2e3876a4a2e1d7456dbc95a254b419de25a9b26d2bab3d98d8c9ff0faa43b48cblackmatter: 2e3876a4 — 38th sibling, PE checksum 0x2FA78, .text MD5 cfbda2c4
Another specimen in the MSVC 14.12 reflective-loader cluster falsely tagged ransomware.blackmatter by OpenCTI. Identical stub template to all 37 prior siblings — same compilation timestamp, linker version, and XOR key — with a fresh .data payload and unique PE checksum. Delivered via Phorpiex spam infrastructure. Static-only; CAPE skipped.
What It Is
- SHA-256:
2e3876a4a2e1d7456dbc95a254b419de25a9b26d2bab3d98d8c9ff0faa43b48c^[file.txt] - File type: PE32 executable (GUI) Intel 80386, 6 sections, 150 KB ^[file.txt]
- Compilation:
Fri Sep 9 01:27:01 2022 UTC(0x631A9665) ^[pefile.txt:34] - Linker: MSVC 14.12 (VS 2017 15.5+) ^[pefile.txt:45]
- Subsystem: Windows GUI ^[pefile.txt:67]
- Mitigations: ASLR, DEP/NX, stack canary — all enabled ^[pefile.txt:74]
- Signing: Unsigned ^[rabin2-info.txt:27]
- PE Checksum:
0x2FA78(header) vs0x2dd5e(computed) — mismatch is consistent across cluster ^[pefile.txt:65] ^[rabin2-info.txt:10] - OpenCTI labels:
exe,ransomware.blackmatter,urlhaus^[triage.json]
How It Works
This sample is a twin build of the unattributed MSVC 14.12 reflective loader described in the cluster entity page blackmatter. The .text stub is byte-identical to the majority group (MD5 cfbda2c44e51b3b0b00bcbbc767c62a2) ^[pefile.txt:93]; the only per-sample variation is the encrypted payload in .data and the resulting PE checksum. The .data section is 40 KB with near-maximum entropy (7.985) ^[pefile.txt:152], indicating encrypted or compressed payload content.
Cluster behavior (documented in detail on the blackmatter entity page):
- PEB-walking API resolution via
InMemoryOrderModuleListtraversal and export-name hashing; ~30+ threat APIs resolved at runtime and cached in.datapseudo-import table ^[peb-walking-api-resolution] - XOR-NOT alphabet cipher with key
0x10035ffffor string decryption ^[xor-not-string-decryption] - CPUID hypervisor-bit check + RDTSC timing gate for anti-VM / anti-emulation ^[blackmatter]
- LCG PRNG (
0x19660d/0x3c6ef35f) for C2 URL generation at runtime ^[blackmatter] - Reflective PE loader: decrypts
.datapayload, maps it into RWX memory viaVirtualAlloc, and transfers execution
Decompiled Behavior
Static-only analysis. No Ghidra decompilation run (tool unavailable for this session). Stub behavior is inferred from cluster siblings and prior deep-dive reports (136b5750, 21b12514, 80d36c04, etc.) where the same .text template was decompiled. See blackmatter entity page for reconstructed entry-point flow and xref evidence.
C2 Infrastructure
No hardcoded C2 strings recovered statically. The stub generates C2 URLs at runtime using an LCG PRNG seeded from the system clock. This is a domain-generation algorithm (DGA) pattern that defeats static IOC extraction. No domains, IPs, or URLs are embedded in the binary.
Interesting Tidbits
.textMD5cfbda2c4matches the majority group shared by 37+ siblings, confirming a single builder pipeline with per-sample payload customization. ^[pefile.txt:93].dataSHA-256795b3d29c47ca0fe79f7d0a07244a2b0c697b7fb8e624bfda0ba0f5fde5cbe5ais unique to this sample. ^[pefile.txt:155]- Import facade is identical to all siblings: GDI32 (6 GUI functions), USER32 (11 window/dialog functions), KERNEL32 (7 base functions including
LoadLibraryWandGetTickCount). No networking, crypto, or process APIs are imported statically. ^[pefile.txt:249-301] - PE checksum mismatch (
0x2FA78vs computed0x2dd5e) is intentional or a builder artifact; present across the entire cluster. ^[pefile.txt:65] blackmatterOpenCTI label is a false-positive family attribution. The binary is a reflective loader / dropper, not ransomware. ^[blackmatter]- Capa failed due to missing signature database in this environment. FLOSS invocation used incorrect CLI syntax. ^[capa.txt] ^[floss.txt]
How To Mess With It (Homelab Replication)
See the cluster-level replication notes on the blackmatter entity page. To reproduce a comparable binary:
- Compile a minimal PE32 GUI stub in MSVC 14.12 with POGO optimization
- Implement PEB-walking API resolution (no static imports beyond KERNEL32/GDI32/USER32 facade)
- Embed an encrypted payload in
.datawith a per-sample XOR-NOT cipher - Add CPUID + RDTSC anti-VM gate before decryption
- Run
capaagainst the result; should match the cluster's capability fingerprint once signatures are installed
Deployable Signatures
YARA Rule — BlackMatter Cluster PE32 Reflective Loader
rule BlackMatter_Loader_Cluster_PE32
{
meta:
description = "MSVC 14.12 reflective loader cluster (false-positive blackmatter label)"
author = "PacketPursuit"
date = "2026-09-03"
sha256 = "2e3876a4a2e1d7456dbc95a254b419de25a9b26d2bab3d98d8c9ff0faa43b48c"
cluster = "blackmatter-loader"
strings:
$mz = { 4D 5A }
$linker_14_12 = { 0E 0C }
$ts_2022_09_09 = { 65 96 1A 63 }
$peb_walk_gdi = "gdi32.dll" ascii
$peb_walk_user = "USER32.dll" ascii
$peb_walk_kernel = "KERNEL32.dll" ascii
condition:
$mz at 0 and
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
uint16(uint32(0x3C)+0x14) == 0xE0 and
uint8(uint32(0x3C)+0x5C) == 0x02 and
uint16(uint32(0x3C)+0x16) == 0x0006 and
uint32(uint32(0x3C)+0x40) == 0x631A9665 and
uint8(uint32(0x3C)+0x42) == 0x0E and
uint8(uint32(0x3C)+0x43) == 0x0C and
filesize < 200KB and
filesize > 120KB
}
Behavioral Hunt Query — KQL (Microsoft Defender / Sentinel)
DeviceProcessEvents
| where FileName endswith ".exe"
| where SHA256 startswith "2e3876a4" or
(FolderPath contains @"\AppData\Local\Temp\" and
InitiatingProcessFileName == @"wscript.exe" or InitiatingProcessFileName == @"cscript.exe")
| where ProcessCommandLine contains "rundll32" or ProcessCommandLine contains "regsvr32"
| summarize arg_min(Timestamp, *) by SHA256
Note: This query targets the Phorpiex delivery chain observed in sibling samples. The loader itself has no static command-line signature.
IOC List
| Indicator | Value | Type | Notes |
|---|---|---|---|
| SHA-256 | 2e3876a4a2e1d7456dbc95a254b419de25a9b26d2bab3d98d8c9ff0faa43b48c |
File | Primary sample |
| .text MD5 | cfbda2c44e51b3b0b00bcbbc767c62a2 |
Section hash | Majority group stub |
| .data SHA-256 | 795b3d29c47ca0fe79f7d0a07244a2b0c697b7fb8e624bfda0ba0f5fde5cbe5a |
Section hash | Per-sample payload |
| PE Checksum | 0x2FA78 |
PE header | Unique per sample |
| Compilation | 0x631A9665 (2022-09-09 01:27:01 UTC) |
Timestamp | Shared across all 38 siblings |
| XOR Key | 0x10035fff |
Crypto | Inferred from cluster decompilation |
| LCG Seeds | 0x19660d / 0x3c6ef35f |
PRNG | C2 URL generation (inferred) |
| ssdeep | 3072:M6glyuxE4GsUPnliByocWephIid7rXg0Tb5oZw3:M6gDBGpvEByocWeThJrwsqw |
Fuzzy hash | Sample-specific |
| tlsh | 87E37D21F213D0B3C83718F13736B572B39E8E6C19996947EAD80F59BCA58232F15993 |
Fuzzy hash | Sample-specific |
Behavioral Fingerprint Statement
This binary is a 150 KB PE32 GUI executable compiled with MSVC 14.12 on 2022-09-09. It imports only 24 functions across GDI32, USER32, and KERNEL32 — all GUI or base CRT functions. No networking, process injection, or cryptographic APIs are imported statically. At runtime, it walks the PEB InMemoryOrderModuleList to resolve ~30+ threat APIs by hashed export names, decrypts a 40 KB .data payload using an XOR-NOT cipher with key 0x10035fff, and reflectively maps the decrypted payload into RWX memory. Prior to decryption, it performs a CPUID hypervisor-bit check and an RDTSC timing gate to detect sandboxes. C2 URLs are generated at runtime using an LCG PRNG with seeds 0x19660d/0x3c6ef35f, preventing static extraction of network indicators. The PE checksum is intentionally mismatched (0x2FA78 vs computed 0x2dd5e).
Detection Signatures
- MITRE ATT&CK: T1055 (Process Injection — reflective PE loading), T1027 (Obfuscated Files or Information), T1497.001 (Virtualization/Sandbox Evasion — CPUID check), T1059.003 (Windows Command Shell — payload execution), T1071.001 (Application Layer Protocol — HTTP for C2), T1573 (Encrypted Channel — runtime C2 payload encryption)
- capa: Not available (signature database missing in environment). Capabilities inferred from cluster decompilation and pefile/rabin2 analysis.
- YARA:
PE_File_Generic(trivial hit) ^[yara.txt]
References
- blackmatter — cluster entity page with full build pattern, decompiled behavior, and all 37 prior siblings
- peb-walking-api-resolution — technique page for the PEB API resolution pattern
- xor-not-string-decryption — technique page for the XOR-NOT cipher
- phorpiex — delivery infrastructure (Phorpiex spam botnet)
- unattributed — umbrella entity for this loader family pending true family identification
- MalwareBazaar / abuse.ch artifact ID:
e6beab92-d576-4962-9b74-4dad26237207^[metadata.json]
Provenance
- Static analysis files generated by triage pipeline on 2026-05-29:
file.txt,pefile.txt,rabin2-info.txt,strings.txt,ssdeep.txt,tlsh.txt,yara.txt,exiftool.json,metadata.json,triage.json,capa.txt(failed — missing signatures),floss.txt(failed — incorrect CLI invocation). - This report written 2026-09-03 based on cluster analysis and static artifacts.
- No dynamic execution (CAPE skipped — no Windows guest available).