SHA-256:
31f5df22bbc18d0068ae3ca520e06a7826695718f5a3796dd1df450dfdf5f2e231f5df22 — Go PE64+ loader with OT-software filename masquerade
1. Build / RE
Toolchain: Go 1.25.4 (gc), CGO_ENABLED=0, GOARCH=amd64, GOOS=windows ^[strings.txt:1714]. Null PE timestamp (TimeDateStamp: 0x0) ^[pefile.txt:34]. Subsystem WINDOWS_GUI (0x2) ^[pefile.txt:65].
Obfuscation / anti-analysis:
- 92 randomized
main.*function names (e.g.main.hvkxnhsya,main.rnsmxgsxwdq,main.tdazpkajyhdph,main.xkxhgzjkneub) ^[strings.txt]. This matches the go-function-name-randomization technique observed across the unclassified-go-pe64 cluster. - No external module paths in strings; only standard-library Go paths (
net/http,crypto/tls,crypto/rsa,html/template) appear inside runtime panic/format strings ^[strings.txt:1644-1645]. Suggests-trimpathor minimal module naming. - IAT restricted to
kernel32.dll(43 imports) ^[pefile.txt:308-363] — networking and cryptography resolved at runtime via statically-linked Go stdlib, a hallmark of the golang-stealer-build-pattern.
PE structure:
- Nine sections:
.text,.rdata,.data,.pdata,.xdata,.idata,.reloc,.symtab,.rsrc^[pefile.txt:75-255]. .rsrccontains a six-icon PNG suite (16×16, 32×32, 64×64, 128×128, 256×256) ^[binwalk.txt:6-17]. Typical Explorer social-engineering adornment.- Authenticode security directory entry present (
VirtualAddress: 0x44B600,Size: 0x880) ^[pefile.txt:271-274], but the address lies past EOF (file size 0x24B800). No embedded certificate exists; entry is either a linker artifact or stripped post-build.
Code quality / notable functions:
main.tdazpkajyhdph(0x140097720) implements a PE parser: checksMZ(0x5A4D) andPE\0\0(0x4550) signatures, readse_lfanew, parsesIMAGE_FILE_HEADERfields (Machine, NumberOfSections, SizeOfOptionalHeader, Characteristics), and copies section table entries into a Go slice ^[r2:sym.main.tdazpkajyhdph].main.nyhfxyrvf(0x1400988A0) wrapsbufio.Scanner.Scan, suggesting line- or token-oriented parsing of an embedded config or second-stage payload ^[r2:sym.main.nyhfxyrvf].main.main(0x14009AD60) seedsmath/randwith hardcoded constants (0xdd7b17f80,0xa1b203eb3d1a0000), performs float-scaling operations, then dispatches to obfuscated subroutines ^[r2:sym.main.main]. The RNG scaffolding is consistent with runtime decision-making or key generation seen in sibling samples.
2. Deploy / ATT&CK
Static-only inference — CAPE skipped due to no Windows guest ^[dynamic-analysis.md].
Initial Access / Execution:
- T1204.002 — Malicious Link: filename
cx-programmer 9.1 free download full.exemasquerades as OMRON CX-Programmer, a widely used PLC engineering suite. This is an OT-software lure distinct from the usual business-document filenames ^[triage.json]. - T1036.005 — Masquerading: the icon suite and filename together impersonate legitimate industrial software.
Defense Evasion:
- T1027.002 — Obfuscated Files or Information: randomized
main.*function names and null PE timestamp strip developer identity and hinder static clustering. - T1027.009 — Embedded Payloads: the PE parser (
main.tdazpkajyhdph) and scanner (main.nyhfxyrvf) suggest an embedded resource or appended payload is parsed at runtime. No cleartext payload marker found in strings.
Command and Control (inferred):
- T1071.001 — Application Layer Protocol: Web — standard-library
net/httppresent ^[strings.txt:1644]. - T1573.002 — Encrypted Channel:
crypto/tlsandcrypto/rsapresent in stdlib strings ^[strings.txt:1644]. No pinned certificate or C2 URL recovered statically; C2 likely runtime-resolved or decoded via the RNG-seeded routine.
Persistence / Impact:
- No static evidence of registry persistence, scheduled tasks, or service installation. The binary may be a single-stage dropper that unpacks and executes a second payload in memory.
3. Attribution / Family Linkage
- OpenCTI label
de-pumped/depumpedis an umbrella tag with no independent technical fingerprint ^[entities/depumped.md]. The actual technical family is unclassified-go-pe64 Cluster A (randomized-function-name builds). - Build artefacts match the golang-stealer-build-pattern: Go 1.25.4, CGO disabled, randomized
main.*names, kernel32-only IAT,.rsrcicon suite, null timestamp. - The OT-software lure (
cx-programmer) is a new targeting vector not observed in prior siblings, which used generic business-document or software-installer filenames.
Capabilities Summary
- go-pe-parser-runtime
- math-rand-seeded-runtime-decision
- bufio-scanner-config-parse
- ot-software-filename-masquerade
- icon-suite-social-engineering
- kernel32-only-iat
- golang-stdlib-networking-tls
- null-pe-timestamp