3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cdeunattributed: 3b42403b — near-identical twin of 136b5750, individualized encrypted payload
Executive Summary
A 150 KB PE32 GUI binary compiled with MSVC 14.12 on 2022-09-09. It is a near-identical structural twin to sibling 136b5750 — same entry point, same PEB-walking API resolution, same XOR-NOT alphabet cipher, same CPUID anti-VM gate, and same LCG PRNG. The only material deltas are the PE checksum, the .data section hash, and minor .pdata/.reloc variation, indicating the builder injects individualized encrypted payload data per sample while reusing the same stub. OpenCTI label: dropped-by-phorpiex. Static-only analysis (CAPE skipped).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) ^[pefile.txt:18] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal surface: GDI32 (6), USER32 (11), KERNEL32 (8) ^[pefile.txt:249] |
| YARA | Generic PE only ^[yara.txt] |
Twin relationship to 136b5750: Both binaries share the exact same section layout, entry point (0x1946F), import table, resource directory, and POGO debug metadata. The deltas are:
- PE CheckSum:
0x2F448(this sample) vs0x2BC5A(136b5750) ^[pefile.txt:66] ^[sample 136b5750/pefile.txt:66] .datasection SHA-256:d9e7e795...(this sample) vsf2e9b436...(136b5750) ^[pefile.txt:155] ^[sample 136b5750/pefile.txt:155].pdataVirtualSize:0x88E(this sample) vs0x885(136b5750) ^[pefile.txt:160] ^[sample 136b5750/pefile.txt:160].relocSHA-256 differs ^[pefile.txt:195] ^[sample 136b5750/pefile.txt:195]
The .text section is byte-identical between both samples (same MD5 cfbda2c44e51b3b0b00bcbbc767c62a2), confirming the loader stub is a shared template. The .data difference is the encrypted payload / config blob. ^[pefile.txt:93] ^[sample 136b5750/pefile.txt:93]
How It Works
For a full decompiled walkthrough of the loader stub, see the deep analysis of twin 136b5750: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html.
This sample executes the same control flow:
- Entry point (
0x41946F) →fcn.00419479→fcn.0040639c(runtime init) →fcn.00409990(main orchestrator) →fcn.00417458(thread / loader dispatch). ^[r2:fcn.00419479] - PEB-walking API resolution — no imports for
VirtualAlloc,CreateThread,InternetOpen, etc. All resolved viaInMemoryOrderModuleListtraversal and export-name hashing, cached in XOR-encrypted.dataslots at0x425xxx. ^[r2:fcn.00405aec] - XOR-NOT string crypto — hard-coded key
0x10035fffapplied to encrypted DWORD arrays, then bitwise NOT. Builds theA-Z a-z 0-9alphabet table used for runtime C2 URL / UA generation. ^[r2:fcn.00401240] - LCG PRNG (
0x40110c) —seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. Drives sleep jitter and character selection. ^[r2:fcn.0040110c] - Anti-VM gate (
0x4010bc) — CPUID leaf 1 ECX bit 31 + leaf 7 EBX bit 18 (hypervisor bits), plus RDTSC rotate-13 timing differential. ^[r2:fcn.004010bc] - File-system enumerator (
0x407468) — wildcard*recursive directory traversal via resolvedFindFirstFile/FindNextFile. ^[r2:fcn.00407468] - C2 comms (
0x40782c,0x40cfcc) — HTTP POST assembly with encrypted body, WinInet-style handle allocation, runtime-generated URL/UA via alphabet+PRNG. ^[r2:fcn.0040782c] ^[r2:fcn.0040cfcc]
Decompiled Behavior
| Address | Role | Key Observations |
|---|---|---|
0x4010bc |
Anti-debug/VM gate | CPUID hypervisor bits + RDTSC rotate-13 timing — identical to 136b5750 ^[r2:fcn.004010bc] |
0x4011c4 |
String helper | ASCII case-conversion — identical to 136b5750 ^[r2:fcn.004011c4] |
0x40110c |
LCG PRNG | Same multiplier, increment, mask as 136b5750 ^[r2:fcn.0040110c] |
0x401240 |
Decrypt stub | XOR 0x10035fff then NOT — identical to 136b5750 ^[r2:fcn.00401240] |
0x40639c |
Runtime init | Identical XOR-decoded init sequence to 136b5750 ^[r2:fcn.0040639c] |
0x406668 |
Reflective mapper | VirtualAlloc → WriteProcessMemory → VirtualProtect chain — identical ^[r2:fcn.00406668] |
0x417034 |
Main orchestrator | PEB-walk, thread creation, flag-gated dispatch — identical ^[r2:fcn.00417034] |
Radare2 analysis found 519 functions — matching the function count reported for 136b5750. The .itext section is entirely zeroed in both samples (entropy 2.93, no code), serving as padding. ^[pefile.txt:112]
C2 Infrastructure
No hard-coded C2 endpoints survive in the binary. The C2 domain, path, and User-Agent are generated at runtime via the alphabet table + LCG PRNG, then transmitted over HTTP POST with encrypted body data. For the full C2 construction logic, see the 136b5750 report. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
Interesting Tidbits
- Builder-level individualization: The
.datasection hash differs between twins, while.textis byte-identical. This means the builder recompiles or repacks the same stub with a fresh encrypted payload per drop. The.pdatasize delta (0x88Evs0x885) suggests the payload may contain a varying number of exception-handler records or function metadata. ^[pefile.txt:160] - Checksum field mismatch: The PE optional-header CheckSum is
0x2F448(this sample) vs0x2BC5A(136b5750). Windows does not enforce this field, but the builder appears to compute it differently per sample — or one sample has a corrupted checksum. ^[pefile.txt:66] - POGO debug metadata preserved: Both twins carry
IMAGE_DEBUG_TYPE_POGO(Profile Guided Optimization) records. This is unusual for crimeware and suggests the builder was compiled with MSVC Release + PGO, not a quick debug build. ^[pefile.txt:313] - SSDeep similarity: Both samples share the substring
P6glyuxE4GsUPnliByocwithin their ssdeep hashes, confirming structural homology despite differing block sizes (1536 vs 3072). ^[ssdeep.txt] ^[sample 136b5750/ssdeep.txt] - No
.rsrcpayload: Unlike theinitterm-hijack Phorpiex droppers that hide payloads inside.rsrcicons, this twin uses an encrypted.datablob — a different staging mechanism entirely. ^[pefile.txt:207]
How To Mess With It (Homelab Replication)
See the 136b5750 report for the full replication guide: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html.
To reproduce the twin effect specifically:
- Build the MSVC 14.12 reflective loader stub once.
- Encrypt two different payload blobs with the same XOR-NOT scheme.
- Embed each blob into the
.datasection of a copy of the stub. - Recompute PE checksums; observe that CheckSum and
.data/.pdatahashes diverge while.textremains identical.
Deployable Signatures
YARA Rule
Use the same rule developed for 136b5750, expanded to cover both SHA-256s:
rule unattributed_msvc14_peb_walking_xor_not_loader
{
meta:
description = "PE32 MSVC 14.12 reflective loader with XOR-NOT string crypto, PEB-walking API resolution, and LCG PRNG"
author = "PacketPursuit"
date = "2026-07-29"
sha256_1 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
sha256_2 = "3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde"
strings:
$xor_not_key = { 3D FF 5F 03 10 }
$xor_not_op = { 81 31 FF 5F 03 10 }
$lcg_mul = { 0D 66 19 00 00 }
$lcg_inc = { 35 3C EF C6 03 }
$lcg_mask = { 25 FF FF FF 07 }
$alphabet_1 = { 41 BB BF EA }
$alphabet_2 = { 45 E6 BB A7 }
$alphabet_3 = { 49 EA B7 A3 }
$post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C) + 0x18) == 0x10B and
3 of ($xor_not_*) and
2 of ($lcg_*) and
2 of ($alphabet_*) and
$post_wide
}
Behavioral Fingerprint
This binary loads with a minimal IAT (GDI32, USER32, KERNEL32 GUI APIs only), then walks the PEB InMemoryOrderModuleList to resolve ~30+ threat APIs at runtime. It allocates memory via indirect VirtualAlloc, maps an encrypted payload from .data, and spawns worker threads for file-system enumeration and HTTP POST C2 communication. It performs CPUID hypervisor-bit checks and RDTSC rotate-13 timing gates before entering the main payload loop. The C2 URL and User-Agent are built character-by-character from a base-62 alphabet table constructed via XOR-NOT decryption at runtime. No hard-coded network indicators survive in the binary.
IOC List
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | Hash | 3b42403b11b999e966158b0bea2080b863409f37cbae53845ecb1a2af67d8cde |
| SHA-256 (twin) | Hash | 136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51 |
| TLSH | Hash | 89E36D21F213D073C83718F12736B5B2F39E4D6C19A96907EA980F9DBC658232F15A97 ^[tlsh.txt] |
| File size | Static | 149,504 bytes |
| Compile time | Static | 2022-09-09 01:27:01 UTC |
| PE CheckSum | Static | 0x2F448 |
| Linker version | Static | 14.12 |
Detection Signatures
- MITRE ATT&CK T1055 — Process Injection (reflective loader via
VirtualAlloc+WriteProcessMemory) ^[r2:fcn.00406668] - MITRE ATT&CK T1620 — Reflective Code Loading (PEB-walking API resolution, encrypted
.datapayload) ^[r2:fcn.00405aec] - MITRE ATT&CK T1497.001 — Virtualization/Sandbox Evasion (CPUID hypervisor-bit checks) ^[r2:fcn.004010bc]
- MITRE ATT&CK T1027.002 — Obfuscated Files or Information: Software Packing (XOR-NOT encrypted
.datapayload) ^[r2:fcn.00401240] - MITRE ATT&CK T1071.001 — Application Layer Protocol: Web Protocols (HTTP POST C2 with encrypted body) ^[r2:fcn.0040cfcc]
- MITRE ATT&CK T1083 — File and Directory Discovery (recursive
*wildcard enumeration) ^[r2:fcn.00407468] - MITRE ATT&CK T1059.003 — Windows Command Shell (indirect
CreateProcessvia resolved slot, inferred from 136b5750 report) ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
References
- Twin deep-analysis report: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
- Entity page: unattributed
- Technique page: peb-walking-api-resolution
- OpenCTI artifact ID:
a2827e28-52aa-4c17-b244-c8a547198bb4^[metadata.json]
Provenance
file.txt,exiftool.json,pefile.txt,strings.txt,ssdeep.txt,tlsh.txt,yara.txt,metadata.json,triage.json,floss.txt,capa.txt,binwalk.txt,rabin2-info.txt,dynamic-analysis.md— pre-gathered by triage pipeline.- Radare2 analysis:
r2v5.9.8,aaalevel 3,pdgdecompiler (default), 519 functions recovered. - Comparison diff:
diffagainst136b5750pefile/rabin2/exiftool outputs. - No CAPE detonation — skipped due to no Windows guest available ^[dynamic-analysis.md].