^[r2:fcn.0040d4b0]
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) ^[r2:fcn.004010bc]
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate ^[r2:fcn.004010bc]
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile ^[r2:fcn.00407468]
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body ^[r2:fcn.0040782c]
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling ^[r2:fcn.0040782c]

IOCs

Indicator Value Notes
SHA-256 21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c Primary
SHA-1 23765c717e1f163d91faf20b827c9a55f8727829 ^[pefile.txt:163]
MD5 e96b16aa390ee3888bbcfa87e3a73f9f ^[pefile.txt:163]
Compilation Sep 9 2022 01:27:01 UTC Timestamp 0x631A9665 (shared with siblings)
Linker 14.12 VS 2017 15.5+
PE Checksum 0x2F55C Differs from 136b5750 (0x2BC5A)
XOR Key 0x10035fff Shared with siblings
LCG multiplier 0x19660d Shared with siblings
LCG increment 0x3c6ef35f Shared with siblings
Anti-VM CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 Shared with siblings
Pseudo-import region 0x425000–0x425fff (.data VA) Decrypted at runtime; content individualized

Cluster Membership

Hash Role Notes
136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51 First observed sibling Deep structural analysis (report reference)
3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde Second confirmed sibling Individualized .data payload, same stub template ^[/intel/analyses/3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde.html]
21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c Third confirmed sibling (this) Individualized .data payload, new section hashes, same stub template

References

  • Deep structural analysis of cluster stub: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Second sibling: /intel/analyses/3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde.html
  • OpenCTI artifact labels: dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
  • Entity page: unattributed
  • Technique pages: peb-walking-api-resolution, prng-seeded-c2-url-decoding

Provenance

Analysis produced from static triage inputs and radare2 decompilation (analysis level 3) of the binary at <sample 21b12514e8d7.bin>. CAPE dynamic analysis skipped — no Windows guest available. All behavioral claims are statically inferred and marked accordingly. Sibling relationship verified via PE metadata (timestamp, linker version, size) and section-hash comparison.