typeanalysisfamilyblackmatterconfidencehighcreated2026-08-30updated2026-08-30pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8

blackmatter: 34f9b16d — 35th confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x31f6e

Executive Summary

Thirty-fifth confirmed sibling in the MSVC 14.12 reflective-loader cluster first documented at 136b5750. Identical encrypted .text stub (SHA-256 000a9a8b...), identical XOR-NOT cipher (0x10035fff), identical compilation timestamp (0x631A9665 — Fri Sep 9 01:27:01 2022 UTC), and identical PEB-walking API resolution template. The .data section carries an individualized encrypted payload (SHA-256 58c7f053...), confirming per-sample customization in a builder pipeline. Tagged dropped-by-phorpiex and blackmatter by OpenCTI. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:34] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal facade — GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt:249]
YARA Generic PE only; no family-specific hits ^[yara.txt]
PE Checksum (stored) 0x31f6e
PE Checksum (computed) 0x30257 — mismatch indicates post-build modification or builder artifact
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 — matches cluster majority group
.data SHA-256 58c7f053f29d7180ea7cf77222e1588e36b3c10b6af3fef56a2e3e5fceebc59c — unique to this sample

How It Works

This sample is structurally identical to the cluster described in the primary analysis at 136b5750 and the cluster entity page blackmatter. No new functional deltas were observed. For full behavioral details see:

  • /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
  • blackmatter — cluster entity page with 34 prior siblings

Cluster-Fingerprint Confirmation

  1. Encrypted entry point: The byte at 0x1946F (declared AddressOfEntryPoint) is 0xc4 — not a valid x86 instruction start. Actual code is decrypted in-memory at runtime. ^[r2:entry0]

  2. Encrypted .text: First 32 bytes of .text at file offset 0x400 are ff 5f 03 11 55 8b ec 51 ... — decrypt to standard x86 prologue sequences after XOR-NOT cipher with key 0x10035fff. ^[pefile.txt:93]

  3. XOR-NOT alphabet cipher: Same two-step transform (^ 0x10035fff then ~ / bitwise NOT) observed across all 34 prior siblings. Encrypted alphabet table yields the same 62-character ordered alphabet: ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789. ^[strings.txt:43]

  4. PEB-walking API resolution: No threat APIs in static import table. All ~30+ APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) resolved at runtime by walking PEB InMemoryOrderModuleList and hashing export names. Resolved pointers cached in .data pseudo-import slots. ^[r2:fcn.00405aec]

  5. Anti-VM: CPUID leaf 1 ECX bit 31 (hypervisor present) + CPUID leaf 7 EBX bit 18 + RDTSC differential timing gate with 13-bit rotate. ^[r2:fcn.004010bc]

  6. LCG PRNG C2 URL generation: Same linear congruential generator constants (a = 0x19660d, c = 0x3c6ef35f) used to generate pseudo-random C2 domain names character-by-character from the alphabet table. ^[r2:fcn.0040110c]

  7. HTTP POST C2: Same encrypted wide-character fragments decoding to "POST" at runtime, confirming HTTP POST as the C2 verb. ^[r2:fcn.0040cfcc]

C2 Infrastructure

No static C2 strings recoverable — host names and URLs generated at runtime via the LCG PRNG + alphabet table. The C2 is ephemeral and reconstructed on each execution. See the primary 136b5750 analysis for the reconstruction algorithm.

Interesting Tidbits

  • blackmatter label present — both blackmatter and dropped-by-phorpiex tags carried, consistent with siblings 24–30, 33–34. ^[metadata.json]
  • Individualized .data payload: The .data section hash is unique, confirming the builder pipeline customizes the encrypted payload per sample while sharing the stub. The .text section is byte-identical across all 35 siblings — a strong builder-template fingerprint.
  • PE checksum mismatch: Stored checksum 0x31f6e does not match computed 0x30257, indicating post-build modification or builder artifact. This is a useful cluster detection heuristic when .text is encrypted and standard checksum verification fails. ^[pefile.txt:65]
  • Section layout invariant: All 35 siblings share the exact same 6-section layout (.text, .itext, .rdata, .data, .pdata, .reloc) with identical virtual addresses and nearly identical sizes. The only per-sample variance is in .data and .pdata contents.

How To Mess With It (Homelab Replication)

See the primary 136b5750 analysis and the peb-walking-api-resolution technique page. To replicate the stub:

  1. Compile a minimal PE32 GUI in MSVC 2017 15.5+ with POGO enabled.
  2. Strip all imports except GDI32/USER32/KERNEL32 GUI functions.
  3. Embed a PEB-walker that resolves VirtualAlloc, CreateThread, InternetOpen, etc. by export hash.
  4. Encrypt the .text section with XOR-NOT (key = 0x10035fff), storing the decryptor in .itext.
  5. Embed an individualized payload in .data encrypted with the same cipher.
  6. Add CPUID anti-VM and RDTSC timing gate at entry.
  7. Verify: run capa on the reproducer — should hit the same TTPs as the cluster.

Deployable Signatures

YARA Rule — MSVC 14.12 Reflective Loader Cluster

rule BlackMatter_ReflectiveLoader_Cluster
{
    meta:
        description = "MSVC 14.12 PEB-walking reflective-loader cluster (blackmatter/unattributed)"
        author = "PacketPursuit"
        date = "2026-08-30"
        hash1 = "34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8"
        hash2 = "06fe6a157bd3f67ae9f7cdf3478a0db670c2772b584cae5900d2473b6b109bb7"
        hash3 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
        version = "3.5"
    strings:
        $s_text_hash = { 00 0a 9a 8b 14 40 e4 4c de 00 fd 7a cc 5b dd a6 }
        $s_xor_key = { ff 5f 03 11 }
        $s_alpha1 = "ABCD" ascii wide
        $s_alpha2 = "EFGH" ascii wide
        $s_alpha3 = "IJKL" ascii wide
        $s_alpha4 = "MNOP" ascii wide
        $s_alpha5 = "QRST" ascii wide
        $s_alpha6 = "UVWX" ascii wide
        $s_alpha7 = "YZab" ascii wide
        $s_alpha8 = "cdef" ascii wide
        $s_alpha9 = "ghij" ascii wide
        $s_alpha10 = "klmn" ascii wide
        $s_alpha11 = "opqr" ascii wide
        $s_alpha12 = "stuv" ascii wide
        $s_alpha13 = "wxyz" ascii wide
        $imp_gdi = "gdi32.dll" ascii wide
        $imp_user = "USER32.dll" ascii wide
        $imp_kernel = "KERNEL32.dll" ascii wide
        $poi1 = "CreateSolidBrush" ascii wide
        $poi2 = "GetDeviceCaps" ascii wide
        $poi3 = "SetPixel" ascii wide
        $poi4 = "DialogBoxParamW" ascii wide
        $poi5 = "GetKeyNameTextW" ascii wide
        $poi6 = "LoadLibraryW" ascii wide
        $poi7 = "GetTickCount" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x18) == 0x010B and
        uint16(uint32(0x3C)+0x40) == 0x0002 and
        uint16(uint32(0x3C)+0x14) == 0x00E0 and
        uint16(uint32(0x3C)+0x14+0x02) == 0x0102 and
        uint16(uint32(0x3C)+0x40+0x06) == 0x8140 and
        uint8(uint32(0x3C)+0x18+0x02) == 0x0E and
        uint8(uint32(0x3C)+0x18+0x03) == 0x0C and
        uint32(uint32(0x3C)+0x08) == 0x631A9665 and
        ($s_xor_key at 0x400 or $s_xor_key at 0x401 or $s_xor_key at 0x402 or $s_xor_key at 0x403) and
        3 of ($s_alpha*) and
        all of ($imp_*) and
        5 of ($poi*) and
        uint16(uint32(0x3C)+0x06) == 6
}

IOC List

Indicator Value Type
SHA-256 34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8 File hash
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 Section hash (cluster match)
.data SHA-256 58c7f053f29d7180ea7cf77222e1588e36b3c10b6af3fef56a2e3e5fceebc59c Section hash (unique payload)
PE Checksum (stored) 0x31f6e PE header
PE Checksum (computed) 0x30257 Mismatch indicates post-build modification
Compilation timestamp 0x631A9665 (Fri Sep 9 01:27:01 2022 UTC) Builder artifact
XOR cipher key 0x10035fff Decryption key
LCG multiplier 0x19660d PRNG constant
LCG increment 0x3c6ef35f PRNG constant

Behavioral Fingerprint

This binary is a 150 KB PE32 GUI with MSVC 14.12 linker signature, POGO optimization, six standard sections, and a minimal import facade (25 total imports across GDI32/USER32/KERNEL32, all GUI housekeeping). The .text section is encrypted and only decrypts at runtime via an XOR-NOT cipher with key 0x10035fff. The entry point is a single encrypted byte (0xc4). At runtime, the stub walks the PEB InMemoryOrderModuleList to resolve ~30 threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) by export hash, caching pointers in a pseudo-import table in .data. It performs CPUID hypervisor-bit checks and RDTSC differential timing before spawning worker threads for file-system enumeration and HTTP POST C2 communication. C2 URLs are generated on-the-fly via an LCG PRNG with constants 0x19660d/0x3c6ef35f indexing a 62-character alphabet table. No static C2 strings exist. The .data section carries a per-sample individualized encrypted payload. This is a builder-template malware, not a hand-crafted binary.

Detection Signatures

ATT&CK ID Technique Evidence
T1620 Reflective Code Loading PEB-walking API resolution -> VirtualAlloc -> section mapping -> in-memory execution ^[r2:fcn.00417034]
T1055 Process Injection VirtualAlloc + WriteProcessMemory + VirtualProtect + CreateRemoteThread / ResumeThread ^[r2:fcn.00417034]
T1059 Command and Scripting Interpreter Worker threads spawn child processes with command-line arguments ^[r2:fcn.00417034]
T1083 File and Directory Discovery Recursive FindFirstFileA / FindNextFileA with * wildcard in dedicated thread ^[r2:fcn.00407468]
T1071.001 Application Layer Protocol: Web Protocols HTTP POST C2 with WinInet API handles ^[r2:fcn.0040782c]
T1573.001 Encrypted Channel: Symmetric Cryptography Payload encrypted with XOR-NOT cipher; C2 body encrypted with CryptEncrypt ^[r2:fcn.00401240]
T1497.001 Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit check + RDTSC timing gate ^[r2:fcn.004010bc]
T1027.002 Obfuscated Files or Information: Software Packing In-place .text decryption; encrypted entry point ^[pefile.txt:93]
T1070.004 Indicator Removal: File Deletion Self-erasure routine referenced in thread worker ^[r2:fcn.0040782c]

References

  • Primary analysis: 136b5750 — /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Cluster entity: blackmatter
  • Umbrella entity: unattributed
  • Technique page: peb-walking-api-resolution
  • Technique page: prng-seeded-c2-url-decoding
  • OpenCTI artifact ID: c3ddfe90-cb14-403c-abb7-3ff47e52608e
  • MalwareBazaar: 34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile Python module
  • rabin2-info.txt — radare2 rabin2 -I
  • exiftool.json — ExifTool 12.76
  • strings.txt — strings(1)
  • yara.txt — YARA
  • metadata.json — OpenCTI connector artifact metadata
  • r2:fcn.* — radare2 5.x analysis (level 2), 517 functions found
  • .text/.data section hashes computed with Python hashlib.sha256
  • Cross-sibling comparison against prior 34 cluster analyses via grep on wiki/wiki/raw/analyses/*/report.md