typeanalysisfamily54e64econfidencemediumcreated2026-08-04updated2026-08-04pemalware-familyloaderdefense-evasionevasioncompilerobfuscationsigning
SHA-256: 536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119

54e64e: 536a323c — Signed MSVC x64 XMM-loader with Chrome masquerade

Executive Summary

A 2.46 MB PE32+ x64 GUI binary (MSVC 14.0, Apr 2026) that decrypts a ~2.5 MB payload in-place via SSE2 word-wise arithmetic before jumping through an indirect thunk. Second confirmed sibling of the 54e64e MSVC 14.0 XMM-loader morph (first: 6e0ef3af). Notable deltas: valid Microsoft Authenticode signature (CN=Microsoft Corporation), Google Chrome v70 VS_VERSIONINFO masquerade, and a smaller encrypted .data payload. OpenCTI labels it coinminer; that is a pipeline misattribution.

What It Is

Field Value
SHA-256 536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119
Size 2,585,128 bytes (2.46 MB) ^[file.txt:1]
Type PE32+ executable (GUI) x86-64, 8 sections ^[pefile.txt:1]
Linker MSVC 14.0 (Visual Studio 2015+) ^[exiftool.json:18]
Timestamp 2026-04-23 23:24:48 UTC ^[pefile.txt:34]
Signed Yes — Microsoft Corporation / Microsoft Code Signing PCA 2011 ^[rabin2-info.txt:27] ^[binwalk.txt:5]
Resources RT_VERSION only (VS_VERSIONINFO) ^[pefile.txt:197]

VS_VERSIONINFO masquerade

CompanyName: Google Inc., FileDescription: Google Chrome, FileTitle: chrome.exe, FileVersion: 70,0,3538,110 ^[pefile.txt:321]. This is the Chrome v70 version string from late 2018, grafted onto an Apr 2026 build.

Section balance

Section VirtualSize Entropy Notes
.text 0x4276 (~17 KB) 6.17 Stub + SSE2 decryption loops
.rdata 0x1560 (~5 KB) 4.53 Import table, constants
.data 0x26E800 (~2.5 MB) 6.49 Encrypted payload container
.rsrc 0x350 2.83 VS_VERSIONINFO only

^[pefile.txt:76] ^[pefile.txt:197]

How It Works

At launch the stub runs standard MSVC C++ initialisation (__initterm, _setusermatherr, _set_app_type) then enters the payload loader at fcn.140002AF0 ^[r2:entry0] ^[r2:fcn.140001160]. The loader:

  1. Gates decryption on boolean flags in .bss (0x140275fc4, 0x140275fc5, 0x140275fc6, 0x1402760a8) ^[r2:fcn.140002AF0].
  2. Decrypts wide-char strings and executable content using SSE2 paddw (addend 0xeb) followed by pand (mask 0x00ff) in a tight loop over 128-bit chunks ^[r2:fcn.140002AF0].
  3. After decryption, constructs Unicode paths via wcscat/wcscpy on stack buffers — the payload carries its own filenames/registry keys ^[r2:fcn.140002AF0].
  4. Resolves the final entry point through an indirect thunk (fcn.140001394) that uses an internal hash/lookup table (constants 0x397e15be, 0xa5e289cc) ^[r2:fcn.140001394] ^[r2:fcn.140004C70].
  5. A MinGW-w64 pseudo-relocation handler (fcn.140001880) patches RVAs in the decrypted payload before execution ^[strings.txt:50].

Decompiled Behavior

fcn.140002AF0 — payload loader (core)

  • Saves XMM6–XMM8 to the stack frame, allocates 0x1738 bytes.
  • Loads 16-byte chunks from .data into xmm0, executes paddw xmm1, xmm0 then pand xmm1, xmm2, writes back. The addend and mask are read from .rdata constants.
  • After the SSE2 pass, calls sub.msvcrt.dll_wcslen on a decrypted wide-char buffer at 0x140276030, then wcscat/wcscpy to build paths.
  • Calls VirtualProtect (imported) to remap page permissions before the indirect jump.

^[r2:fcn.140002AF0]

fcn.140004C70 — internal hash/lookup resolver

  • Walks a linked list structure using hardcoded hash seeds (0x397e15be, 0x397e159a, 0x397e1562, 0xa5e243ca).
  • Compares dword values against computed hashes to locate the target function pointer.
  • Returns the resolved address in rax for the indirect call.

^[r2:fcn.140004C70]

fcn.140004A70 — string/section initializer

  • Zeroes five consecutive xmmword regions in .data (likely clearing decrypted plaintext buffers after use or preparing scratch space).

^[r2:fcn.140004A70]

C2 Infrastructure

None observable statically. No hardcoded IPs, domains, URLs, mutex names, or named pipes appear in imports or string dumps ^[strings.txt:1-50500]. The decrypted payload may contain C2 configuration; without dynamic execution (CAPE skipped — no Windows guest) this is unrecoverable.

Interesting Tidbits

  • Valid Microsoft signature: Authenticode chain is Microsoft Corporation → Microsoft Code Signing PCA 2011 → Microsoft Root Certificate Authority 2011 ^[binwalk.txt:5]. The certificate has not been independently verified as revoked, but the build fingerprint is malicious. This is either a stolen/leaked cert or a supply-chain artifact.
  • Chrome masquerade with old version: v70.0.3538.110 is from October 2018, eight years before the PE timestamp. The version string is copy-pasted from an old Chrome build ^[pefile.txt:321].
  • Mixed CRT heritage: MSVC PE structure with MinGW-w64 pseudo-relocation error strings and handler. Suggests the author transplanted MinGW relocation code into an MSVC build for in-memory payload fixups ^[strings.txt:50] ^[strings.txt:64].
  • Smaller payload than first sibling: .data raw size is 0x26E000 (2.43 MB) vs 0x2AF6D0 (2.73 MB) in 6e0ef3af ^[pefile.txt:123] ^[/intel/analyses/6e0ef3af90cd3e4a8d48b6e5fee62e5d88f69d007135314f9014e63cfb179e93.html]. The builder may be parameterizing payload size.
  • No network imports: Only msvcrt.dll + KERNEL32.dll are imported. The payload is either fully self-contained after decryption or resolves Winsock/WinInet APIs dynamically.

How To Mess With It (Homelab Replication)

Goal: Reproduce the SSE2 word-wise decryption loop in a minimal MSVC x64 project.

  1. Toolchain: Visual Studio 2022 (v143), x64 Release.
  2. Source skeleton:
#include <immintrin.h>
#include <cstdint>

void decrypt_payload(uint16_t* data, size_t len, __m128i addend, __m128i mask) {
    for (size_t i = 0; i < len / 8; i++) {
        __m128i chunk = _mm_loadu_si128((__m128i*)&data[i * 8]);
        chunk = _mm_add_epi16(chunk, addend);
        chunk = _mm_and_si128(chunk, mask);
        _mm_storeu_si128((__m128i*)&data[i * 8], chunk);
    }
}
  1. Compile: /O2 /arch:SSE2, then dumpbin /disasm to confirm paddw (66 0f fd) and pand (66 0f db) opcodes.
  2. Payload staging: Encrypt a small PE with the same loop, embed in .data, fix up RVAs with a pseudo-relocation pass, and jump through an indirect thunk.

Deployable Signatures

YARA Rule

rule XMM_Data_Loader_54e64e_Signed_Sibling
{
    meta:
        description = "MSVC x64 loader with large encrypted .data, SSE2 decryption, and Microsoft Authenticode"
        author = "pp-hermes"
        date = "2026-08-04"
        sha256 = "536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119"
        family = "54e64e"
    strings:
        $mingw_fail = "Mingw-w64 runtime failure:" ascii
        $pseudo_reloc = "Unknown pseudo relocation protocol version %d." ascii
        $matherr = "_matherr(): %s in %s(%g, %g)  (retval=%g)" ascii
        $chrome_ver = "70,0,3538,110" wide
        $paddw_pand = { 66 0f fd ?? ?? ?? ?? ?? 66 0f db ?? ?? ?? ?? ?? }
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        pe.machine == pe.MACHINE_AMD64 and
        pe.sections[2].name == ".data" and
        pe.sections[2].raw_data_size > 0x200000 and
        pe.number_of_imports <= 2 and
        pe.imports("KERNEL32.dll", "VirtualProtect") and
        pe.imports("msvcrt.dll", "memcpy") and
        3 of ($*) and
        for any i in (0..pe.number_of_signatures): (
            pe.signatures[i].subject contains "Microsoft Corporation"
        )
}

Behavioral Fingerprint

This binary is a PE32+ x64 GUI executable with a minimal import table (msvcrt + KERNEL32 only). Its .data section exceeds 2 MB and has entropy between 6.0 and 6.8. On launch, the small .text stub (~17 KB) executes SSE2 word-wise loops (paddw/pand) against .data buffers before jumping through an indirect thunk. The binary carries a valid Microsoft Authenticode signature and Google Chrome VS_VERSIONINFO masquerade. No hardcoded network indicators, resources, or icons are present. MinGW-w64 pseudo-relocation code is linked into an MSVC PE.

IOC List

Indicator Value Notes
SHA-256 536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119
SSDeep 49152:DXJl1eCpXd9sD8r6v+04zUdIQj/LKXTmMqFKMr7SHT1CUs/iF:DnsCpXdYbaQ7qTgJCHsLKF ^[ssdeep.txt:2]
Timestamp 0x69EAAA40 (2026-04-23 23:24:48 UTC)
Section .data size 0x26E000 bytes
Entry point 0x1140
Image base 0x140000000
Leaf cert CN Microsoft Corporation Valid Authenticode chain
VS_VERSIONINFO Google Chrome v70.0.3538.110 Masquerade

Detection Signatures

ATT&CK Technique Evidence Confidence
T1027 — Obfuscated Files or Information ~2.5 MB .data payload encrypted with SSE2 word-wise arithmetic High
T1055 — Process Injection Runtime decryption + VirtualProtect + indirect jump into decrypted payload Medium (static inference)
T1036.005 — Match Legitimate Name or Location Google Chrome VS_VERSIONINFO masquerade on a non-browser binary High
T1204.002 — User Execution GUI PE requires user launch Medium
T1553.002 — Code Signing Valid Microsoft Authenticode signature on malicious payload High

References

  • 54e64e — Entity page for the OpenCTI family umbrella (now five build morphs).
  • /intel/analyses/6e0ef3af90cd3e4a8d48b6e5fee62e5d88f69d007135314f901e63cfb179e93.html — First confirmed sibling of this XMM-loader morph (unsigned, no masquerade).
  • coinminer — Entity page; this sample is not a coinminer (OpenCTI mislabel).
  • xmm-wordwise-payload-decryption — Technique page for the SSE2 decryption pattern.
  • MalwareBazaar entry: 536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119
  • OpenCTI labels: coinminer (false positive), exe, urlhaus

Provenance

Analysis derived from:

  • file.txt, pefile.txt, exiftool.json, rabin2-info.txt — static metadata
  • strings.txt — full ASCII/Unicode string dump (50,500 lines)
  • binwalk.txt — embedded artefact scan (PKCS#7 signature block)
  • radare2 analysis (aaa level 3) — function list, decompilation, disassembly
  • dynamic-analysis.md — CAPE skipped (no Windows guest available)