34ca794e716157290147b180a0d65d47ddf6dedde646957324d40bf299289294blackmatter: 34ca794e — Eleventh confirmed MSVC 14.12 reflective-loader sibling
Executive Summary
Eleventh confirmed sibling of the MSVC 14.12 PE32 reflective-loader cluster (see 136b5750 primary analysis). Identical stub template — same compilation timestamp, same linker, same .text section hash, same XOR-NOT alphabet cipher, same PEB-walking API resolution, same CPUID anti-VM gate. Only delta is individualized .data payload and a unique PE checksum (0x00026DC4). OpenCTI labels: dropped-by-phorpiex, exe. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 34ca794e716157290147b180a0d65d47ddf6dedde646957324d40bf299289294 |
| Size | 149,504 bytes (146 KB) ^[file.txt] |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:46] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI housekeeping ^[pefile.txt:249] |
.text MD5 |
cfbda2c44e51b3b0b00bcbbc767c62a2 — identical to all ten prior siblings ^[pefile.txt:93] |
| PE checksum | 0x00026DC4 — unique to this sample ^[pefile.txt:65] |
| YARA | Generic PE only (PE_File_Generic) ^[yara.txt] |
How It Works
This sample is a cluster sibling, not a new family. All threat logic, anti-analysis, API resolution, and C2 behaviour is documented in the primary analysis at [unattributed](/intel/families/unattributed.html) and [blackmatter](/intel/families/blackmatter.html). The per-sample delta is limited to:
- PE checksum —
0x00026DC4(hdr.csum) vs0x0002BC5Aon136b5750,0x0002F55Con21b12514,0x0002A237ondc870a75,0x000306CEon73841818,0x0002FF42on0017ecc5^[pefile.txt:65] .dataand.pdatasection contents — individualized encrypted payload and unwind info; entropy remains high (7.987for.data,7.325for.pdata) ^[pefile.txt:152] ^[pefile.txt:172]- No new C2 strings — static extraction yields the same alphabet-cipher fragments (
ABCD,EFGH,IJKL, etc.) used by the XOR-NOT decoder ^[strings.txt:45]
The entry-point stub at RVA 0x1946f delegates to the runtime orchestrator (same as cluster), which then:
- Walks the PEB
InMemoryOrderModuleListto resolve ~30+ threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) ^[r2:fcn.00417034] - Decrypts embedded strings via XOR-NOT against a hardcoded alphabet table ^[r2:fcn.00401180]
- Spawns file-system enumeration and network C2 threads ^[r2:fcn.00417034]
- Performs reflective PE loading via VirtualAlloc + WriteProcessMemory + VirtualProtect pattern ^[r2:fcn.00406668]
Refer to [blackmatter](/intel/families/blackmatter.html) cluster page and [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html) technique page for full decompiled behaviour, slot tables, and ATT&CK mappings.
Decompiled Behavior
Not re-derived — this sample uses the identical stub to 136b5750. The decompiled orchestrator (fcn.00417034), PEB-walker, XOR-NOT cipher (fcn.00401180), and thread spawner are byte-for-byte equivalent in .text. Any analysis of runtime behaviour from this sample will produce the same result as the primary report.
C2 Infrastructure
No new static C2 indicators. The encrypted payload in .data is unique to this sample; C2 host/port would be decoded at runtime by the same LCG PRNG + XOR-NOT chain documented in [blackmatter](/intel/families/blackmatter.html).
Interesting Tidbits
- Eleventh sibling — this pushes the confirmed cluster to eleven samples, all sharing the identical
.texthash and compilation timestamp. The builder pipeline is clearly mass-producing individualized payloads from a shared stub template. ^[pefile.txt:93] - ssdeep similarity —
Y6gDBGpvEByocWeFy7Sy4pj+eLblock matches the cluster signature; only the tail changes with.datacontent. ^[ssdeep.txt:2]
How To Mess With It (Homelab Replication)
Refer to the primary analysis at [blackmatter](/intel/families/blackmatter.html) and [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html) for build recipes. The stub is MSVC 14.12 POGO-optimized; the payload is injected as raw encrypted bytes into .data during the build pipeline.
Deployable Signatures
YARA Rule — Cluster Stub Fingerprint
rule msvc_pogo_reflective_loader_cluster {
meta:
description = "MSVC 14.12 POGO reflective-loader cluster (unattributed / blackmatter-tagged)"
author = "PacketPursuit"
date = "2026-07-29"
reference = "/intel/analyses/34ca794e716157290147b180a0d65d47ddf6dedde646957324d40bf299289294.html"
strings:
$mz = { 4D 5A }
$text_hash = { cfbda2c44e51b3b0b00bcbbc767c62a2 }
$alphabet1 = "ABCD" ascii
$alphabet2 = "EFGH" ascii
$alphabet3 = "IJKL" ascii
$alphabet4 = "MNOP" ascii
$alphabet5 = "QRST" ascii
$alphabet6 = "UVWX" ascii
$alphabet7 = "YZab" ascii
$alphabet8 = "cdef" ascii
$alphabet9 = "ghij" ascii
$alphabet10 = "klmn" ascii
$alphabet11 = "opqr" ascii
$alphabet12 = "stuv" ascii
$alphabet13 = "wxyz" ascii
$alphabet14 = "0123" ascii
$alphabet15 = "4567" ascii
$alphabet16 = "89+/" ascii
$peb_walk_stub = { 64 A1 30 00 00 00 }
$pogo_debug = { 0D 00 00 00 F4 00 00 00 }
condition:
$mz at 0 and
uint16(0x5C) == 0x80 and
uint32(0x80) == 0x4550 and
uint16(0x18A) == 0x0006 and
uint32(0x88) == 0x631A9665 and
uint16(0x9A) == 0x0E0C and
uint32(0xD8) == 0x00026DC4 or uint32(0xD8) == 0x0002BC5A or uint32(0xD8) == 0x0002F55C or uint32(0xD8) == 0x0002A237 or uint32(0xD8) == 0x000306CE or uint32(0xD8) == 0x0002FF42 and
5 of ($alphabet*) and
$peb_walk_stub and
$pogo_debug
}
Note: The .text section hash condition cannot be expressed directly in YARA; use the compilation timestamp + linker version + PE checksum whitelist as a proxy. For hunting, target the alphabet-string constellation + POGO debug + PEB-walk stub.
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 34ca794e716157290147b180a0d65d47ddf6dedde646957324d40bf299289294 |
hash |
| PE Timestamp | 0x631A9665 (Fri Sep 9 01:27:01 2022) |
compile-time |
| Linker Version | 14.12 (VS 2017 15.5+) | toolchain |
.text MD5 |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
section hash |
| PE Checksum | 0x00026DC4 |
unique delta |
| Known checksums | 0x0002BC5A, 0x0002F55C, 0x0002A237, 0x000306CE, 0x0002FF42 |
cluster variants |
Behavioral Fingerprint
A PE32 GUI binary compiled with MSVC 14.12 on 2022-09-09, carrying POGO debug info, minimal static imports (only GDI32/USER32/KERNEL32 GUI functions), and a high-entropy .data section (~7.99). At runtime it resolves VirtualAlloc, CreateThread, InternetOpen, and CryptAcquireContext via PEB-walking, decrypts C2 strings with a XOR-NOT alphabet cipher, and spawns threads for file-system enumeration and HTTP POST C2 communication. The .text section is bit-for-bit identical across at least eleven samples — only .data payload and PE checksum vary.
Detection Signatures
- capa signatures failed (missing signature database) ^[capa.txt]
- floss signatures failed (bad argument invocation) ^[floss.txt]
- Static-only inference pending CAPE Windows guest availability.
References
- Artifact ID:
e4fd5264-ca55-4d82-b265-831bf448f874^[metadata.json] - Primary cluster analysis:
[blackmatter](/intel/families/blackmatter.html) - Technique page:
[peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html) - Sibling reports:
/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html,/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html,/intel/analyses/dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4.html,/intel/analyses/73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729.html,/intel/analyses/0017ecc5f6c73be23b7575057c8e16b4e8a24723d8409420257144a0c7f6d575.html
Provenance
file.txt— file(1) outputexiftool.json— ExifTool PE metadatapefile.txt— pefile.py full header/section/import dumprabin2-info.txt— radare2 binary summary (rabin2 -I)strings.txt— GNU strings outputssdeep.txt— ssdeep fuzzy hashyara.txt— YARA scan resultsbinwalk.txt— Binwalk embedded-artefact scancapa.txt— Mandiant capa output (failed — missing sigs)floss.txt— FireEye flare-floss output (failed — bad args)dynamic-analysis.md— CAPE sandbox summary (skipped — no Windows guest)- Radare2 analysis —
r2level-3 auto-analysis, 519 functions discovered