536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f011954e64e: 536a323c — Signed MSVC x64 XMM-loader with Chrome masquerade
Executive Summary
A 2.46 MB PE32+ x64 GUI binary (MSVC 14.0, Apr 2026) that decrypts a ~2.5 MB payload in-place via SSE2 word-wise arithmetic before jumping through an indirect thunk. Second confirmed sibling of the 54e64e MSVC 14.0 XMM-loader morph (first: 6e0ef3af). Notable deltas: valid Microsoft Authenticode signature (CN=Microsoft Corporation), Google Chrome v70 VS_VERSIONINFO masquerade, and a smaller encrypted .data payload. OpenCTI labels it coinminer; that is a pipeline misattribution.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119 |
| Size | 2,585,128 bytes (2.46 MB) ^[file.txt:1] |
| Type | PE32+ executable (GUI) x86-64, 8 sections ^[pefile.txt:1] |
| Linker | MSVC 14.0 (Visual Studio 2015+) ^[exiftool.json:18] |
| Timestamp | 2026-04-23 23:24:48 UTC ^[pefile.txt:34] |
| Signed | Yes — Microsoft Corporation / Microsoft Code Signing PCA 2011 ^[rabin2-info.txt:27] ^[binwalk.txt:5] |
| Resources | RT_VERSION only (VS_VERSIONINFO) ^[pefile.txt:197] |
VS_VERSIONINFO masquerade
CompanyName: Google Inc., FileDescription: Google Chrome, FileTitle: chrome.exe, FileVersion: 70,0,3538,110 ^[pefile.txt:321]. This is the Chrome v70 version string from late 2018, grafted onto an Apr 2026 build.
Section balance
| Section | VirtualSize | Entropy | Notes |
|---|---|---|---|
| .text | 0x4276 (~17 KB) | 6.17 | Stub + SSE2 decryption loops |
| .rdata | 0x1560 (~5 KB) | 4.53 | Import table, constants |
| .data | 0x26E800 (~2.5 MB) | 6.49 | Encrypted payload container |
| .rsrc | 0x350 | 2.83 | VS_VERSIONINFO only |
^[pefile.txt:76] ^[pefile.txt:197]
How It Works
At launch the stub runs standard MSVC C++ initialisation (__initterm, _setusermatherr, _set_app_type) then enters the payload loader at fcn.140002AF0 ^[r2:entry0] ^[r2:fcn.140001160]. The loader:
- Gates decryption on boolean flags in
.bss(0x140275fc4,0x140275fc5,0x140275fc6,0x1402760a8) ^[r2:fcn.140002AF0]. - Decrypts wide-char strings and executable content using SSE2
paddw(addend0xeb) followed bypand(mask0x00ff) in a tight loop over 128-bit chunks ^[r2:fcn.140002AF0]. - After decryption, constructs Unicode paths via
wcscat/wcscpyon stack buffers — the payload carries its own filenames/registry keys ^[r2:fcn.140002AF0]. - Resolves the final entry point through an indirect thunk (
fcn.140001394) that uses an internal hash/lookup table (constants0x397e15be,0xa5e289cc) ^[r2:fcn.140001394] ^[r2:fcn.140004C70]. - A MinGW-w64 pseudo-relocation handler (
fcn.140001880) patches RVAs in the decrypted payload before execution ^[strings.txt:50].
Decompiled Behavior
fcn.140002AF0 — payload loader (core)
- Saves XMM6–XMM8 to the stack frame, allocates 0x1738 bytes.
- Loads 16-byte chunks from
.dataintoxmm0, executespaddw xmm1, xmm0thenpand xmm1, xmm2, writes back. The addend and mask are read from.rdataconstants. - After the SSE2 pass, calls
sub.msvcrt.dll_wcslenon a decrypted wide-char buffer at0x140276030, thenwcscat/wcscpyto build paths. - Calls
VirtualProtect(imported) to remap page permissions before the indirect jump.
^[r2:fcn.140002AF0]
fcn.140004C70 — internal hash/lookup resolver
- Walks a linked list structure using hardcoded hash seeds (
0x397e15be,0x397e159a,0x397e1562,0xa5e243ca). - Compares dword values against computed hashes to locate the target function pointer.
- Returns the resolved address in
raxfor the indirect call.
^[r2:fcn.140004C70]
fcn.140004A70 — string/section initializer
- Zeroes five consecutive
xmmwordregions in.data(likely clearing decrypted plaintext buffers after use or preparing scratch space).
^[r2:fcn.140004A70]
C2 Infrastructure
None observable statically. No hardcoded IPs, domains, URLs, mutex names, or named pipes appear in imports or string dumps ^[strings.txt:1-50500]. The decrypted payload may contain C2 configuration; without dynamic execution (CAPE skipped — no Windows guest) this is unrecoverable.
Interesting Tidbits
- Valid Microsoft signature: Authenticode chain is Microsoft Corporation → Microsoft Code Signing PCA 2011 → Microsoft Root Certificate Authority 2011 ^[binwalk.txt:5]. The certificate has not been independently verified as revoked, but the build fingerprint is malicious. This is either a stolen/leaked cert or a supply-chain artifact.
- Chrome masquerade with old version: v70.0.3538.110 is from October 2018, eight years before the PE timestamp. The version string is copy-pasted from an old Chrome build ^[pefile.txt:321].
- Mixed CRT heritage: MSVC PE structure with MinGW-w64 pseudo-relocation error strings and handler. Suggests the author transplanted MinGW relocation code into an MSVC build for in-memory payload fixups ^[strings.txt:50] ^[strings.txt:64].
- Smaller payload than first sibling:
.dataraw size is 0x26E000 (2.43 MB) vs 0x2AF6D0 (2.73 MB) in6e0ef3af^[pefile.txt:123] ^[/intel/analyses/6e0ef3af90cd3e4a8d48b6e5fee62e5d88f69d007135314f9014e63cfb179e93.html]. The builder may be parameterizing payload size. - No network imports: Only
msvcrt.dll+KERNEL32.dllare imported. The payload is either fully self-contained after decryption or resolves Winsock/WinInet APIs dynamically.
How To Mess With It (Homelab Replication)
Goal: Reproduce the SSE2 word-wise decryption loop in a minimal MSVC x64 project.
- Toolchain: Visual Studio 2022 (v143), x64 Release.
- Source skeleton:
#include <immintrin.h>
#include <cstdint>
void decrypt_payload(uint16_t* data, size_t len, __m128i addend, __m128i mask) {
for (size_t i = 0; i < len / 8; i++) {
__m128i chunk = _mm_loadu_si128((__m128i*)&data[i * 8]);
chunk = _mm_add_epi16(chunk, addend);
chunk = _mm_and_si128(chunk, mask);
_mm_storeu_si128((__m128i*)&data[i * 8], chunk);
}
}
- Compile:
/O2 /arch:SSE2, thendumpbin /disasmto confirmpaddw(66 0f fd) andpand(66 0f db) opcodes. - Payload staging: Encrypt a small PE with the same loop, embed in
.data, fix up RVAs with a pseudo-relocation pass, and jump through an indirect thunk.
Deployable Signatures
YARA Rule
rule XMM_Data_Loader_54e64e_Signed_Sibling
{
meta:
description = "MSVC x64 loader with large encrypted .data, SSE2 decryption, and Microsoft Authenticode"
author = "pp-hermes"
date = "2026-08-04"
sha256 = "536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119"
family = "54e64e"
strings:
$mingw_fail = "Mingw-w64 runtime failure:" ascii
$pseudo_reloc = "Unknown pseudo relocation protocol version %d." ascii
$matherr = "_matherr(): %s in %s(%g, %g) (retval=%g)" ascii
$chrome_ver = "70,0,3538,110" wide
$paddw_pand = { 66 0f fd ?? ?? ?? ?? ?? 66 0f db ?? ?? ?? ?? ?? }
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
pe.machine == pe.MACHINE_AMD64 and
pe.sections[2].name == ".data" and
pe.sections[2].raw_data_size > 0x200000 and
pe.number_of_imports <= 2 and
pe.imports("KERNEL32.dll", "VirtualProtect") and
pe.imports("msvcrt.dll", "memcpy") and
3 of ($*) and
for any i in (0..pe.number_of_signatures): (
pe.signatures[i].subject contains "Microsoft Corporation"
)
}
Behavioral Fingerprint
This binary is a PE32+ x64 GUI executable with a minimal import table (msvcrt + KERNEL32 only). Its
.datasection exceeds 2 MB and has entropy between 6.0 and 6.8. On launch, the small.textstub (~17 KB) executes SSE2 word-wise loops (paddw/pand) against.databuffers before jumping through an indirect thunk. The binary carries a valid Microsoft Authenticode signature and Google Chrome VS_VERSIONINFO masquerade. No hardcoded network indicators, resources, or icons are present. MinGW-w64 pseudo-relocation code is linked into an MSVC PE.
IOC List
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | 536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119 |
|
| SSDeep | 49152:DXJl1eCpXd9sD8r6v+04zUdIQj/LKXTmMqFKMr7SHT1CUs/iF:DnsCpXdYbaQ7qTgJCHsLKF |
^[ssdeep.txt:2] |
| Timestamp | 0x69EAAA40 (2026-04-23 23:24:48 UTC) |
|
| Section .data size | 0x26E000 bytes | |
| Entry point | 0x1140 | |
| Image base | 0x140000000 | |
| Leaf cert CN | Microsoft Corporation |
Valid Authenticode chain |
| VS_VERSIONINFO | Google Chrome v70.0.3538.110 |
Masquerade |
Detection Signatures
| ATT&CK Technique | Evidence | Confidence |
|---|---|---|
| T1027 — Obfuscated Files or Information | ~2.5 MB .data payload encrypted with SSE2 word-wise arithmetic |
High |
| T1055 — Process Injection | Runtime decryption + VirtualProtect + indirect jump into decrypted payload | Medium (static inference) |
| T1036.005 — Match Legitimate Name or Location | Google Chrome VS_VERSIONINFO masquerade on a non-browser binary | High |
| T1204.002 — User Execution | GUI PE requires user launch | Medium |
| T1553.002 — Code Signing | Valid Microsoft Authenticode signature on malicious payload | High |
References
- 54e64e — Entity page for the OpenCTI family umbrella (now five build morphs).
- /intel/analyses/6e0ef3af90cd3e4a8d48b6e5fee62e5d88f69d007135314f901e63cfb179e93.html — First confirmed sibling of this XMM-loader morph (unsigned, no masquerade).
- coinminer — Entity page; this sample is not a coinminer (OpenCTI mislabel).
- xmm-wordwise-payload-decryption — Technique page for the SSE2 decryption pattern.
- MalwareBazaar entry:
536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119 - OpenCTI labels:
coinminer(false positive),exe,urlhaus
Provenance
Analysis derived from:
file.txt,pefile.txt,exiftool.json,rabin2-info.txt— static metadatastrings.txt— full ASCII/Unicode string dump (50,500 lines)binwalk.txt— embedded artefact scan (PKCS#7 signature block)- radare2 analysis (
aaalevel 3) — function list, decompilation, disassembly dynamic-analysis.md— CAPE skipped (no Windows guest available)