34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8blackmatter: 34f9b16d — 35th confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x31f6e
Executive Summary
Thirty-fifth confirmed sibling in the MSVC 14.12 reflective-loader cluster first documented at 136b5750. Identical encrypted .text stub (SHA-256 000a9a8b...), identical XOR-NOT cipher (0x10035fff), identical compilation timestamp (0x631A9665 — Fri Sep 9 01:27:01 2022 UTC), and identical PEB-walking API resolution template. The .data section carries an individualized encrypted payload (SHA-256 58c7f053...), confirming per-sample customization in a builder pipeline. Tagged dropped-by-phorpiex and blackmatter by OpenCTI. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8 |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:34] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal facade — GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt:249] |
| YARA | Generic PE only; no family-specific hits ^[yara.txt] |
| PE Checksum (stored) | 0x31f6e |
| PE Checksum (computed) | 0x30257 — mismatch indicates post-build modification or builder artifact |
| .text SHA-256 | 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 — matches cluster majority group |
| .data SHA-256 | 58c7f053f29d7180ea7cf77222e1588e36b3c10b6af3fef56a2e3e5fceebc59c — unique to this sample |
How It Works
This sample is structurally identical to the cluster described in the primary analysis at 136b5750 and the cluster entity page blackmatter. No new functional deltas were observed. For full behavioral details see:
- /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
- blackmatter — cluster entity page with 34 prior siblings
Cluster-Fingerprint Confirmation
-
Encrypted entry point: The byte at
0x1946F(declared AddressOfEntryPoint) is0xc4— not a valid x86 instruction start. Actual code is decrypted in-memory at runtime. ^[r2:entry0] -
Encrypted
.text: First 32 bytes of.textat file offset0x400areff 5f 03 11 55 8b ec 51 ...— decrypt to standard x86 prologue sequences after XOR-NOT cipher with key0x10035fff. ^[pefile.txt:93] -
XOR-NOT alphabet cipher: Same two-step transform (
^ 0x10035fffthen~/ bitwise NOT) observed across all 34 prior siblings. Encrypted alphabet table yields the same 62-character ordered alphabet:ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789. ^[strings.txt:43] -
PEB-walking API resolution: No threat APIs in static import table. All ~30+ APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) resolved at runtime by walking PEB InMemoryOrderModuleList and hashing export names. Resolved pointers cached in
.datapseudo-import slots. ^[r2:fcn.00405aec] -
Anti-VM: CPUID leaf 1 ECX bit 31 (hypervisor present) + CPUID leaf 7 EBX bit 18 + RDTSC differential timing gate with 13-bit rotate. ^[r2:fcn.004010bc]
-
LCG PRNG C2 URL generation: Same linear congruential generator constants (
a = 0x19660d,c = 0x3c6ef35f) used to generate pseudo-random C2 domain names character-by-character from the alphabet table. ^[r2:fcn.0040110c] -
HTTP POST C2: Same encrypted wide-character fragments decoding to
"POST"at runtime, confirming HTTP POST as the C2 verb. ^[r2:fcn.0040cfcc]
C2 Infrastructure
No static C2 strings recoverable — host names and URLs generated at runtime via the LCG PRNG + alphabet table. The C2 is ephemeral and reconstructed on each execution. See the primary 136b5750 analysis for the reconstruction algorithm.
Interesting Tidbits
blackmatterlabel present — bothblackmatteranddropped-by-phorpiextags carried, consistent with siblings 24–30, 33–34. ^[metadata.json]- Individualized
.datapayload: The.datasection hash is unique, confirming the builder pipeline customizes the encrypted payload per sample while sharing the stub. The.textsection is byte-identical across all 35 siblings — a strong builder-template fingerprint. - PE checksum mismatch: Stored checksum
0x31f6edoes not match computed0x30257, indicating post-build modification or builder artifact. This is a useful cluster detection heuristic when.textis encrypted and standard checksum verification fails. ^[pefile.txt:65] - Section layout invariant: All 35 siblings share the exact same 6-section layout (
.text,.itext,.rdata,.data,.pdata,.reloc) with identical virtual addresses and nearly identical sizes. The only per-sample variance is in.dataand.pdatacontents.
How To Mess With It (Homelab Replication)
See the primary 136b5750 analysis and the peb-walking-api-resolution technique page. To replicate the stub:
- Compile a minimal PE32 GUI in MSVC 2017 15.5+ with POGO enabled.
- Strip all imports except GDI32/USER32/KERNEL32 GUI functions.
- Embed a PEB-walker that resolves VirtualAlloc, CreateThread, InternetOpen, etc. by export hash.
- Encrypt the
.textsection with XOR-NOT (key = 0x10035fff), storing the decryptor in.itext. - Embed an individualized payload in
.dataencrypted with the same cipher. - Add CPUID anti-VM and RDTSC timing gate at entry.
- Verify: run
capaon the reproducer — should hit the same TTPs as the cluster.
Deployable Signatures
YARA Rule — MSVC 14.12 Reflective Loader Cluster
rule BlackMatter_ReflectiveLoader_Cluster
{
meta:
description = "MSVC 14.12 PEB-walking reflective-loader cluster (blackmatter/unattributed)"
author = "PacketPursuit"
date = "2026-08-30"
hash1 = "34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8"
hash2 = "06fe6a157bd3f67ae9f7cdf3478a0db670c2772b584cae5900d2473b6b109bb7"
hash3 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
version = "3.5"
strings:
$s_text_hash = { 00 0a 9a 8b 14 40 e4 4c de 00 fd 7a cc 5b dd a6 }
$s_xor_key = { ff 5f 03 11 }
$s_alpha1 = "ABCD" ascii wide
$s_alpha2 = "EFGH" ascii wide
$s_alpha3 = "IJKL" ascii wide
$s_alpha4 = "MNOP" ascii wide
$s_alpha5 = "QRST" ascii wide
$s_alpha6 = "UVWX" ascii wide
$s_alpha7 = "YZab" ascii wide
$s_alpha8 = "cdef" ascii wide
$s_alpha9 = "ghij" ascii wide
$s_alpha10 = "klmn" ascii wide
$s_alpha11 = "opqr" ascii wide
$s_alpha12 = "stuv" ascii wide
$s_alpha13 = "wxyz" ascii wide
$imp_gdi = "gdi32.dll" ascii wide
$imp_user = "USER32.dll" ascii wide
$imp_kernel = "KERNEL32.dll" ascii wide
$poi1 = "CreateSolidBrush" ascii wide
$poi2 = "GetDeviceCaps" ascii wide
$poi3 = "SetPixel" ascii wide
$poi4 = "DialogBoxParamW" ascii wide
$poi5 = "GetKeyNameTextW" ascii wide
$poi6 = "LoadLibraryW" ascii wide
$poi7 = "GetTickCount" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
uint16(uint32(0x3C)+0x18) == 0x010B and
uint16(uint32(0x3C)+0x40) == 0x0002 and
uint16(uint32(0x3C)+0x14) == 0x00E0 and
uint16(uint32(0x3C)+0x14+0x02) == 0x0102 and
uint16(uint32(0x3C)+0x40+0x06) == 0x8140 and
uint8(uint32(0x3C)+0x18+0x02) == 0x0E and
uint8(uint32(0x3C)+0x18+0x03) == 0x0C and
uint32(uint32(0x3C)+0x08) == 0x631A9665 and
($s_xor_key at 0x400 or $s_xor_key at 0x401 or $s_xor_key at 0x402 or $s_xor_key at 0x403) and
3 of ($s_alpha*) and
all of ($imp_*) and
5 of ($poi*) and
uint16(uint32(0x3C)+0x06) == 6
}
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8 |
File hash |
| .text SHA-256 | 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
Section hash (cluster match) |
| .data SHA-256 | 58c7f053f29d7180ea7cf77222e1588e36b3c10b6af3fef56a2e3e5fceebc59c |
Section hash (unique payload) |
| PE Checksum (stored) | 0x31f6e |
PE header |
| PE Checksum (computed) | 0x30257 |
Mismatch indicates post-build modification |
| Compilation timestamp | 0x631A9665 (Fri Sep 9 01:27:01 2022 UTC) |
Builder artifact |
| XOR cipher key | 0x10035fff |
Decryption key |
| LCG multiplier | 0x19660d |
PRNG constant |
| LCG increment | 0x3c6ef35f |
PRNG constant |
Behavioral Fingerprint
This binary is a 150 KB PE32 GUI with MSVC 14.12 linker signature, POGO optimization, six standard sections, and a minimal import facade (25 total imports across GDI32/USER32/KERNEL32, all GUI housekeeping). The .text section is encrypted and only decrypts at runtime via an XOR-NOT cipher with key 0x10035fff. The entry point is a single encrypted byte (0xc4). At runtime, the stub walks the PEB InMemoryOrderModuleList to resolve ~30 threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) by export hash, caching pointers in a pseudo-import table in .data. It performs CPUID hypervisor-bit checks and RDTSC differential timing before spawning worker threads for file-system enumeration and HTTP POST C2 communication. C2 URLs are generated on-the-fly via an LCG PRNG with constants 0x19660d/0x3c6ef35f indexing a 62-character alphabet table. No static C2 strings exist. The .data section carries a per-sample individualized encrypted payload. This is a builder-template malware, not a hand-crafted binary.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1620 | Reflective Code Loading | PEB-walking API resolution -> VirtualAlloc -> section mapping -> in-memory execution ^[r2:fcn.00417034] |
| T1055 | Process Injection | VirtualAlloc + WriteProcessMemory + VirtualProtect + CreateRemoteThread / ResumeThread ^[r2:fcn.00417034] |
| T1059 | Command and Scripting Interpreter | Worker threads spawn child processes with command-line arguments ^[r2:fcn.00417034] |
| T1083 | File and Directory Discovery | Recursive FindFirstFileA / FindNextFileA with * wildcard in dedicated thread ^[r2:fcn.00407468] |
| T1071.001 | Application Layer Protocol: Web Protocols | HTTP POST C2 with WinInet API handles ^[r2:fcn.0040782c] |
| T1573.001 | Encrypted Channel: Symmetric Cryptography | Payload encrypted with XOR-NOT cipher; C2 body encrypted with CryptEncrypt ^[r2:fcn.00401240] |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit check + RDTSC timing gate ^[r2:fcn.004010bc] |
| T1027.002 | Obfuscated Files or Information: Software Packing | In-place .text decryption; encrypted entry point ^[pefile.txt:93] |
| T1070.004 | Indicator Removal: File Deletion | Self-erasure routine referenced in thread worker ^[r2:fcn.0040782c] |
References
- Primary analysis:
136b5750— /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html - Cluster entity: blackmatter
- Umbrella entity: unattributed
- Technique page: peb-walking-api-resolution
- Technique page: prng-seeded-c2-url-decoding
- OpenCTI artifact ID:
c3ddfe90-cb14-403c-abb7-3ff47e52608e - MalwareBazaar:
34f9b16d363f1bd44d912a62ee0745985ac696b6c4aaf4799a9b2b37d11720e8
Provenance
file.txt— file(1) outputpefile.txt— pefile Python modulerabin2-info.txt— radare2rabin2 -Iexiftool.json— ExifTool 12.76strings.txt— strings(1)yara.txt— YARAmetadata.json— OpenCTI connector artifact metadatar2:fcn.*— radare2 5.x analysis (level 2), 517 functions found.text/.datasection hashes computed with Python hashlib.sha256- Cross-sibling comparison against prior 34 cluster analyses via grep on
wiki/wiki/raw/analyses/*/report.md