typeanalysisfamilyunattributedconfidencemediumcreated2026-07-29updated2026-07-29pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde

unattributed: 3b42403b — near-identical twin of 136b5750, individualized encrypted payload

Executive Summary

A 150 KB PE32 GUI binary compiled with MSVC 14.12 on 2022-09-09. It is a near-identical structural twin to sibling 136b5750 — same entry point, same PEB-walking API resolution, same XOR-NOT alphabet cipher, same CPUID anti-VM gate, and same LCG PRNG. The only material deltas are the PE checksum, the .data section hash, and minor .pdata/.reloc variation, indicating the builder injects individualized encrypted payload data per sample while reusing the same stub. OpenCTI label: dropped-by-phorpiex. Static-only analysis (CAPE skipped).

What It Is

Field Value
SHA-256 3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) ^[pefile.txt:18] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal surface: GDI32 (6), USER32 (11), KERNEL32 (8) ^[pefile.txt:249]
YARA Generic PE only ^[yara.txt]

Twin relationship to 136b5750: Both binaries share the exact same section layout, entry point (0x1946F), import table, resource directory, and POGO debug metadata. The deltas are:

  • PE CheckSum: 0x2F448 (this sample) vs 0x2BC5A (136b5750) ^[pefile.txt:66] ^[sample 136b5750/pefile.txt:66]
  • .data section SHA-256: d9e7e795... (this sample) vs f2e9b436... (136b5750) ^[pefile.txt:155] ^[sample 136b5750/pefile.txt:155]
  • .pdata VirtualSize: 0x88E (this sample) vs 0x885 (136b5750) ^[pefile.txt:160] ^[sample 136b5750/pefile.txt:160]
  • .reloc SHA-256 differs ^[pefile.txt:195] ^[sample 136b5750/pefile.txt:195]

The .text section is byte-identical between both samples (same MD5 cfbda2c44e51b3b0b00bcbbc767c62a2), confirming the loader stub is a shared template. The .data difference is the encrypted payload / config blob. ^[pefile.txt:93] ^[sample 136b5750/pefile.txt:93]

How It Works

For a full decompiled walkthrough of the loader stub, see the deep analysis of twin 136b5750: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html.

This sample executes the same control flow:

  1. Entry point (0x41946F) → fcn.00419479 → fcn.0040639c (runtime init) → fcn.00409990 (main orchestrator) → fcn.00417458 (thread / loader dispatch). ^[r2:fcn.00419479]
  2. PEB-walking API resolution — no imports for VirtualAlloc, CreateThread, InternetOpen, etc. All resolved via InMemoryOrderModuleList traversal and export-name hashing, cached in XOR-encrypted .data slots at 0x425xxx. ^[r2:fcn.00405aec]
  3. XOR-NOT string crypto — hard-coded key 0x10035fff applied to encrypted DWORD arrays, then bitwise NOT. Builds the A-Z a-z 0-9 alphabet table used for runtime C2 URL / UA generation. ^[r2:fcn.00401240]
  4. LCG PRNG (0x40110c) — seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. Drives sleep jitter and character selection. ^[r2:fcn.0040110c]
  5. Anti-VM gate (0x4010bc) — CPUID leaf 1 ECX bit 31 + leaf 7 EBX bit 18 (hypervisor bits), plus RDTSC rotate-13 timing differential. ^[r2:fcn.004010bc]
  6. File-system enumerator (0x407468) — wildcard * recursive directory traversal via resolved FindFirstFile / FindNextFile. ^[r2:fcn.00407468]
  7. C2 comms (0x40782c, 0x40cfcc) — HTTP POST assembly with encrypted body, WinInet-style handle allocation, runtime-generated URL/UA via alphabet+PRNG. ^[r2:fcn.0040782c] ^[r2:fcn.0040cfcc]

Decompiled Behavior

Address Role Key Observations
0x4010bc Anti-debug/VM gate CPUID hypervisor bits + RDTSC rotate-13 timing — identical to 136b5750 ^[r2:fcn.004010bc]
0x4011c4 String helper ASCII case-conversion — identical to 136b5750 ^[r2:fcn.004011c4]
0x40110c LCG PRNG Same multiplier, increment, mask as 136b5750 ^[r2:fcn.0040110c]
0x401240 Decrypt stub XOR 0x10035fff then NOT — identical to 136b5750 ^[r2:fcn.00401240]
0x40639c Runtime init Identical XOR-decoded init sequence to 136b5750 ^[r2:fcn.0040639c]
0x406668 Reflective mapper VirtualAlloc → WriteProcessMemory → VirtualProtect chain — identical ^[r2:fcn.00406668]
0x417034 Main orchestrator PEB-walk, thread creation, flag-gated dispatch — identical ^[r2:fcn.00417034]

Radare2 analysis found 519 functions — matching the function count reported for 136b5750. The .itext section is entirely zeroed in both samples (entropy 2.93, no code), serving as padding. ^[pefile.txt:112]

C2 Infrastructure

No hard-coded C2 endpoints survive in the binary. The C2 domain, path, and User-Agent are generated at runtime via the alphabet table + LCG PRNG, then transmitted over HTTP POST with encrypted body data. For the full C2 construction logic, see the 136b5750 report. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

Interesting Tidbits

  • Builder-level individualization: The .data section hash differs between twins, while .text is byte-identical. This means the builder recompiles or repacks the same stub with a fresh encrypted payload per drop. The .pdata size delta (0x88E vs 0x885) suggests the payload may contain a varying number of exception-handler records or function metadata. ^[pefile.txt:160]
  • Checksum field mismatch: The PE optional-header CheckSum is 0x2F448 (this sample) vs 0x2BC5A (136b5750). Windows does not enforce this field, but the builder appears to compute it differently per sample — or one sample has a corrupted checksum. ^[pefile.txt:66]
  • POGO debug metadata preserved: Both twins carry IMAGE_DEBUG_TYPE_POGO (Profile Guided Optimization) records. This is unusual for crimeware and suggests the builder was compiled with MSVC Release + PGO, not a quick debug build. ^[pefile.txt:313]
  • SSDeep similarity: Both samples share the substring P6glyuxE4GsUPnliByoc within their ssdeep hashes, confirming structural homology despite differing block sizes (1536 vs 3072). ^[ssdeep.txt] ^[sample 136b5750/ssdeep.txt]
  • No .rsrc payload: Unlike the initterm-hijack Phorpiex droppers that hide payloads inside .rsrc icons, this twin uses an encrypted .data blob — a different staging mechanism entirely. ^[pefile.txt:207]

How To Mess With It (Homelab Replication)

See the 136b5750 report for the full replication guide: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html.

To reproduce the twin effect specifically:

  1. Build the MSVC 14.12 reflective loader stub once.
  2. Encrypt two different payload blobs with the same XOR-NOT scheme.
  3. Embed each blob into the .data section of a copy of the stub.
  4. Recompute PE checksums; observe that CheckSum and .data/.pdata hashes diverge while .text remains identical.

Deployable Signatures

YARA Rule

Use the same rule developed for 136b5750, expanded to cover both SHA-256s:

rule unattributed_msvc14_peb_walking_xor_not_loader
{
    meta:
        description = "PE32 MSVC 14.12 reflective loader with XOR-NOT string crypto, PEB-walking API resolution, and LCG PRNG"
        author = "PacketPursuit"
        date = "2026-07-29"
        sha256_1 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
        sha256_2 = "3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde"
    strings:
        $xor_not_key = { 3D FF 5F 03 10 }
        $xor_not_op = { 81 31 FF 5F 03 10 }
        $lcg_mul = { 0D 66 19 00 00 }
        $lcg_inc = { 35 3C EF C6 03 }
        $lcg_mask = { 25 FF FF FF 07 }
        $alphabet_1 = { 41 BB BF EA }
        $alphabet_2 = { 45 E6 BB A7 }
        $alphabet_3 = { 49 EA B7 A3 }
        $post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + 0x18) == 0x10B and
        3 of ($xor_not_*) and
        2 of ($lcg_*) and
        2 of ($alphabet_*) and
        $post_wide
}

Behavioral Fingerprint

This binary loads with a minimal IAT (GDI32, USER32, KERNEL32 GUI APIs only), then walks the PEB InMemoryOrderModuleList to resolve ~30+ threat APIs at runtime. It allocates memory via indirect VirtualAlloc, maps an encrypted payload from .data, and spawns worker threads for file-system enumeration and HTTP POST C2 communication. It performs CPUID hypervisor-bit checks and RDTSC rotate-13 timing gates before entering the main payload loop. The C2 URL and User-Agent are built character-by-character from a base-62 alphabet table constructed via XOR-NOT decryption at runtime. No hard-coded network indicators survive in the binary.

IOC List

Indicator Type Value
SHA-256 Hash 3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde
SHA-256 (twin) Hash 136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51
TLSH Hash 89E36D21F213D073C83718F12736B5B2F39E4D6C19A96907EA980F9DBC658232F15A97 ^[tlsh.txt]
File size Static 149,504 bytes
Compile time Static 2022-09-09 01:27:01 UTC
PE CheckSum Static 0x2F448
Linker version Static 14.12

Detection Signatures

  • MITRE ATT&CK T1055 — Process Injection (reflective loader via VirtualAlloc + WriteProcessMemory) ^[r2:fcn.00406668]
  • MITRE ATT&CK T1620 — Reflective Code Loading (PEB-walking API resolution, encrypted .data payload) ^[r2:fcn.00405aec]
  • MITRE ATT&CK T1497.001 — Virtualization/Sandbox Evasion (CPUID hypervisor-bit checks) ^[r2:fcn.004010bc]
  • MITRE ATT&CK T1027.002 — Obfuscated Files or Information: Software Packing (XOR-NOT encrypted .data payload) ^[r2:fcn.00401240]
  • MITRE ATT&CK T1071.001 — Application Layer Protocol: Web Protocols (HTTP POST C2 with encrypted body) ^[r2:fcn.0040cfcc]
  • MITRE ATT&CK T1083 — File and Directory Discovery (recursive * wildcard enumeration) ^[r2:fcn.00407468]
  • MITRE ATT&CK T1059.003 — Windows Command Shell (indirect CreateProcess via resolved slot, inferred from 136b5750 report) ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

References

  • Twin deep-analysis report: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Entity page: unattributed
  • Technique page: peb-walking-api-resolution
  • OpenCTI artifact ID: a2827e28-52aa-4c17-b244-c8a547198bb4 ^[metadata.json]

Provenance

  • file.txt, exiftool.json, pefile.txt, strings.txt, ssdeep.txt, tlsh.txt, yara.txt, metadata.json, triage.json, floss.txt, capa.txt, binwalk.txt, rabin2-info.txt, dynamic-analysis.md — pre-gathered by triage pipeline.
  • Radare2 analysis: r2 v5.9.8, aaa level 3, pdg decompiler (default), 519 functions recovered.
  • Comparison diff: diff against 136b5750 pefile/rabin2/exiftool outputs.
  • No CAPE detonation — skipped due to no Windows guest available ^[dynamic-analysis.md].