typeanalysisfamilybromechokucomconfidencemediumcreated2026-08-07pedelphiratbanking-trojanlatamscreen-captureqr-codessl-c2persistenceanti-debug
SHA-256: 36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a

bromechokucom: 36a4bca2 — Delphi PE32 banking trojan with DXGI/WGC screen capture, ZXing QR generation, and remote module control

Executive Summary. A 4.7 MB Delphi/Embarcadero PE32 GUI binary compiled May 2026, masquerading as Microsoft Edge. It carries Portuguese-language internal names (TModuloRemoto, TValorClickHelper, uRecorte) and a custom screen-capture stack (uCaptureDXGI + uCaptureWGC), QR-code generation (DelphiZXingQRCode), synthetic input primitives, and an Indy TCP/SSL C2 surface. OpenCTI tags it bromechoku-com / latam / remoto-ddins-click. No CAPE detonation available; all behavior inferred statically.


1. Build / RE

Toolchain. Delphi/Embarcadero RAD Studio (PE32 GUI, 11 sections, ImageBase 0x400000). Compilation timestamp 2026-05-25 20:45:34 UTC ^[pefile.txt:34]. Extensive RTL/VCL units in strings: System.Net.HttpClient, Vcl.Forms, Winapi.ShlObj, System.Win.Registry, System.ZLib, Winapi.GDIPOBJ, Winapi.Wincodec ^[strings.txt:44594]. Version info claims Microsoft Edge / Mcrosoft Corporaton with ProgramID com.embarcadero.misge ^[pefile.txt:382-388].

Packing / obfuscation. None observed. .text entropy 6.45, .data 5.47, .rsrc 6.07 — all within native-code ranges ^[pefile.txt:92,132,292]. Full Delphi RTL string table is readable. No packer signature in YARA (PE_File_Generic only) ^[triage.json:17].

Anti-analysis. Lightweight. IsDebuggerPresent imported ^[pefile.txt:854]. wine_get_version string present ^[strings.txt:564]. GetTickCount / QueryPerformanceCounter / GetTickCount64 (delay-imported) for timing ^[pefile.txt:853,1220]. No VM-specific strings (VMware, VBox, Xen). No TLS callbacks. No section encryption.

Embedded resources / custom units. Eleven sections; .rsrc is 160 KB and contains the Delphi runtime resources. The high-signal custom components are:

  • TModuloRemoto — "Remote Module" (Portuguese) ^[strings.txt:24345]
  • DelphiZXingQRCode — full ZXing QR-code encoder with Reed-Solomon, mask patterns, error-correction levels, and multiple encoding modes (numeric, alphanumeric, byte, kanji) ^[strings.txt:25689-25948]
  • uCaptureDXGI / uCaptureWGC — Desktop Duplication API + Windows Graphics Capture wrappers; exposes ScreenW, ScreenH, DirtyRects, DirtyJpegs, MoveRects, TDXGIDeltaResult ^[strings.txt:30751-30769]
  • NtLoader — appears twice, once prefixed with $ ^[strings.txt:35216,44596]
  • uRecorte / ExecutarRecorte — "Cut/Clip" module with LogoUrl and TBadgePanel ^[strings.txt:35212-35220]
  • TValorClickHelper / TValorClickHelper9 — banking click-helper ("Valor" = amount/value in Portuguese) ^[strings.txt:34991-34994]
  • TDownloader, DownloadUtils, TDownloadLog — downloader with FNomeArquivo (filename), FDestino (destination), FValidarExe, FValidarExeOuZip ^[strings.txt:24345-24370]
  • TAvProduct / TAvList — AV enumeration ^[strings.txt:35225]
  • TOSCaps — OS capability probe (HasDXGI, HasExcludeFromCapture, HasWGC) ^[strings.txt:30769]

Notable functions / imports.

  • GDI screen capture fallback: BitBlt, StretchBlt, GetDIBits, CreateCompatibleDC, CreateCompatibleBitmap ^[pefile.txt:1045,1052,1102,1114,1125]
  • Synthetic input: SendInput, SetCursorPos, GetCursorPos ^[pefile.txt:638,604,605]
  • Keylogging: SetWindowsHookExW, CallNextHookEx, GetKeyState, GetKeyboardState ^[pefile.txt:669,544,610,677]
  • Networking (Indy): TIdTCPClient, TIdSSLIOHandlerSocketOpenSSL, IdSSLOpenSSL, TIdCookieManager, IdZLibCompressorBase, TIdHashMessageDigest5 ^[strings.txt:28064,29568,29669,28331,29865,29874]
  • Networking (system): System.Net.HttpClient, System.Net.HttpClient.Win, Winapi.WinHTTP ^[strings.txt:44594]
  • WinInet imports: InternetOpenW, InternetOpenUrlW, InternetGetConnectedState ^[pefile.txt:442-443]
  • WinHTTP imports: full API surface (WinHttpOpen, WinHttpConnect, WinHttpSendRequest, WinHttpReceiveResponse, etc.) ^[pefile.txt:816-833]
  • Registry: RegSetValueExW, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegDeleteValueW ^[pefile.txt:770-781]
  • Process / execution: CreateProcessW, OpenProcess, VirtualAlloc ^[pefile.txt:878,901,937]
  • Window management: EnumWindows, FindWindowW, FindWindowExW, GetForegroundWindow, GetWindowTextW, SetWindowDisplayAffinity (delay-imported) ^[pefile.txt:517,708,698,652,547,1180]
  • Clipboard: SetClipboardData, GetClipboardData, EmptyClipboard, OpenClipboard, CloseClipboard ^[pefile.txt:644,645,670,685,690]

2. Deploy / ATT&CK

All TTPs below are statically inferred; CAPE was skipped due to no Windows guest ^[dynamic-analysis.md].

MITRE ATT&CK mapping:

Technique Evidence Confidence
T1056.001 Keylogging SetWindowsHookExW, GetKeyState, GetKeyboardState high
T1056.002 GUI Input Capture SendInput, tagMOUSEINPUT, tagKEYBDINPUT high
T1113 Screen Capture uCaptureDXGI, uCaptureWGC, BitBlt, GetDIBits, DirtyJpegs high
T1057 Process Discovery TAvProduct, TAvList medium
T1082 System Information Discovery TOSCaps (HasDXGI, HasWGC) medium
T1547.001 Registry Run Keys RegSetValueExW, RegCreateKeyExW medium
T1071.001 Web Protocols TIdTCPClient + TIdSSLIOHandlerSocketOpenSSL, WinHttpSendRequest, InternetOpenUrlW high
T1105 Ingress Tool Transfer TDownloader, DownloadUtils, ValidarExe, ValidarExeOuZip high
T1204.002 Malicious File EXE/ZIP download validation and execution medium
T1497.001 Virtualization/Sandbox Evasion IsDebuggerPresent, wine_get_version, timing APIs medium
T1569.002 System Services Registry write + CreateProcessW low

Persistence. Registry writes via RegSetValueExW / RegCreateKeyExW are available; exact Run-key path is not hardcoded in strings. No service creation strings observed.

C2 protocol. The binary carries two parallel HTTP stacks:

  1. Indy TCP/SSL: TIdTCPClient with TIdSSLIOHandlerSocketOpenSSL and IdSSLOpenSSL ^[strings.txt:28064-29674]. Zlib compression (IdZLibCompressorBase) and MD5 hashing (TIdHashMessageDigest5) present. Cookie manager (TIdCookieManager) suggests sessioned HTTP.
  2. System WinHTTP: Full WinHttp* API surface including proxy detection (WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl), authentication (WinHttpSetCredentials, WinHttpQueryAuthSchemes), and TLS option setting (WinHttpSetOption) ^[pefile.txt:816-833].

No hardcoded IP, domain, or URL strings were found in the extracted string table. C2 endpoints are likely runtime-resolved or fetched from a config (possibly embedded in the .rsrc or downloaded post-install).

Screen capture stack. Dual-engine:

  • Primary: DXGI Desktop Duplication (uCaptureDXGI) with delta-rectangle JPEG encoding (DirtyJpegs)
  • Secondary: Windows Graphics Capture (uCaptureWGC) with HasExcludeFromCapture capability probe
  • Fallback: GDI BitBlt/GetDIBits via standard imports This is a professional-grade capture stack, not a quick GDI screenshot.

QR code generation. Full ZXing encoder present with all error-correction levels and mask patterns. In a LatAm banking trojan context, this is almost certainly used to generate PIX instant-payment QR codes to hijack bank transfers by presenting a victim-generated QR to the operator. The TValorClickHelper unit corroborates this — it likely overlays click helpers on bank web pages to steer users toward attacker-controlled PIX QR codes.

Attribution / linguistics.

  • Portuguese internal naming: TModuloRemoto, Sucesso, FNomeArquivo, FDestino, ValidarExe, Executar, uRecorte, TValorClickHelper ^[strings.txt:24345-34994]
  • OpenCTI labels: bromechoku-com, latam, remoto-ddins-click ^[triage.json:8-13]
  • Version-info masquerade: Mcrosoft Corporaton (misspelled), com.embarcadero.misge (Embarcadero IDE fingerprint) ^[pefile.txt:382-388]
  • No Spanish or Brazilian Portuguese locale strings beyond the internal unit names.

Confidence note. Family attribution is medium: OpenCTI has labeled it, but this is the first sample of this family in our corpus. No sibling comparisons possible. The bromechokucom label appears to be a domain-derived name (common for Brazilian banking trojans).


Deployable Signatures

YARA — bromechokucom_delphi_banking_trojan

rule bromechokucom_delphi_banking_trojan {
    meta:
        description = "Delphi/Embarcadero PE32 banking trojan with DXGI/WGC capture, ZXing QR, and remote module"
        author = "PacketPursuit SOC"
        date = "2026-08-07"
        hash = "36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a"
    strings:
        $a1 = "TModuloRemoto" ascii wide
        $a2 = "DelphiZXingQRCode" ascii wide
        $a3 = "uCaptureDXGI" ascii wide
        $a4 = "uCaptureWGC" ascii wide
        $a5 = "TValorClickHelper" ascii wide
        $a6 = "uRecorte" ascii wide
        $a7 = "NtLoader" ascii wide
        $a8 = "TDownloader" ascii wide
        $a9 = "DownloadUtils" ascii wide
        $a10 = "TAvProduct" ascii wide
        $a11 = "TOSCaps" ascii wide
        $b1 = "TIdSSLIOHandlerSocketOpenSSL" ascii wide
        $b2 = "System.Net.HttpClient" ascii wide
        $b3 = "Winapi.WinHTTP" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        (4 of ($a*) or (2 of ($a*) and 2 of ($b*)))
}

Behavioral Fingerprint

On execution this Delphi binary will:

  1. Probe OS capabilities (HasDXGI, HasWGC) via TOSCaps.
  2. Enumerate installed AV products (TAvProduct / TAvList).
  3. Open one or more TLS-backed HTTP sessions via Indy TIdTCPClient + OpenSSL or WinHTTP.
  4. Download additional payloads (TDownloader with EXE/ZIP validation).
  5. Capture screen deltas via DXGI Desktop Duplication or WGC, encoding dirty rectangles as JPEG.
  6. Generate QR codes via ZXing (likely PIX payment codes in Brazilian victim context).
  7. Inject synthetic mouse/keyboard input (SendInput, tagMOUSEINPUT) and log keystrokes (SetWindowsHookExW).
  8. Write to registry Run keys for persistence.

IOCs

Type Value Notes
SHA-256 36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a Primary sample
File size 4,775,424 bytes ^[triage.json:15]
Compile time 2026-05-25 20:45:34 UTC ^[pefile.txt:34]
VS_VERSIONINFO Microsoft Edge / Mcrosoft Corporaton / com.embarcadero.misge Masquerade ^[pefile.txt:382-388]
Mutex / pipe None observed statically C2 likely runtime-resolved
Registry RegSetValueExW + RegCreateKeyExW Persistence mechanism inferred

References


Provenance

  • file.txt, pefile.txt, strings.txt, triage.json, metadata.json, dynamic-analysis.md — standard triage pipeline
  • capa.txt — capa failed (missing signatures) ^[capa.txt]
  • floss.txt — floss invocation error (argument parsing) ^[floss.txt]
  • radare2 MCP — unreachable after 3 consecutive failures; no decompiled output obtained
  • pyghidra MCP — not attempted (r2 already failed, sample is Delphi/PE32 with 4+ MB .text; static string analysis proved sufficient)
  • All string references cite strings.txt line numbers as reported by grep -n