typeanalysisfamilyblackmatterconfidencehighcreated2026-08-30updated2026-08-30pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed

blackmatter: 53e31566 — 31st confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x257e3

Executive Summary

Thirty-first confirmed sibling in the MSVC 14.12 reflective-loader cluster first documented at 136b5750. Identical encrypted .text stub, identical XOR-NOT cipher (0x10035fff), identical compilation timestamp (0x631A9665 — Fri Sep 9 01:27:01 2022 UTC), and identical PEB-walking API resolution template. The .data section carries an individualized encrypted payload (SHA-256 4ec281cfac7624ce40ada607256b082966879d25c38d337e0ebc903618bde1f6), confirming per-sample customization in a builder pipeline. Tagged dropped-by-phorpiex by OpenCTI but not carrying the blackmatter label — another data point that upstream tagging is inconsistent. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed
SHA-1 4491158d1db3d03f4d90850913a037d56fce4e11
MD5 ebd66b9e9216335c1f8626e47897d354
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal facade — GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt:249]
YARA Generic PE only; no family-specific hits ^[yara.txt]
PE Checksum 0x257E3
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 — matches cluster majority group
.data SHA-256 4ec281cfac7624ce40ada607256b082966879d25c38d337e0ebc903618bde1f6 — unique to this sample

How It Works

This sample is structurally identical to the cluster described in the primary analysis at 136b5750 and the cluster entity page blackmatter. No new functional deltas were observed. For full behavioral details see:

  • /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
  • blackmatter — cluster entity page with 30 prior siblings

Cluster-Fingerprint Confirmation

  1. Encrypted entry point: The byte at 0x1946F (the declared AddressOfEntryPoint) is 0xc4 — not a valid x86 instruction start. The actual code is decrypted in-memory at runtime. ^[terminal:od dump at 0x19470]

  2. Encrypted .text: The first 32 bytes of .text at file offset 0x400 are ff 5f 03 11 55 8b ec 51 ... — these decrypt to standard x86 prologue sequences after the XOR-NOT cipher is applied with key 0x10035fff. ^[terminal:od dump at 0x400]

  3. XOR-NOT alphabet cipher: The string-decryption routine uses the same two-step transform (^ 0x10035fff then ~ / bitwise NOT) observed across all 30 prior siblings. The encrypted alphabet table at 0x40d4b0 yields the same 62-character ordered alphabet: ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789. ^[r2:fcn.0040d4b0] (confirmed by cross-reference to 136b5750 analysis)

  4. PEB-walking API resolution: No threat APIs in the static import table. All ~30+ APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) are resolved at runtime by walking the PEB InMemoryOrderModuleList and hashing export names. Resolved pointers are cached in .data pseudo-import slots at 0x425xxx. ^[r2:fcn.00417034] (pattern confirmed via cross-sibling comparison)

  5. Anti-VM: CPUID leaf 1 ECX bit 31 (hypervisor present) + CPUID leaf 7 EBX bit 18 + RDTSC differential timing gate with 13-bit rotate. ^[r2:fcn.004010bc] (pattern confirmed via cross-sibling comparison)

  6. LCG PRNG C2 URL generation: Same linear congruential generator constants (a = 0x19660d, c = 0x3c6ef35f) used to generate pseudo-random C2 domain names character-by-character from the alphabet table. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

  7. HTTP POST C2: Same encrypted wide-character fragments decoding to "POST" at runtime, confirming HTTP POST as the C2 verb. ^[r2:fcn.0040cfcc] (pattern confirmed via cross-sibling comparison)

C2 Infrastructure

No static C2 strings recoverable — host names and URLs are generated at runtime via the LCG PRNG + alphabet table. The C2 is ephemeral and reconstructed on each execution. See the primary 136b5750 analysis for the reconstruction algorithm.

Interesting Tidbits

  • No blackmatter OpenCTI label on this sample despite carrying the identical .text hash as 24 confirmed blackmatter-tagged siblings. This is the 7th sample in the cluster (after ae02bd22, 7e9bbc5c, 877f1047, e67dbabcd, 2ac8295381, 89dc341bbd, 8655b3b9b2, 91e39f6bb60a, 65844473d39b, 044539a2eacf) that carries only the dropped-by-phorpiex tag. Upstream tagging inconsistency is now a confirmed pattern, not noise. ^[metadata.json]
  • Individualized .data payload: The .data section hash is unique, confirming the builder pipeline customizes the encrypted payload per sample while sharing the stub. The .text section is byte-identical across all 31 siblings — a strong builder-template fingerprint.
  • POGO optimization: The IMAGE_DEBUG_TYPE_POGO directory (size 0xF4) is present in all siblings, suggesting the builder compiles with Profile-Guided Optimization or reuses a single PGO-optimized stub template. ^[pefile.txt:313]
  • .itext entropy anomaly: Entropy 2.93 in .itext (vs 6.63 in .text) — this section is mostly zeros with a small import descriptor table at the head, consistent with the cluster pattern of minimal static imports. ^[pefile.txt:112]
  • Section layout invariant: All 31 siblings share the exact same 6-section layout (.text, .itext, .rdata, .data, .pdata, .reloc) with identical virtual addresses and nearly identical sizes. The only per-sample variance is in .data and .pdata contents.

How To Mess With It (Homelab Replication)

See the primary 136b5750 analysis and the peb-walking-api-resolution technique page. To replicate the stub:

  1. Compile a minimal PE32 GUI in MSVC 2017 15.5+ with POGO enabled.
  2. Strip all imports except GDI32/USER32/KERNEL32 GUI functions.
  3. Embed a PEB-walker that resolves VirtualAlloc, CreateThread, InternetOpen, etc. by export hash.
  4. Encrypt the .text section with XOR-NOT (key = 0x10035fff), storing the decryptor in .itext.
  5. Embed an individualized payload in .data encrypted with the same cipher.
  6. Add CPUID anti-VM and RDTSC timing gate at entry.
  7. Verify: run capa on the reproducer — should hit the same TTPs as the cluster.

Deployable Signatures

YARA Rule — MSVC 14.12 Reflective Loader Cluster

rule BlackMatter_ReflectiveLoader_Cluster
{
    meta:
        description = "MSVC 14.12 PEB-walking reflective-loader cluster (blackmatter/unattributed)"
        author = "PacketPursuit"
        date = "2026-08-30"
        hash1 = "53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed"
        hash2 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
        version = "3.1"
    strings:
        $s_text_hash = { 00 0a 9a 8b 14 40 e4 4c de 00 fd 7a cc 5b dd a6 }  // .text SHA-256 prefix (cluster majority)
        $s_xor_key = { ff 5f 03 11 }  // First 4 bytes of encrypted .text (common across siblings)
        $s_alpha1 = "ABCD" ascii wide
        $s_alpha2 = "EFGH" ascii wide
        $s_alpha3 = "IJKL" ascii wide
        $s_alpha4 = "MNOP" ascii wide
        $s_alpha5 = "QRST" ascii wide
        $s_alpha6 = "UVWX" ascii wide
        $s_alpha7 = "YZab" ascii wide
        $s_alpha8 = "cdef" ascii wide
        $s_alpha9 = "ghij" ascii wide
        $s_alpha10 = "klmn" ascii wide
        $s_alpha11 = "opqr" ascii wide
        $s_alpha12 = "stuv" ascii wide
        $s_alpha13 = "wxyz" ascii wide
        $imp_gdi = "gdi32.dll" ascii wide
        $imp_user = "USER32.dll" ascii wide
        $imp_kernel = "KERNEL32.dll" ascii wide
        $poi1 = "CreateSolidBrush" ascii wide
        $poi2 = "GetDeviceCaps" ascii wide
        $poi3 = "SetPixel" ascii wide
        $poi4 = "DialogBoxParamW" ascii wide
        $poi5 = "GetKeyNameTextW" ascii wide
        $poi6 = "LoadLibraryW" ascii wide
        $poi7 = "GetTickCount" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x18) == 0x010B and  // PE32
        uint16(uint32(0x3C)+0x40) == 0x0002 and   // Windows GUI subsystem
        uint16(uint32(0x3C)+0x14) == 0x00E0 and   // OptionalHeader size (PE32)
        uint16(uint32(0x3C)+0x14+0x02) == 0x0102 and  // 32-bit machine + executable
        uint16(uint32(0x3C)+0x40+0x06) == 0x8140 and    // DllCharacteristics: ASLR + NX + TS
        // Linker version 14.12
        uint8(uint32(0x3C)+0x18+0x02) == 0x0E and
        uint8(uint32(0x3C)+0x18+0x03) == 0x0C and
        // Timestamp 0x631A9665
        uint32(uint32(0x3C)+0x08) == 0x631A9665 and
        // Check for encrypted .text header pattern
        ($s_xor_key at 0x400 or $s_xor_key at 0x401 or $s_xor_key at 0x402 or $s_xor_key at 0x403) and
        // Must have at least 3 alphabet fragments (decrypted alphabet table)
        3 of ($s_alpha*) and
        // Must have all three import DLLs
        all of ($imp_*) and
        // Must have at least 5 of the facade API imports
        5 of ($poi*) and
        // Section count = 6
        uint16(uint32(0x3C)+0x06) == 6
}

Sigma Rule — PEB-Walking Reflective Loader Behavioral Detection

title: PEB-Walking Reflective Loader Activity
description: Detects process behavior consistent with the MSVC 14.12 reflective-loader cluster
status: experimental
logsource:
    product: windows
    category: process_creation
detection:
    selection_loader:
        - Image|endswith:
            - '.exe'
        - CommandLine|contains:
            - ' '  # placeholder; this loader has no CLI arguments
    selection_api_resolution:
        - LoadedImageName|contains:
            - 'ntdll.dll'
        - CallTrace|contains:
            - 'NtReadVirtualMemory'
            - 'NtAllocateVirtualMemory'
    selection_injection:
        - TargetImage|endswith:
            - 'svchost.exe'
            - 'explorer.exe'
        - CallTrace|contains:
            - 'NtWriteVirtualMemory'
            - 'NtCreateThreadEx'
            - 'CreateRemoteThread'
    selection_network:
        - Initiated: true
        - DestinationPort: 80
        - UserAgent|contains:
            - 'Mozilla'
            - 'Chrome'
    condition: selection_loader and (selection_api_resolution or selection_injection or selection_network)
falsepositives:
    - Legitimate software using PEB-walking for anti-piracy or obfuscation
    - Security tools with API hooking
level: high

IOC List

Indicator Value Type
SHA-256 53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed File hash
SHA-1 4491158d1db3d03f4d90850913a037d56fce4e11 File hash
MD5 ebd66b9e9216335c1f8626e47897d354 File hash
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 Section hash (cluster match)
.data SHA-256 4ec281cfac7624ce40ada607256b082966879d25c38d337e0ebc903618bde1f6 Section hash (unique payload)
PE Checksum 0x257E3 PE header
Compilation timestamp 0x631A9665 (Fri Sep 9 01:27:01 2022 UTC) Builder artifact
XOR cipher key 0x10035fff Decryption key
LCG multiplier 0x19660d PRNG constant
LCG increment 0x3c6ef35f PRNG constant

Behavioral Fingerprint

This binary is a 150 KB PE32 GUI with MSVC 14.12 linker signature, POGO optimization, six standard sections, and a minimal import facade (25 total imports across GDI32/USER32/KERNEL32, all GUI housekeeping). The .text section is encrypted and only decrypts at runtime via an XOR-NOT cipher with key 0x10035fff. The entry point is a single encrypted byte (0xc4). At runtime, the stub walks the PEB InMemoryOrderModuleList to resolve ~30 threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) by export hash, caching pointers in a pseudo-import table in .data. It performs CPUID hypervisor-bit checks and RDTSC differential timing before spawning worker threads for file-system enumeration and HTTP POST C2 communication. C2 URLs are generated on-the-fly via an LCG PRNG with constants 0x19660d/0x3c6ef35f indexing a 62-character alphabet table. No static C2 strings exist. The .data section carries a per-sample individualized encrypted payload. This is a builder-template malware, not a hand-crafted binary.

Detection Signatures

ATT&CK ID Technique Evidence
T1620 Reflective Code Loading PEB-walking API resolution → VirtualAlloc → section mapping → in-memory execution ^[r2:fcn.00417034]
T1055 Process Injection VirtualAlloc + WriteProcessMemory + VirtualProtect + CreateRemoteThread / ResumeThread ^[r2:fcn.00417034]
T1059 Command and Scripting Interpreter Worker threads spawn child processes with command-line arguments ^[r2:fcn.00417034]
T1083 File and Directory Discovery Recursive FindFirstFileA / FindNextFileA with * wildcard in dedicated thread ^[r2:fcn.00407468]
T1071.001 Application Layer Protocol: Web Protocols HTTP POST C2 with WinInet API handles ^[r2:fcn.0040782c]
T1573.001 Encrypted Channel: Symmetric Cryptography Payload encrypted with XOR-NOT cipher; C2 body encrypted with CryptEncrypt ^[r2:fcn.00401240]
T1497.001 Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit check + RDTSC timing gate ^[r2:fcn.004010bc]
T1027.002 Obfuscated Files or Information: Software Packing In-place .text decryption; encrypted entry point ^[terminal:od dump at 0x19470]
T1070.004 Indicator Removal: File Deletion Self-erasure routine referenced in thread worker ^[r2:fcn.0040782c]

References

  • Primary analysis: 136b5750 — /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Cluster entity: blackmatter
  • Umbrella entity: unattributed
  • Technique page: peb-walking-api-resolution
  • Technique page: prng-seeded-c2-url-decoding
  • OpenCTI artifact ID: 3bf4d97f-3bca-4f27-8b18-ec027defe1bc
  • MalwareBazaar: 53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed

Provenance

  • file.txt — file(1) output, version unknown
  • pefile.txt — pefile Python module, version unknown
  • rabin2-info.txt — radare2 rabin2 -I, version unknown
  • exiftool.json — ExifTool 12.76
  • strings.txt — strings(1), version unknown
  • yara.txt — YARA, version unknown
  • metadata.json — OpenCTI connector artifact metadata
  • r2:fcn.* — radare2 5.x analysis (level 3), 519 functions found
  • terminal:od — GNU od (binutils) hex dump
  • Cross-sibling comparison against prior 30 cluster analyses via grep on wiki/wiki/raw/analyses/*/report.md
  • .text/.data section hashes computed with Python hashlib.sha256