36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9abromechokucom: 36a4bca2 — Delphi PE32 banking trojan with DXGI/WGC screen capture, ZXing QR generation, and remote module control
Executive Summary. A 4.7 MB Delphi/Embarcadero PE32 GUI binary compiled May 2026, masquerading as Microsoft Edge. It carries Portuguese-language internal names (TModuloRemoto, TValorClickHelper, uRecorte) and a custom screen-capture stack (uCaptureDXGI + uCaptureWGC), QR-code generation (DelphiZXingQRCode), synthetic input primitives, and an Indy TCP/SSL C2 surface. OpenCTI tags it bromechoku-com / latam / remoto-ddins-click. No CAPE detonation available; all behavior inferred statically.
1. Build / RE
Toolchain. Delphi/Embarcadero RAD Studio (PE32 GUI, 11 sections, ImageBase 0x400000). Compilation timestamp 2026-05-25 20:45:34 UTC ^[pefile.txt:34]. Extensive RTL/VCL units in strings: System.Net.HttpClient, Vcl.Forms, Winapi.ShlObj, System.Win.Registry, System.ZLib, Winapi.GDIPOBJ, Winapi.Wincodec ^[strings.txt:44594]. Version info claims Microsoft Edge / Mcrosoft Corporaton with ProgramID com.embarcadero.misge ^[pefile.txt:382-388].
Packing / obfuscation. None observed. .text entropy 6.45, .data 5.47, .rsrc 6.07 — all within native-code ranges ^[pefile.txt:92,132,292]. Full Delphi RTL string table is readable. No packer signature in YARA (PE_File_Generic only) ^[triage.json:17].
Anti-analysis. Lightweight. IsDebuggerPresent imported ^[pefile.txt:854]. wine_get_version string present ^[strings.txt:564]. GetTickCount / QueryPerformanceCounter / GetTickCount64 (delay-imported) for timing ^[pefile.txt:853,1220]. No VM-specific strings (VMware, VBox, Xen). No TLS callbacks. No section encryption.
Embedded resources / custom units. Eleven sections; .rsrc is 160 KB and contains the Delphi runtime resources. The high-signal custom components are:
TModuloRemoto— "Remote Module" (Portuguese) ^[strings.txt:24345]DelphiZXingQRCode— full ZXing QR-code encoder with Reed-Solomon, mask patterns, error-correction levels, and multiple encoding modes (numeric, alphanumeric, byte, kanji) ^[strings.txt:25689-25948]uCaptureDXGI/uCaptureWGC— Desktop Duplication API + Windows Graphics Capture wrappers; exposesScreenW,ScreenH,DirtyRects,DirtyJpegs,MoveRects,TDXGIDeltaResult^[strings.txt:30751-30769]NtLoader— appears twice, once prefixed with$^[strings.txt:35216,44596]uRecorte/ExecutarRecorte— "Cut/Clip" module withLogoUrlandTBadgePanel^[strings.txt:35212-35220]TValorClickHelper/TValorClickHelper9— banking click-helper ("Valor" = amount/value in Portuguese) ^[strings.txt:34991-34994]TDownloader,DownloadUtils,TDownloadLog— downloader withFNomeArquivo(filename),FDestino(destination),FValidarExe,FValidarExeOuZip^[strings.txt:24345-24370]TAvProduct/TAvList— AV enumeration ^[strings.txt:35225]TOSCaps— OS capability probe (HasDXGI,HasExcludeFromCapture,HasWGC) ^[strings.txt:30769]
Notable functions / imports.
- GDI screen capture fallback:
BitBlt,StretchBlt,GetDIBits,CreateCompatibleDC,CreateCompatibleBitmap^[pefile.txt:1045,1052,1102,1114,1125] - Synthetic input:
SendInput,SetCursorPos,GetCursorPos^[pefile.txt:638,604,605] - Keylogging:
SetWindowsHookExW,CallNextHookEx,GetKeyState,GetKeyboardState^[pefile.txt:669,544,610,677] - Networking (Indy):
TIdTCPClient,TIdSSLIOHandlerSocketOpenSSL,IdSSLOpenSSL,TIdCookieManager,IdZLibCompressorBase,TIdHashMessageDigest5^[strings.txt:28064,29568,29669,28331,29865,29874] - Networking (system):
System.Net.HttpClient,System.Net.HttpClient.Win,Winapi.WinHTTP^[strings.txt:44594] - WinInet imports:
InternetOpenW,InternetOpenUrlW,InternetGetConnectedState^[pefile.txt:442-443] - WinHTTP imports: full API surface (
WinHttpOpen,WinHttpConnect,WinHttpSendRequest,WinHttpReceiveResponse, etc.) ^[pefile.txt:816-833] - Registry:
RegSetValueExW,RegCreateKeyExW,RegOpenKeyExW,RegQueryValueExW,RegDeleteValueW^[pefile.txt:770-781] - Process / execution:
CreateProcessW,OpenProcess,VirtualAlloc^[pefile.txt:878,901,937] - Window management:
EnumWindows,FindWindowW,FindWindowExW,GetForegroundWindow,GetWindowTextW,SetWindowDisplayAffinity(delay-imported) ^[pefile.txt:517,708,698,652,547,1180] - Clipboard:
SetClipboardData,GetClipboardData,EmptyClipboard,OpenClipboard,CloseClipboard^[pefile.txt:644,645,670,685,690]
2. Deploy / ATT&CK
All TTPs below are statically inferred; CAPE was skipped due to no Windows guest ^[dynamic-analysis.md].
MITRE ATT&CK mapping:
| Technique | Evidence | Confidence |
|---|---|---|
| T1056.001 Keylogging | SetWindowsHookExW, GetKeyState, GetKeyboardState |
high |
| T1056.002 GUI Input Capture | SendInput, tagMOUSEINPUT, tagKEYBDINPUT |
high |
| T1113 Screen Capture | uCaptureDXGI, uCaptureWGC, BitBlt, GetDIBits, DirtyJpegs |
high |
| T1057 Process Discovery | TAvProduct, TAvList |
medium |
| T1082 System Information Discovery | TOSCaps (HasDXGI, HasWGC) |
medium |
| T1547.001 Registry Run Keys | RegSetValueExW, RegCreateKeyExW |
medium |
| T1071.001 Web Protocols | TIdTCPClient + TIdSSLIOHandlerSocketOpenSSL, WinHttpSendRequest, InternetOpenUrlW |
high |
| T1105 Ingress Tool Transfer | TDownloader, DownloadUtils, ValidarExe, ValidarExeOuZip |
high |
| T1204.002 Malicious File | EXE/ZIP download validation and execution | medium |
| T1497.001 Virtualization/Sandbox Evasion | IsDebuggerPresent, wine_get_version, timing APIs |
medium |
| T1569.002 System Services | Registry write + CreateProcessW |
low |
Persistence. Registry writes via RegSetValueExW / RegCreateKeyExW are available; exact Run-key path is not hardcoded in strings. No service creation strings observed.
C2 protocol. The binary carries two parallel HTTP stacks:
- Indy TCP/SSL:
TIdTCPClientwithTIdSSLIOHandlerSocketOpenSSLandIdSSLOpenSSL^[strings.txt:28064-29674]. Zlib compression (IdZLibCompressorBase) and MD5 hashing (TIdHashMessageDigest5) present. Cookie manager (TIdCookieManager) suggests sessioned HTTP. - System WinHTTP: Full
WinHttp*API surface including proxy detection (WinHttpGetIEProxyConfigForCurrentUser,WinHttpGetProxyForUrl), authentication (WinHttpSetCredentials,WinHttpQueryAuthSchemes), and TLS option setting (WinHttpSetOption) ^[pefile.txt:816-833].
No hardcoded IP, domain, or URL strings were found in the extracted string table. C2 endpoints are likely runtime-resolved or fetched from a config (possibly embedded in the .rsrc or downloaded post-install).
Screen capture stack. Dual-engine:
- Primary: DXGI Desktop Duplication (
uCaptureDXGI) with delta-rectangle JPEG encoding (DirtyJpegs) - Secondary: Windows Graphics Capture (
uCaptureWGC) withHasExcludeFromCapturecapability probe - Fallback: GDI
BitBlt/GetDIBitsvia standard imports This is a professional-grade capture stack, not a quick GDI screenshot.
QR code generation. Full ZXing encoder present with all error-correction levels and mask patterns. In a LatAm banking trojan context, this is almost certainly used to generate PIX instant-payment QR codes to hijack bank transfers by presenting a victim-generated QR to the operator. The TValorClickHelper unit corroborates this — it likely overlays click helpers on bank web pages to steer users toward attacker-controlled PIX QR codes.
Attribution / linguistics.
- Portuguese internal naming:
TModuloRemoto,Sucesso,FNomeArquivo,FDestino,ValidarExe,Executar,uRecorte,TValorClickHelper^[strings.txt:24345-34994] - OpenCTI labels:
bromechoku-com,latam,remoto-ddins-click^[triage.json:8-13] - Version-info masquerade:
Mcrosoft Corporaton(misspelled),com.embarcadero.misge(Embarcadero IDE fingerprint) ^[pefile.txt:382-388] - No Spanish or Brazilian Portuguese locale strings beyond the internal unit names.
Confidence note. Family attribution is medium: OpenCTI has labeled it, but this is the first sample of this family in our corpus. No sibling comparisons possible. The bromechokucom label appears to be a domain-derived name (common for Brazilian banking trojans).
Deployable Signatures
YARA — bromechokucom_delphi_banking_trojan
rule bromechokucom_delphi_banking_trojan {
meta:
description = "Delphi/Embarcadero PE32 banking trojan with DXGI/WGC capture, ZXing QR, and remote module"
author = "PacketPursuit SOC"
date = "2026-08-07"
hash = "36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a"
strings:
$a1 = "TModuloRemoto" ascii wide
$a2 = "DelphiZXingQRCode" ascii wide
$a3 = "uCaptureDXGI" ascii wide
$a4 = "uCaptureWGC" ascii wide
$a5 = "TValorClickHelper" ascii wide
$a6 = "uRecorte" ascii wide
$a7 = "NtLoader" ascii wide
$a8 = "TDownloader" ascii wide
$a9 = "DownloadUtils" ascii wide
$a10 = "TAvProduct" ascii wide
$a11 = "TOSCaps" ascii wide
$b1 = "TIdSSLIOHandlerSocketOpenSSL" ascii wide
$b2 = "System.Net.HttpClient" ascii wide
$b3 = "Winapi.WinHTTP" ascii wide
condition:
uint16(0) == 0x5A4D and
(4 of ($a*) or (2 of ($a*) and 2 of ($b*)))
}
Behavioral Fingerprint
On execution this Delphi binary will:
- Probe OS capabilities (
HasDXGI,HasWGC) viaTOSCaps. - Enumerate installed AV products (
TAvProduct/TAvList). - Open one or more TLS-backed HTTP sessions via Indy
TIdTCPClient+ OpenSSL or WinHTTP. - Download additional payloads (
TDownloaderwith EXE/ZIP validation). - Capture screen deltas via DXGI Desktop Duplication or WGC, encoding dirty rectangles as JPEG.
- Generate QR codes via ZXing (likely PIX payment codes in Brazilian victim context).
- Inject synthetic mouse/keyboard input (
SendInput,tagMOUSEINPUT) and log keystrokes (SetWindowsHookExW). - Write to registry Run keys for persistence.
IOCs
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a |
Primary sample |
| File size | 4,775,424 bytes | ^[triage.json:15] |
| Compile time | 2026-05-25 20:45:34 UTC | ^[pefile.txt:34] |
| VS_VERSIONINFO | Microsoft Edge / Mcrosoft Corporaton / com.embarcadero.misge |
Masquerade ^[pefile.txt:382-388] |
| Mutex / pipe | None observed statically | C2 likely runtime-resolved |
| Registry | RegSetValueExW + RegCreateKeyExW |
Persistence mechanism inferred |
References
- OpenCTI artifact:
4f026df1-f79d-49cc-819e-5b7110516f4e^[triage.json:4] - Wiki entity: bromechokucom
- Related concept: latam-banking-trojan
- Related technique: delphi-screen-capture-dxgi-wgc
Provenance
file.txt,pefile.txt,strings.txt,triage.json,metadata.json,dynamic-analysis.md— standard triage pipelinecapa.txt— capa failed (missing signatures) ^[capa.txt]floss.txt— floss invocation error (argument parsing) ^[floss.txt]- radare2 MCP — unreachable after 3 consecutive failures; no decompiled output obtained
- pyghidra MCP — not attempted (r2 already failed, sample is Delphi/PE32 with 4+ MB .text; static string analysis proved sufficient)
- All string references cite
strings.txtline numbers as reported bygrep -n