typeanalysisfamilyblackmatterconfidencehighcreated2026-07-29updated2026-07-29pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 34ca794e716157290147b180a0d65d47ddf6dedde646957324d40bf299289294

blackmatter: 34ca794e — Eleventh confirmed MSVC 14.12 reflective-loader sibling

Executive Summary

Eleventh confirmed sibling of the MSVC 14.12 PE32 reflective-loader cluster (see 136b5750 primary analysis). Identical stub template — same compilation timestamp, same linker, same .text section hash, same XOR-NOT alphabet cipher, same PEB-walking API resolution, same CPUID anti-VM gate. Only delta is individualized .data payload and a unique PE checksum (0x00026DC4). OpenCTI labels: dropped-by-phorpiex, exe. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 34ca794e716157290147b180a0d65d47ddf6dedde646957324d40bf299289294
Size 149,504 bytes (146 KB) ^[file.txt]
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:46] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI housekeeping ^[pefile.txt:249]
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 — identical to all ten prior siblings ^[pefile.txt:93]
PE checksum 0x00026DC4 — unique to this sample ^[pefile.txt:65]
YARA Generic PE only (PE_File_Generic) ^[yara.txt]

How It Works

This sample is a cluster sibling, not a new family. All threat logic, anti-analysis, API resolution, and C2 behaviour is documented in the primary analysis at [unattributed](/intel/families/unattributed.html) and [blackmatter](/intel/families/blackmatter.html). The per-sample delta is limited to:

  1. PE checksum — 0x00026DC4 (hdr.csum) vs 0x0002BC5A on 136b5750, 0x0002F55C on 21b12514, 0x0002A237 on dc870a75, 0x000306CE on 73841818, 0x0002FF42 on 0017ecc5 ^[pefile.txt:65]
  2. .data and .pdata section contents — individualized encrypted payload and unwind info; entropy remains high (7.987 for .data, 7.325 for .pdata) ^[pefile.txt:152] ^[pefile.txt:172]
  3. No new C2 strings — static extraction yields the same alphabet-cipher fragments (ABCD, EFGH, IJKL, etc.) used by the XOR-NOT decoder ^[strings.txt:45]

The entry-point stub at RVA 0x1946f delegates to the runtime orchestrator (same as cluster), which then:

  • Walks the PEB InMemoryOrderModuleList to resolve ~30+ threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) ^[r2:fcn.00417034]
  • Decrypts embedded strings via XOR-NOT against a hardcoded alphabet table ^[r2:fcn.00401180]
  • Spawns file-system enumeration and network C2 threads ^[r2:fcn.00417034]
  • Performs reflective PE loading via VirtualAlloc + WriteProcessMemory + VirtualProtect pattern ^[r2:fcn.00406668]

Refer to [blackmatter](/intel/families/blackmatter.html) cluster page and [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html) technique page for full decompiled behaviour, slot tables, and ATT&CK mappings.

Decompiled Behavior

Not re-derived — this sample uses the identical stub to 136b5750. The decompiled orchestrator (fcn.00417034), PEB-walker, XOR-NOT cipher (fcn.00401180), and thread spawner are byte-for-byte equivalent in .text. Any analysis of runtime behaviour from this sample will produce the same result as the primary report.

C2 Infrastructure

No new static C2 indicators. The encrypted payload in .data is unique to this sample; C2 host/port would be decoded at runtime by the same LCG PRNG + XOR-NOT chain documented in [blackmatter](/intel/families/blackmatter.html).

Interesting Tidbits

  • Eleventh sibling — this pushes the confirmed cluster to eleven samples, all sharing the identical .text hash and compilation timestamp. The builder pipeline is clearly mass-producing individualized payloads from a shared stub template. ^[pefile.txt:93]
  • ssdeep similarity — Y6gDBGpvEByocWeFy7Sy4pj+eL block matches the cluster signature; only the tail changes with .data content. ^[ssdeep.txt:2]

How To Mess With It (Homelab Replication)

Refer to the primary analysis at [blackmatter](/intel/families/blackmatter.html) and [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html) for build recipes. The stub is MSVC 14.12 POGO-optimized; the payload is injected as raw encrypted bytes into .data during the build pipeline.

Deployable Signatures

YARA Rule — Cluster Stub Fingerprint

rule msvc_pogo_reflective_loader_cluster {
    meta:
        description = "MSVC 14.12 POGO reflective-loader cluster (unattributed / blackmatter-tagged)"
        author = "PacketPursuit"
        date = "2026-07-29"
        reference = "/intel/analyses/34ca794e716157290147b180a0d65d47ddf6dedde646957324d40bf299289294.html"
    strings:
        $mz = { 4D 5A }
        $text_hash = { cfbda2c44e51b3b0b00bcbbc767c62a2 }
        $alphabet1 = "ABCD" ascii
        $alphabet2 = "EFGH" ascii
        $alphabet3 = "IJKL" ascii
        $alphabet4 = "MNOP" ascii
        $alphabet5 = "QRST" ascii
        $alphabet6 = "UVWX" ascii
        $alphabet7 = "YZab" ascii
        $alphabet8 = "cdef" ascii
        $alphabet9 = "ghij" ascii
        $alphabet10 = "klmn" ascii
        $alphabet11 = "opqr" ascii
        $alphabet12 = "stuv" ascii
        $alphabet13 = "wxyz" ascii
        $alphabet14 = "0123" ascii
        $alphabet15 = "4567" ascii
        $alphabet16 = "89+/" ascii
        $peb_walk_stub = { 64 A1 30 00 00 00 }
        $pogo_debug = { 0D 00 00 00 F4 00 00 00 }
    condition:
        $mz at 0 and
        uint16(0x5C) == 0x80 and
        uint32(0x80) == 0x4550 and
        uint16(0x18A) == 0x0006 and
        uint32(0x88) == 0x631A9665 and
        uint16(0x9A) == 0x0E0C and
        uint32(0xD8) == 0x00026DC4 or uint32(0xD8) == 0x0002BC5A or uint32(0xD8) == 0x0002F55C or uint32(0xD8) == 0x0002A237 or uint32(0xD8) == 0x000306CE or uint32(0xD8) == 0x0002FF42 and
        5 of ($alphabet*) and
        $peb_walk_stub and
        $pogo_debug
}

Note: The .text section hash condition cannot be expressed directly in YARA; use the compilation timestamp + linker version + PE checksum whitelist as a proxy. For hunting, target the alphabet-string constellation + POGO debug + PEB-walk stub.

IOC List

Indicator Value Type
SHA-256 34ca794e716157290147b180a0d65d47ddf6dedde646957324d40bf299289294 hash
PE Timestamp 0x631A9665 (Fri Sep 9 01:27:01 2022) compile-time
Linker Version 14.12 (VS 2017 15.5+) toolchain
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 section hash
PE Checksum 0x00026DC4 unique delta
Known checksums 0x0002BC5A, 0x0002F55C, 0x0002A237, 0x000306CE, 0x0002FF42 cluster variants

Behavioral Fingerprint

A PE32 GUI binary compiled with MSVC 14.12 on 2022-09-09, carrying POGO debug info, minimal static imports (only GDI32/USER32/KERNEL32 GUI functions), and a high-entropy .data section (~7.99). At runtime it resolves VirtualAlloc, CreateThread, InternetOpen, and CryptAcquireContext via PEB-walking, decrypts C2 strings with a XOR-NOT alphabet cipher, and spawns threads for file-system enumeration and HTTP POST C2 communication. The .text section is bit-for-bit identical across at least eleven samples — only .data payload and PE checksum vary.

Detection Signatures

  • capa signatures failed (missing signature database) ^[capa.txt]
  • floss signatures failed (bad argument invocation) ^[floss.txt]
  • Static-only inference pending CAPE Windows guest availability.

References

  • Artifact ID: e4fd5264-ca55-4d82-b265-831bf448f874 ^[metadata.json]
  • Primary cluster analysis: [blackmatter](/intel/families/blackmatter.html)
  • Technique page: [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html)
  • Sibling reports: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html, /intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html, /intel/analyses/dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4.html, /intel/analyses/73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729.html, /intel/analyses/0017ecc5f6c73be23b7575057c8e16b4e8a24723d8409420257144a0c7f6d575.html

Provenance

  • file.txt — file(1) output
  • exiftool.json — ExifTool PE metadata
  • pefile.txt — pefile.py full header/section/import dump
  • rabin2-info.txt — radare2 binary summary (rabin2 -I)
  • strings.txt — GNU strings output
  • ssdeep.txt — ssdeep fuzzy hash
  • yara.txt — YARA scan results
  • binwalk.txt — Binwalk embedded-artefact scan
  • capa.txt — Mandiant capa output (failed — missing sigs)
  • floss.txt — FireEye flare-floss output (failed — bad args)
  • dynamic-analysis.md — CAPE sandbox summary (skipped — no Windows guest)
  • Radare2 analysis — r2 level-3 auto-analysis, 519 functions discovered