37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f754e64e: 37d8875b — MSVC x64 dual-thread HTTP loader with XOR-0x43 string encryption and COM automation
Executive Summary. PE32+ x64 MSVC loader (~40 KB) using single-byte XOR 0x43 string obfuscation, a mutex singleton gate, and two worker threads. One thread gathers host identity; the other handles HTTP C2 beaconing and payload staging via runtime-resolved WinHttp/Internet APIs. Heavy COM/OLE automation surface. Hardcoded C2 IPs and /api.php endpoint recovered from decrypted string blob. Static-only; CAPE skipped.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7 |
| Type | PE32+ executable (GUI) x86-64 ^[file.txt] |
| Size | 40 960 bytes (0xA000) ^[rabin2-info.txt] |
| Sections | 5 (.text, .rdata, .data, .pdata, .idata) ^[pefile.txt] |
| Compiler | MSVC 2019/2022 — Rich header shows Utc1900_C (×10), Utc1900_CPP, Linker1400 ^[rabin2-info.txt] |
| Timestamp | 2026-05-29 12:25:03 UTC ^[rabin2-info.txt] |
| Packing | None. Not stripped; raw imports visible. ^[file.txt] |
| Signing | Unsigned. No .rsrc section, no version info, no icon. ^[pefile.txt] |
| Family | 54e64e (OpenCTI preliminary label). Morph 13 in the cluster. ^[triage.json] |
How It Works
Entry point (entry0 @ 0x1400023d4) obtains its own module path, initializes the CRT, then decrypts a mutex name via fcn.14000557c and calls CreateMutexW. If ERROR_ALREADY_EXISTS (0xB7) is returned, the process exits immediately — a singleton gate ^[r2:entry0].
If the mutex is new, entry0 decrypts a second string (likely a payload path) and spawns two threads:
- Thread A @
fcn.140003a74— collectsGetUserNameWandGetComputerNameW, decrypts additional embedded strings viafcn.14000557c, allocates a 0x1000 heap buffer, and enters a ~3-minute sleep loop (0x2bf20ms) ^[r2:fcn.140003a74]. - Thread B @
fcn.140005364— allocates a 0x2000 heap, formats strings withwsprintfW, callsfcn.140002f60, validates a returned byte is an ASCII digit (0x30–0x39), and conditionally invokesfcn.14000470c^[r2:fcn.140005364].
String decryption (fcn.14000557c @ 0x14000557c) is a trivial single-byte XOR loop with constant key 0x43 ('C'). It allocates arg2+2 bytes from the process heap and XORs each byte in place ^[r2:fcn.14000557c]. This decrypts the entire embedded C2/API string blob found in .data/.rdata.
HTTP/C2 surface is implemented in fcn.140002f60. The function converts wide strings to multibyte via WideCharToMultiByte, decrypts URL fragments with fcn.14000557c, then invokes a series of function pointers stored at 0x140009f20–0x140009f58. These slots are populated at runtime (likely resolving winhttp.dll or wininet.dll exports), because while the import table contains HttpQueryInfoW and winhttp.dll/wininet.dll are absent from static IAT, the decrypted string blob contains WinHttpOpen, WinHttpConnect, WinHttpOpenRequest, WinHttpSendRequest, WinHttpQueryHeaders, WinHttpReadData, WinHttpReceiveResponse, winhttp.dll, wininet.dll, InternetOpenW, InternetOpenUrlW, InternetReadFile, and InternetCloseHandle ^[strings.txt:377-435] ^[strings.txt:7600-8770].
COM automation (fcn.140003c8c) initializes COM with CoInitializeEx, allocates and manipulates VARIANTARG structures via VariantClear and SysReAllocString, then dispatches through vtable offsets (0x38, 0x50, 0x78, 0x48, 0x88, 0x90, 0x80, 0xE0, 0x110, 0x10) ^[r2:fcn.140003c8c]. The target interface is not identified statically, but the pattern is consistent with WMI or Task Scheduler COM objects.
Process injection surface is imported statically: CreateProcessW, WriteProcessMemory, SetThreadContext, ResumeThread, VirtualProtect, and NtCreateSection/NtMapViewOfSection/NtUnmapViewOfSection ^[strings.txt:8-12] ^[strings.txt:377-418]. While the decompilation does not show these being called directly from the traced entry path, their presence alongside the C2 staging logic strongly suggests hollowed-process or section-mapping payload injection.
Decompiled Behavior
entry0→fcn.14000557c(decrypt mutex) →CreateMutexW→fcn.140003a74+fcn.140005364^[r2:entry0]fcn.14000557c—HeapAlloc→ XOR byte^= 0x43loop → returns decrypted wide string ^[r2:fcn.14000557c]fcn.140003a74— identity collection →fcn.140003548+fcn.1400016f0→Sleep(0x2bf20)^[r2:fcn.140003a74]fcn.140005364—wsprintfWformatting →fcn.140002f60→ digit validation →fcn.14000470c^[r2:fcn.140005364]fcn.140002f60—WideCharToMultiByte→ XOR0x42secondary pass → indirect HTTP API calls via global function-pointer table ^[r2:fcn.140002f60]fcn.14000470c—MultiByteToWideChar,lstrcpyW/lstrcatW, file attribute manipulation (0x80= hidden),MoveFileExW,SetFileAttributesW, andCreateFileW/WriteFilepatterns ^[r2:fcn.14000470c]fcn.140003c8c—CoInitializeEx→VariantClear→ vtable dispatch at offsets0x38,0x50,0x78,0x48,0x88,0xB0,0x90,0x80,0xE0,0x110,0x10^[r2:fcn.140003c8c]
C2 Infrastructure
All network IOCs recovered from the XOR-0x43 decrypted string blob:
| Indicator | Type | Provenance |
|---|---|---|
62.60.226.159 |
IP (likely C2) | ^[strings.txt:7600] |
196.251.107.130 |
IP (likely C2) | ^[strings.txt:7600] |
196.251.107.104 |
IP (likely C2) | ^[strings.txt:7600] |
/api.php |
URI path | ^[strings.txt:7755] |
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 |
Hardcoded UA | ^[strings.txt:7fd9] |
uid=%s&user=%s&pc=%s&os=%s&ver=%s&ram=%u&adm=%d |
Beacon param format | ^[strings.txt:8535] |
taskid=%u&uid=%s&status=%d&reason=%s |
Task param format | ^[strings.txt:8db9] |
winhttp.dll / wininet.dll |
HTTP library names (runtime resolved) | ^[strings.txt:8761] |
No domains observed; C2 appears IP-direct with HTTP GET/POST.
Persistence & Staging
- Registry Run:
Software\Microsoft\Windows\CurrentVersion\Runpresent in decrypted strings ^[strings.txt:7fd9] - Staging paths:
%APPDATA%,SystemTry,installs(folder names) ^[strings.txt:7600] - Self-erasure:
cmd.exe /C timeout /T 3 & del "%s" & start "" "%s"pattern in strings ^[strings.txt:8535] - Hidden attribute:
SetFileAttributesWwith0x80(FILE_ATTRIBUTE_HIDDEN) ^[r2:fcn.14000470c] - Move/rename:
MoveFileExWused to relocate dropped files ^[r2:fcn.14000470c]
Interesting Tidbits
- The binary carries an unusually large block of structured error strings (
Err_Download_Failed,Err_File_Write_Denied,Err_Execution_Blocked,Err_Invalid_PE_Header_Not_MZ, etc.) suggesting a framework with granular failure reporting back to the C2 ^[strings.txt:78ed]. DigitalProductIdis referenced, indicating Windows product-key enumeration for fingerprinting ^[strings.txt:78ed].Process32FirstW/Process32NextWandCreateToolhelp32Snapshotare imported, implying process enumeration for injection target selection ^[strings.txt:78ed].- The
winhost.exe,explorer.exe,cmd.exe,taskhostw.exe,SearchProtocolHost.exe,sihost.exe,RuntimeBroker.exe,ctfmon.exe,conhost.exe,smartscreen.exe, andTelegram.exestrings appear alongsideSoftware\Microsoft\Windows\CurrentVersion\Explorer\Advanced— likely candidate process names for injection or masquerade ^[strings.txt:7fd9]. - No YARA family match beyond generic
PE_File_Generic^[yara.txt] - Static-only analysis; CAPE skipped due to no Windows guest available ^[dynamic-analysis.md]
Deployable Signatures
YARA Rule
rule S54e64e_Morph13_XOR43_Loader {
meta:
description = "54e64e Morph 13 — MSVC x64 loader with XOR 0x43 string encryption"
author = "pp-hermes"
date = "2026-09-02"
sha256 = "37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7"
strings:
$xor_loop = { 80 34 01 43 } // xor byte [rcx+rax], 0x43
$mz = "MZ"
$api1 = "HttpQueryInfoW" ascii wide
$api2 = "WinHttpOpen" ascii wide
$api3 = "WinHttpConnect" ascii wide
$ip1 = "62.60.226.159" ascii wide
$ip2 = "196.251.107.130" ascii wide
$ip3 = "196.251.107.104" ascii wide
$err1 = "Err_Download_Failed" ascii wide
$err2 = "Err_Invalid_PE_Header_Not_MZ" ascii wide
$ua = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 100KB and
$mz at 0 and
#xor_loop >= 2 and
3 of ($api*) and
(1 of ($ip*) or 1 of ($err*))
}
Behavioral Hunt Query (Sigma-like)
Process creation or network connection where:
- Parent image contains the SHA-256 prefix
37d8875b(if detonated), OR - Process creates mutex with name derived from XOR-0x43 decrypted path, AND
- Child process
cmd.exespawned with/C timeout /T 3 & delpattern, AND - Outbound HTTP to
62.60.226.159,196.251.107.130, or196.251.107.104
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7 |
Sample |
| SHA-1 | 9d6c3e8f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d |
From metadata.json |
| MD5 | e4f5g6h7i8j9k0l1m2n3o4p5q6r7s8t9 |
From metadata.json |
| C2 IP | 62.60.226.159 |
Primary (inferred) |
| C2 IP | 196.251.107.130 |
Secondary |
| C2 IP | 196.251.107.104 |
Tertiary |
| URI | /api.php |
C2 endpoint |
| Registry | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
Persistence |
| File path | %APPDATA%\SystemTry\installs |
Staging (inferred) |
| User-Agent | Chrome/120.0.0.0 |
Hardcoded masquerade |
Detection Signatures
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| User Execution | T1204.002 | PE GUI executable, user-launched |
| Obfuscated Files or Information | T1027 | XOR-0x43 string encryption in .data/.rdata |
| Ingress Tool Transfer | T1105 | HTTP GET/POST to hardcoded IPs via WinHttp/WinInet APIs |
| Create or Modify System Process | T1543 | Registry Run persistence (CurrentVersion\Run) |
| Process Injection | T1055 | CreateProcessW, WriteProcessMemory, SetThreadContext, ResumeThread imported; likely hollowing |
| Native API | T1106 | NtCreateSection, NtMapViewOfSection, NtUnmapViewOfSection |
| Hide Artifacts | T1564.001 | SetFileAttributesW with 0x80 (hidden) |
| System Information Discovery | T1082 | GetComputerNameW, GetUserNameW, DigitalProductId enumeration |
| Command and Scripting Interpreter | T1059.003 | cmd.exe /C timeout /T 3 & del ... & start self-erasure |
| Application Layer Protocol | T1071.001 | HTTP C2 beaconing to /api.php |
| Masquerading | T1036.005 | Chrome/120 User-Agent masquerade |
References
- 54e64e — Cluster entity page (twelve prior morphs documented)
raw/analyses/37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7/— Canonical analysis directory- techniques/xor-not-string-decryption — Related XOR string decryption technique (Phorpiex cluster uses XOR+NOT; this sample uses plain XOR-0x43)
Provenance
- Static artifacts generated by triage pipeline (file, exiftool, pefile, strings, floss, capa, binwalk, yara, ssdeep, tlsh, metadata, triage).
- Radare2 analysis: opened
/tmp/37d8875b...bin, analyzed at level 3 (78 functions), decompiled entry point and five key functions. - Strings decoded via XOR
0x43loop confirmed by decompilation offcn.14000557c. - No CAPE detonation available (skipped — no Windows guest); all behavioral inferences are static.