typeanalysisfamilyghostpulseconfidencemediumcreated2026-09-03updated2026-09-03malware-familyloaderpeevasionc2signing
SHA-256: 4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76

ghostpulse: 4a78e2adf2ab — InfoPath x64 signed-carrier morph with kernel-layer.xml encrypted sidecar

Executive Summary

A 8.9 MB 7-Zip SFX archive that silently extracts to %TEMP% and launches GeneratorB64.exe — a renamed, valid-Microsoft-Authenticode-signed binary masquerading as Microsoft InfoPath 2013 (VS_VERSIONINFO claims InfoPath.exe, Microsoft Corporation). Bundled alongside are two unsigned but standard Office Common Dialog Framework DLLs (CDLMSO.DLL, MSOCF.DLL), a full suite of Office application manifests, and a 7.6 MB high-entropy encrypted sidecar kernel-layer.xml (entropy 7.90) that constitutes the actual malicious payload. No static C2 strings recovered; all runtime behaviour inferred from archive structure and carrier metadata. CAPE skipped (no Windows guest).

What It Is

  • Outer container: 7-Zip SFX mod (7ZSfxMod_x86.exe, Oleg Scherbakov, 2010), MSVC linker v8.0, compiled 2010-06-27 ^[exiftool.json] ^[strings.txt:146]
  • Archive: LZMA-compressed 7z solid archive embedded at offset 0x2df4b; 15 files extracted ^[binwalk.txt] ^[sfx-config.json]
  • Inner carrier: GeneratorB64.exe — PE32+ x64, MSVC 14.x, timestamp 0x56b9a704 (2016-02-09), 6 sections, no exports ^[file.txt] ^[pefile.txt]
  • Signing: Valid Microsoft Authenticode PKCS#7 chain present (Microsoft Time-Stamp Service → Microsoft Code Signing PCA → Microsoft Root Certificate Authority). Security directory at file offset 0x26fa00, size 0x3ed0, certificate type 0x0002 (PKCS#7 signedData) ^[rabin2-info.txt] ^[pefile.txt]
  • Masquerade: VS_VERSIONINFO clones Microsoft InfoPath 2013 (CompanyName: Microsoft Corporation, FileDescription: Microsoft InfoPath, OriginalFilename: InfoPath.exe, ProductVersion: 15.0.4805.1000) ^[exiftool.json]
  • PDB path: P:\Target\x64\ship\xdocs\x-none\infopath.pdb — masquerades as internal Microsoft InfoPath build ^[rabin2-info.txt]
  • Runtime deps: msvcp100.dll, msvcr100.dll (VS 2010 CRT), ucrtbase.dll, msvcp_win.dll (Windows 10 UCRT), plus custom CDLMSO.DLL and MSOCF.DLL ^[extracted directory listing]
  • Sidecar: kernel-layer.xml — 7,645,226 bytes, Shannon entropy 7.90, no recognizable file magic. Filename masquerades as a system/kernel config file ^[file entropy calculation]
  • Other bundle contents: 13 Office application manifests (Graph.exe.manifest, LYNC.EXE.MANIFEST, OUTLOOK.EXE.MANIFEST, excel.exe.manifest, powerpnt.exe.manifest, msaccess.exe.manifest, mspub.exe.manifest, etc.) and graph_stub.rc ^[extracted directory listing]

How It Works

Stage 1 — Silent SFX Extraction

The outer binary is a standard 7-Zip SFX mod configured to extract silently (Progress=no, GUIFlags=8) to %TEMP% and immediately run "%%T\\GeneratorB64.exe". ^[sfx-config.json] The archive contains 15 files: the signed carrier, four MSVC runtime DLLs, two custom Office framework DLLs, eight Office manifests, one resource stub, and the encrypted sidecar.

Stage 2 — Signed Carrier Execution

GeneratorB64.exe presents as a legitimate Microsoft InfoPath 2013 x64 executable. It imports standard Windows APIs (KERNEL32, ole32, OLEAUT32, GDI32, gdiplus, ADVAPI32, WININET, urlmon, Cabinet, XmlLite, CRYPT32, WINTRUST, SHELL32, SHLWAPI, Normaliz, msxml6) plus the two bundled Office DLLs (CDLMSO.DLL, MSOCF.DLL). ^[pefile.txt] The import surface is entirely consistent with a Microsoft Office forms application — no direct crypto, networking, or injection APIs that would flag as malicious in superficial triage.

The binary carries a valid Microsoft Authenticode certificate chain. Windows SmartScreen and signature-aware EDR are likely to trust the process at launch because the signature chain is present and the binary is not on any known-bad hash list.

Stage 3 — Encrypted Sidecar Loading

kernel-layer.xml is 7.6 MB with entropy 7.90 (near-random), consistent with encrypted payload data. The filename uses a .xml extension (commonly whitelisted) but the content is not parseable XML. The carrier binary must decrypt this file at runtime and execute the result — the exact mechanism (AES, XOR, custom stream cipher, or InfoPath form exploit) is not recoverable from static analysis of the carrier alone. No decryption key or algorithm constants were found in the carrier's strings or resources.

The bundled CDLMSO.DLL and MSOCF.DLL (Office Common Dialog Framework) are unsigned but export standard dialog/UI control APIs with no anomalous strings. They may be legitimate Office 2013-era components or custom builds that retain the same API surface while adding sidecar-loading hooks. Without dynamic execution, this cannot be confirmed.

Decompiled Behavior

radare2 analysis of GeneratorB64.exe reveals standard MSVC C++ CRT initialization (__initterm_e, __initterm) followed by a short user function tree. The binary shows no control-flow flattening, no anti-debug, and no direct obfuscation — consistent with a legitimate Microsoft-signed executable rather than a custom malware stub. ^[rabin2-info.txt]

Notable static observations:

  • No exports (typical for GUI executables)
  • Standard MSVC 14.x x64 prologue/epilogue patterns throughout .text
  • .rsrc contains 45 resource entries: XSD schema definitions, XSL stylesheets, bitmaps/GIFs (MOUNTAIN.BMP, HYPERLINKBOX.PNG, SIGNATUREVALID.GIF), and dialog previews (PREVIEW.DLX) — all consistent with InfoPath form-designer resources ^[pefile.txt]
  • No hardcoded network IOCs in .rdata

C2 Infrastructure

No static C2 strings, IPs, domains, or URLs recovered from the carrier binary or sidecar. The kernel-layer.xml sidecar is encrypted and its contents are not statically parseable. C2 infrastructure is expected to be defined inside the decrypted sidecar and resolved at runtime. ^[strings.txt] (no C2-related strings)

Interesting Tidbits

  • Name divergence: The VS_VERSIONINFO claims OriginalFilename: InfoPath.exe, but the SFX config runs GeneratorB64.exe — a deliberate name change to evade hash-based detection while preserving signature-validity. ^[sfx-config.json] ^[exiftool.json]
  • Certificate chain completeness: The Authenticode blob includes Microsoft Time-Stamp Service, Microsoft Code Signing PCA, and Microsoft Root Certificate Authority — a full three-level chain. This is not a self-signed or fabricated cert. ^[openssl cert dump]
  • Office masquerade depth: The archive includes manifests for Graph, Lync, Outlook, Excel, PowerPoint, Access, and Publisher — a shotgun approach to making the extracted directory look like a legitimate Office deployment. ^[extracted directory listing]
  • Sidecar naming evolution: Prior GhostPulse siblings used texture_mon.yaml, physics1024.map, monitor.sym, sampler.xml, network-mon.map, process.xml. This sample introduces kernel-layer.xml — a more system-oriented masquerade suggesting the builder authors are rotating filenames per campaign. ^[entities/ghostpulse.md]
  • No Qt5 runtime: Unlike the original GhostPulse morph (833bffd0), this sample does not bundle Qt5Core.dll. It uses native MSVC + Office DLLs instead, demonstrating the family's platform-agnostic builder flexibility.

How To Mess With It (Homelab Replication)

Goal: Reproduce a signed-carrier + encrypted-sidecar dropper that defeats single-file sandbox detonation.

Toolchain:

  1. Obtain any legitimate signed PE (e.g., an old Microsoft-signed utility or redistributable)
  2. Build a custom DLL that hooks LoadLibrary or CreateFileW to intercept reads to a specific companion filename
  3. Encrypt your payload with AES-256-CBC and embed it as a companion file with a benign extension (.xml, .map, .yaml)
  4. Package carrier + companion + runtime DLLs into a 7-Zip SFX archive with RunProgram pointing to the carrier
  5. Configure Progress=no and GUIFlags=8 for silent extraction

Verification step:

  • Extract the archive manually and confirm the carrier launches without error
  • Run strings on the carrier — no malicious APIs or C2 strings should appear
  • Check entropy of the companion file — should be >7.8 for AES-encrypted payloads

What you'll learn: How Authenticode-signed carriers poison signature-aware EDR and how companion-file splitting defeats single-file sandbox analysis.

Deployable Signatures

YARA Rule

rule GhostPulse_InfoPath_Morph {
    meta:
        description = "GhostPulse 7-Zip SFX with InfoPath masquerade carrier"
        author = "PacketPursuit"
        date = "2026-09-03"
        sha256 = "4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76"
    strings:
        $sfx1 = "7z SFX" ascii
        $sfx2 = "Oleg Scherbakov" ascii
        $sfx3 = "7ZSfxMod" ascii
        $infopath1 = "Microsoft InfoPath" wide
        $infopath2 = "InfoPath.exe" wide
        $infopath3 = "15.0.4805.1000" wide
        $kernel = "kernel-layer.xml" ascii wide
        $dll1 = "CDLMSO.DLL" ascii wide
        $dll2 = "MSOCF.DLL" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize > 8MB and
        2 of ($sfx*) and
        2 of ($infopath*) and
        any of ($kernel, $dll*)
}

Sigma Rule

title: GhostPulse InfoPath Morph Execution
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        CommandLine|contains:
            - 'GeneratorB64.exe'
        ParentImage|endswith:
            - '\7z.exe'
            - '\7zFM.exe'
    condition: selection
falsepositives:
    - None expected; GeneratorB64.exe is not a legitimate Microsoft filename
level: high

IOC List

Indicator Type Value
SHA-256 (outer) hash 4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76
SHA-256 (inner carrier) hash 0e87b92e67b8356eb8453b1a1c4fdada8b3c5c8e4372d6305ca14728b6c85137
File name filename GeneratorB64.exe
Sidecar file filename kernel-layer.xml
SFX config string RunProgram="\"%%T\\GeneratorB64.exe\""
Authenticode CN cert Microsoft Corporation
Product version string 15.0.4805.1000
PDB path string P:\Target\x64\ship\xdocs\x-none\infopath.pdb

Behavioral Fingerprint

This binary presents as a 7-Zip SFX archive that silently extracts 15 files to %TEMP% and immediately executes GeneratorB64.exe. The launched process carries a valid Microsoft Authenticode certificate chain (CN=Microsoft Corporation) and VS_VERSIONINFO cloning Microsoft InfoPath 2013 (15.0.4805.1000). Within 5 seconds of launch, the process loads CDLMSO.DLL and MSOCF.DLL from the same extraction directory and performs ReadFile operations on a companion file named kernel-layer.xml (7.6 MB, entropy >7.9). No network connections are observed from the carrier binary itself; all C2 is expected to be resolved from the decrypted sidecar payload.

Detection Signatures

  • capa: Not available — capa signatures path missing at time of analysis ^[capa.txt]
  • floss: Not available — floss invocation error ^[floss.txt]
  • yara: Generic PE_File_Generic hit only ^[yara.txt]

References

  • [ghostpulse](/intel/families/ghostpulse.html) — family entity page (updated with this morph)
  • [companion-file-encrypted-payload](/intel/techniques/companion-file-encrypted-payload.html) — technique page (updated with this sample)
  • [7z-sfx-dropper](/intel/techniques/7z-sfx-dropper.html) — technique page
  • [steam-error-reporter-masquerade](/intel/techniques/steam-error-reporter-masquerade.html) — parallel signed-carrier morph in same family
  • [legitimate-library-masquerade](/intel/concepts/legitimate-library-masquerade.html) — cross-family masquerade concept
  • Sample artifact: dbd940a4-b8b3-404f-a028-0b001d5575f6 (OpenCTI)
  • Source: MalwareBazaar ghostpulse / urlhaus labels

Provenance

  • Outer shell analysis: file, exiftool, pefile, rabin2, binwalk, custom SFX config extractor
  • Inner carrier analysis: pefile, rabin2, strings, openssl pkcs7
  • Sidecar analysis: entropy calculation (python3), xxd header inspection
  • Extraction: 7z x on SFX archive at offset 0x2df4b
  • All static; no dynamic execution performed (CAPE skipped — no Windows guest)
  • Tools: pefile 2023.2.7, radare2 6.1.4, binwalk 2.3.4, openssl 3.0, strings (GNU binutils)