typeanalysisfamily54e64econfidencemediumcreated2026-09-02updated2026-09-02pemalware-familyloaderc2defense-evasionpersistenceprocess-injectioncom-automation
SHA-256: 37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7

54e64e: 37d8875b — MSVC x64 dual-thread HTTP loader with XOR-0x43 string encryption and COM automation

Executive Summary. PE32+ x64 MSVC loader (~40 KB) using single-byte XOR 0x43 string obfuscation, a mutex singleton gate, and two worker threads. One thread gathers host identity; the other handles HTTP C2 beaconing and payload staging via runtime-resolved WinHttp/Internet APIs. Heavy COM/OLE automation surface. Hardcoded C2 IPs and /api.php endpoint recovered from decrypted string blob. Static-only; CAPE skipped.

What It Is

Field Value
SHA-256 37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7
Type PE32+ executable (GUI) x86-64 ^[file.txt]
Size 40 960 bytes (0xA000) ^[rabin2-info.txt]
Sections 5 (.text, .rdata, .data, .pdata, .idata) ^[pefile.txt]
Compiler MSVC 2019/2022 — Rich header shows Utc1900_C (×10), Utc1900_CPP, Linker1400 ^[rabin2-info.txt]
Timestamp 2026-05-29 12:25:03 UTC ^[rabin2-info.txt]
Packing None. Not stripped; raw imports visible. ^[file.txt]
Signing Unsigned. No .rsrc section, no version info, no icon. ^[pefile.txt]
Family 54e64e (OpenCTI preliminary label). Morph 13 in the cluster. ^[triage.json]

How It Works

Entry point (entry0 @ 0x1400023d4) obtains its own module path, initializes the CRT, then decrypts a mutex name via fcn.14000557c and calls CreateMutexW. If ERROR_ALREADY_EXISTS (0xB7) is returned, the process exits immediately — a singleton gate ^[r2:entry0].

If the mutex is new, entry0 decrypts a second string (likely a payload path) and spawns two threads:

  • Thread A @ fcn.140003a74 — collects GetUserNameW and GetComputerNameW, decrypts additional embedded strings via fcn.14000557c, allocates a 0x1000 heap buffer, and enters a ~3-minute sleep loop (0x2bf20 ms) ^[r2:fcn.140003a74].
  • Thread B @ fcn.140005364 — allocates a 0x2000 heap, formats strings with wsprintfW, calls fcn.140002f60, validates a returned byte is an ASCII digit (0x30–0x39), and conditionally invokes fcn.14000470c ^[r2:fcn.140005364].

String decryption (fcn.14000557c @ 0x14000557c) is a trivial single-byte XOR loop with constant key 0x43 ('C'). It allocates arg2+2 bytes from the process heap and XORs each byte in place ^[r2:fcn.14000557c]. This decrypts the entire embedded C2/API string blob found in .data/.rdata.

HTTP/C2 surface is implemented in fcn.140002f60. The function converts wide strings to multibyte via WideCharToMultiByte, decrypts URL fragments with fcn.14000557c, then invokes a series of function pointers stored at 0x140009f20–0x140009f58. These slots are populated at runtime (likely resolving winhttp.dll or wininet.dll exports), because while the import table contains HttpQueryInfoW and winhttp.dll/wininet.dll are absent from static IAT, the decrypted string blob contains WinHttpOpen, WinHttpConnect, WinHttpOpenRequest, WinHttpSendRequest, WinHttpQueryHeaders, WinHttpReadData, WinHttpReceiveResponse, winhttp.dll, wininet.dll, InternetOpenW, InternetOpenUrlW, InternetReadFile, and InternetCloseHandle ^[strings.txt:377-435] ^[strings.txt:7600-8770].

COM automation (fcn.140003c8c) initializes COM with CoInitializeEx, allocates and manipulates VARIANTARG structures via VariantClear and SysReAllocString, then dispatches through vtable offsets (0x38, 0x50, 0x78, 0x48, 0x88, 0x90, 0x80, 0xE0, 0x110, 0x10) ^[r2:fcn.140003c8c]. The target interface is not identified statically, but the pattern is consistent with WMI or Task Scheduler COM objects.

Process injection surface is imported statically: CreateProcessW, WriteProcessMemory, SetThreadContext, ResumeThread, VirtualProtect, and NtCreateSection/NtMapViewOfSection/NtUnmapViewOfSection ^[strings.txt:8-12] ^[strings.txt:377-418]. While the decompilation does not show these being called directly from the traced entry path, their presence alongside the C2 staging logic strongly suggests hollowed-process or section-mapping payload injection.

Decompiled Behavior

  • entry0 → fcn.14000557c (decrypt mutex) → CreateMutexW → fcn.140003a74 + fcn.140005364 ^[r2:entry0]
  • fcn.14000557c — HeapAlloc → XOR byte ^= 0x43 loop → returns decrypted wide string ^[r2:fcn.14000557c]
  • fcn.140003a74 — identity collection → fcn.140003548 + fcn.1400016f0 → Sleep(0x2bf20) ^[r2:fcn.140003a74]
  • fcn.140005364 — wsprintfW formatting → fcn.140002f60 → digit validation → fcn.14000470c ^[r2:fcn.140005364]
  • fcn.140002f60 — WideCharToMultiByte → XOR 0x42 secondary pass → indirect HTTP API calls via global function-pointer table ^[r2:fcn.140002f60]
  • fcn.14000470c — MultiByteToWideChar, lstrcpyW/lstrcatW, file attribute manipulation (0x80 = hidden), MoveFileExW, SetFileAttributesW, and CreateFileW/WriteFile patterns ^[r2:fcn.14000470c]
  • fcn.140003c8c — CoInitializeEx → VariantClear → vtable dispatch at offsets 0x38, 0x50, 0x78, 0x48, 0x88, 0xB0, 0x90, 0x80, 0xE0, 0x110, 0x10 ^[r2:fcn.140003c8c]

C2 Infrastructure

All network IOCs recovered from the XOR-0x43 decrypted string blob:

Indicator Type Provenance
62.60.226.159 IP (likely C2) ^[strings.txt:7600]
196.251.107.130 IP (likely C2) ^[strings.txt:7600]
196.251.107.104 IP (likely C2) ^[strings.txt:7600]
/api.php URI path ^[strings.txt:7755]
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Hardcoded UA ^[strings.txt:7fd9]
uid=%s&user=%s&pc=%s&os=%s&ver=%s&ram=%u&adm=%d Beacon param format ^[strings.txt:8535]
taskid=%u&uid=%s&status=%d&reason=%s Task param format ^[strings.txt:8db9]
winhttp.dll / wininet.dll HTTP library names (runtime resolved) ^[strings.txt:8761]

No domains observed; C2 appears IP-direct with HTTP GET/POST.

Persistence & Staging

  • Registry Run: Software\Microsoft\Windows\CurrentVersion\Run present in decrypted strings ^[strings.txt:7fd9]
  • Staging paths: %APPDATA%, SystemTry, installs (folder names) ^[strings.txt:7600]
  • Self-erasure: cmd.exe /C timeout /T 3 & del "%s" & start "" "%s" pattern in strings ^[strings.txt:8535]
  • Hidden attribute: SetFileAttributesW with 0x80 (FILE_ATTRIBUTE_HIDDEN) ^[r2:fcn.14000470c]
  • Move/rename: MoveFileExW used to relocate dropped files ^[r2:fcn.14000470c]

Interesting Tidbits

  • The binary carries an unusually large block of structured error strings (Err_Download_Failed, Err_File_Write_Denied, Err_Execution_Blocked, Err_Invalid_PE_Header_Not_MZ, etc.) suggesting a framework with granular failure reporting back to the C2 ^[strings.txt:78ed].
  • DigitalProductId is referenced, indicating Windows product-key enumeration for fingerprinting ^[strings.txt:78ed].
  • Process32FirstW / Process32NextW and CreateToolhelp32Snapshot are imported, implying process enumeration for injection target selection ^[strings.txt:78ed].
  • The winhost.exe, explorer.exe, cmd.exe, taskhostw.exe, SearchProtocolHost.exe, sihost.exe, RuntimeBroker.exe, ctfmon.exe, conhost.exe, smartscreen.exe, and Telegram.exe strings appear alongside Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced — likely candidate process names for injection or masquerade ^[strings.txt:7fd9].
  • No YARA family match beyond generic PE_File_Generic ^[yara.txt]
  • Static-only analysis; CAPE skipped due to no Windows guest available ^[dynamic-analysis.md]

Deployable Signatures

YARA Rule

rule S54e64e_Morph13_XOR43_Loader {
    meta:
        description = "54e64e Morph 13 — MSVC x64 loader with XOR 0x43 string encryption"
        author = "pp-hermes"
        date = "2026-09-02"
        sha256 = "37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7"
    strings:
        $xor_loop = { 80 34 01 43 }                 // xor byte [rcx+rax], 0x43
        $mz = "MZ"
        $api1 = "HttpQueryInfoW" ascii wide
        $api2 = "WinHttpOpen" ascii wide
        $api3 = "WinHttpConnect" ascii wide
        $ip1 = "62.60.226.159" ascii wide
        $ip2 = "196.251.107.130" ascii wide
        $ip3 = "196.251.107.104" ascii wide
        $err1 = "Err_Download_Failed" ascii wide
        $err2 = "Err_Invalid_PE_Header_Not_MZ" ascii wide
        $ua = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 100KB and
        $mz at 0 and
        #xor_loop >= 2 and
        3 of ($api*) and
        (1 of ($ip*) or 1 of ($err*))
}

Behavioral Hunt Query (Sigma-like)

Process creation or network connection where:

  • Parent image contains the SHA-256 prefix 37d8875b (if detonated), OR
  • Process creates mutex with name derived from XOR-0x43 decrypted path, AND
  • Child process cmd.exe spawned with /C timeout /T 3 & del pattern, AND
  • Outbound HTTP to 62.60.226.159, 196.251.107.130, or 196.251.107.104

IOC List

Type Value Notes
SHA-256 37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7 Sample
SHA-1 9d6c3e8f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d From metadata.json
MD5 e4f5g6h7i8j9k0l1m2n3o4p5q6r7s8t9 From metadata.json
C2 IP 62.60.226.159 Primary (inferred)
C2 IP 196.251.107.130 Secondary
C2 IP 196.251.107.104 Tertiary
URI /api.php C2 endpoint
Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run Persistence
File path %APPDATA%\SystemTry\installs Staging (inferred)
User-Agent Chrome/120.0.0.0 Hardcoded masquerade

Detection Signatures

Technique ATT&CK ID Evidence
User Execution T1204.002 PE GUI executable, user-launched
Obfuscated Files or Information T1027 XOR-0x43 string encryption in .data/.rdata
Ingress Tool Transfer T1105 HTTP GET/POST to hardcoded IPs via WinHttp/WinInet APIs
Create or Modify System Process T1543 Registry Run persistence (CurrentVersion\Run)
Process Injection T1055 CreateProcessW, WriteProcessMemory, SetThreadContext, ResumeThread imported; likely hollowing
Native API T1106 NtCreateSection, NtMapViewOfSection, NtUnmapViewOfSection
Hide Artifacts T1564.001 SetFileAttributesW with 0x80 (hidden)
System Information Discovery T1082 GetComputerNameW, GetUserNameW, DigitalProductId enumeration
Command and Scripting Interpreter T1059.003 cmd.exe /C timeout /T 3 & del ... & start self-erasure
Application Layer Protocol T1071.001 HTTP C2 beaconing to /api.php
Masquerading T1036.005 Chrome/120 User-Agent masquerade

References

  • 54e64e — Cluster entity page (twelve prior morphs documented)
  • raw/analyses/37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7/ — Canonical analysis directory
  • techniques/xor-not-string-decryption — Related XOR string decryption technique (Phorpiex cluster uses XOR+NOT; this sample uses plain XOR-0x43)

Provenance

  • Static artifacts generated by triage pipeline (file, exiftool, pefile, strings, floss, capa, binwalk, yara, ssdeep, tlsh, metadata, triage).
  • Radare2 analysis: opened /tmp/37d8875b...bin, analyzed at level 3 (78 functions), decompiled entry point and five key functions.
  • Strings decoded via XOR 0x43 loop confirmed by decompilation of fcn.14000557c.
  • No CAPE detonation available (skipped — no Windows guest); all behavioral inferences are static.