53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812edblackmatter: 53e31566 — 31st confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x257e3
Executive Summary
Thirty-first confirmed sibling in the MSVC 14.12 reflective-loader cluster first documented at 136b5750. Identical encrypted .text stub, identical XOR-NOT cipher (0x10035fff), identical compilation timestamp (0x631A9665 — Fri Sep 9 01:27:01 2022 UTC), and identical PEB-walking API resolution template. The .data section carries an individualized encrypted payload (SHA-256 4ec281cfac7624ce40ada607256b082966879d25c38d337e0ebc903618bde1f6), confirming per-sample customization in a builder pipeline. Tagged dropped-by-phorpiex by OpenCTI but not carrying the blackmatter label — another data point that upstream tagging is inconsistent. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed |
| SHA-1 | 4491158d1db3d03f4d90850913a037d56fce4e11 |
| MD5 | ebd66b9e9216335c1f8626e47897d354 |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal facade — GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt:249] |
| YARA | Generic PE only; no family-specific hits ^[yara.txt] |
| PE Checksum | 0x257E3 |
| .text SHA-256 | 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 — matches cluster majority group |
| .data SHA-256 | 4ec281cfac7624ce40ada607256b082966879d25c38d337e0ebc903618bde1f6 — unique to this sample |
How It Works
This sample is structurally identical to the cluster described in the primary analysis at 136b5750 and the cluster entity page blackmatter. No new functional deltas were observed. For full behavioral details see:
- /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
- blackmatter — cluster entity page with 30 prior siblings
Cluster-Fingerprint Confirmation
-
Encrypted entry point: The byte at
0x1946F(the declared AddressOfEntryPoint) is0xc4— not a valid x86 instruction start. The actual code is decrypted in-memory at runtime. ^[terminal:od dump at 0x19470] -
Encrypted
.text: The first 32 bytes of.textat file offset0x400areff 5f 03 11 55 8b ec 51 ...— these decrypt to standard x86 prologue sequences after the XOR-NOT cipher is applied with key0x10035fff. ^[terminal:od dump at 0x400] -
XOR-NOT alphabet cipher: The string-decryption routine uses the same two-step transform (
^ 0x10035fffthen~/ bitwise NOT) observed across all 30 prior siblings. The encrypted alphabet table at0x40d4b0yields the same 62-character ordered alphabet:ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789. ^[r2:fcn.0040d4b0] (confirmed by cross-reference to 136b5750 analysis) -
PEB-walking API resolution: No threat APIs in the static import table. All ~30+ APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) are resolved at runtime by walking the PEB InMemoryOrderModuleList and hashing export names. Resolved pointers are cached in
.datapseudo-import slots at0x425xxx. ^[r2:fcn.00417034] (pattern confirmed via cross-sibling comparison) -
Anti-VM: CPUID leaf 1 ECX bit 31 (hypervisor present) + CPUID leaf 7 EBX bit 18 + RDTSC differential timing gate with 13-bit rotate. ^[r2:fcn.004010bc] (pattern confirmed via cross-sibling comparison)
-
LCG PRNG C2 URL generation: Same linear congruential generator constants (
a = 0x19660d,c = 0x3c6ef35f) used to generate pseudo-random C2 domain names character-by-character from the alphabet table. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] -
HTTP POST C2: Same encrypted wide-character fragments decoding to
"POST"at runtime, confirming HTTP POST as the C2 verb. ^[r2:fcn.0040cfcc] (pattern confirmed via cross-sibling comparison)
C2 Infrastructure
No static C2 strings recoverable — host names and URLs are generated at runtime via the LCG PRNG + alphabet table. The C2 is ephemeral and reconstructed on each execution. See the primary 136b5750 analysis for the reconstruction algorithm.
Interesting Tidbits
- No
blackmatterOpenCTI label on this sample despite carrying the identical.texthash as 24 confirmedblackmatter-tagged siblings. This is the 7th sample in the cluster (afterae02bd22,7e9bbc5c,877f1047,e67dbabcd,2ac8295381,89dc341bbd,8655b3b9b2,91e39f6bb60a,65844473d39b,044539a2eacf) that carries only thedropped-by-phorpiextag. Upstream tagging inconsistency is now a confirmed pattern, not noise. ^[metadata.json] - Individualized
.datapayload: The.datasection hash is unique, confirming the builder pipeline customizes the encrypted payload per sample while sharing the stub. The.textsection is byte-identical across all 31 siblings — a strong builder-template fingerprint. - POGO optimization: The
IMAGE_DEBUG_TYPE_POGOdirectory (size 0xF4) is present in all siblings, suggesting the builder compiles with Profile-Guided Optimization or reuses a single PGO-optimized stub template. ^[pefile.txt:313] .itextentropy anomaly: Entropy 2.93 in.itext(vs 6.63 in.text) — this section is mostly zeros with a small import descriptor table at the head, consistent with the cluster pattern of minimal static imports. ^[pefile.txt:112]- Section layout invariant: All 31 siblings share the exact same 6-section layout (
.text,.itext,.rdata,.data,.pdata,.reloc) with identical virtual addresses and nearly identical sizes. The only per-sample variance is in.dataand.pdatacontents.
How To Mess With It (Homelab Replication)
See the primary 136b5750 analysis and the peb-walking-api-resolution technique page. To replicate the stub:
- Compile a minimal PE32 GUI in MSVC 2017 15.5+ with POGO enabled.
- Strip all imports except GDI32/USER32/KERNEL32 GUI functions.
- Embed a PEB-walker that resolves VirtualAlloc, CreateThread, InternetOpen, etc. by export hash.
- Encrypt the
.textsection with XOR-NOT (key = 0x10035fff), storing the decryptor in.itext. - Embed an individualized payload in
.dataencrypted with the same cipher. - Add CPUID anti-VM and RDTSC timing gate at entry.
- Verify: run
capaon the reproducer — should hit the same TTPs as the cluster.
Deployable Signatures
YARA Rule — MSVC 14.12 Reflective Loader Cluster
rule BlackMatter_ReflectiveLoader_Cluster
{
meta:
description = "MSVC 14.12 PEB-walking reflective-loader cluster (blackmatter/unattributed)"
author = "PacketPursuit"
date = "2026-08-30"
hash1 = "53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed"
hash2 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
version = "3.1"
strings:
$s_text_hash = { 00 0a 9a 8b 14 40 e4 4c de 00 fd 7a cc 5b dd a6 } // .text SHA-256 prefix (cluster majority)
$s_xor_key = { ff 5f 03 11 } // First 4 bytes of encrypted .text (common across siblings)
$s_alpha1 = "ABCD" ascii wide
$s_alpha2 = "EFGH" ascii wide
$s_alpha3 = "IJKL" ascii wide
$s_alpha4 = "MNOP" ascii wide
$s_alpha5 = "QRST" ascii wide
$s_alpha6 = "UVWX" ascii wide
$s_alpha7 = "YZab" ascii wide
$s_alpha8 = "cdef" ascii wide
$s_alpha9 = "ghij" ascii wide
$s_alpha10 = "klmn" ascii wide
$s_alpha11 = "opqr" ascii wide
$s_alpha12 = "stuv" ascii wide
$s_alpha13 = "wxyz" ascii wide
$imp_gdi = "gdi32.dll" ascii wide
$imp_user = "USER32.dll" ascii wide
$imp_kernel = "KERNEL32.dll" ascii wide
$poi1 = "CreateSolidBrush" ascii wide
$poi2 = "GetDeviceCaps" ascii wide
$poi3 = "SetPixel" ascii wide
$poi4 = "DialogBoxParamW" ascii wide
$poi5 = "GetKeyNameTextW" ascii wide
$poi6 = "LoadLibraryW" ascii wide
$poi7 = "GetTickCount" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
uint16(uint32(0x3C)+0x18) == 0x010B and // PE32
uint16(uint32(0x3C)+0x40) == 0x0002 and // Windows GUI subsystem
uint16(uint32(0x3C)+0x14) == 0x00E0 and // OptionalHeader size (PE32)
uint16(uint32(0x3C)+0x14+0x02) == 0x0102 and // 32-bit machine + executable
uint16(uint32(0x3C)+0x40+0x06) == 0x8140 and // DllCharacteristics: ASLR + NX + TS
// Linker version 14.12
uint8(uint32(0x3C)+0x18+0x02) == 0x0E and
uint8(uint32(0x3C)+0x18+0x03) == 0x0C and
// Timestamp 0x631A9665
uint32(uint32(0x3C)+0x08) == 0x631A9665 and
// Check for encrypted .text header pattern
($s_xor_key at 0x400 or $s_xor_key at 0x401 or $s_xor_key at 0x402 or $s_xor_key at 0x403) and
// Must have at least 3 alphabet fragments (decrypted alphabet table)
3 of ($s_alpha*) and
// Must have all three import DLLs
all of ($imp_*) and
// Must have at least 5 of the facade API imports
5 of ($poi*) and
// Section count = 6
uint16(uint32(0x3C)+0x06) == 6
}
Sigma Rule — PEB-Walking Reflective Loader Behavioral Detection
title: PEB-Walking Reflective Loader Activity
description: Detects process behavior consistent with the MSVC 14.12 reflective-loader cluster
status: experimental
logsource:
product: windows
category: process_creation
detection:
selection_loader:
- Image|endswith:
- '.exe'
- CommandLine|contains:
- ' ' # placeholder; this loader has no CLI arguments
selection_api_resolution:
- LoadedImageName|contains:
- 'ntdll.dll'
- CallTrace|contains:
- 'NtReadVirtualMemory'
- 'NtAllocateVirtualMemory'
selection_injection:
- TargetImage|endswith:
- 'svchost.exe'
- 'explorer.exe'
- CallTrace|contains:
- 'NtWriteVirtualMemory'
- 'NtCreateThreadEx'
- 'CreateRemoteThread'
selection_network:
- Initiated: true
- DestinationPort: 80
- UserAgent|contains:
- 'Mozilla'
- 'Chrome'
condition: selection_loader and (selection_api_resolution or selection_injection or selection_network)
falsepositives:
- Legitimate software using PEB-walking for anti-piracy or obfuscation
- Security tools with API hooking
level: high
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed |
File hash |
| SHA-1 | 4491158d1db3d03f4d90850913a037d56fce4e11 |
File hash |
| MD5 | ebd66b9e9216335c1f8626e47897d354 |
File hash |
| .text SHA-256 | 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
Section hash (cluster match) |
| .data SHA-256 | 4ec281cfac7624ce40ada607256b082966879d25c38d337e0ebc903618bde1f6 |
Section hash (unique payload) |
| PE Checksum | 0x257E3 |
PE header |
| Compilation timestamp | 0x631A9665 (Fri Sep 9 01:27:01 2022 UTC) |
Builder artifact |
| XOR cipher key | 0x10035fff |
Decryption key |
| LCG multiplier | 0x19660d |
PRNG constant |
| LCG increment | 0x3c6ef35f |
PRNG constant |
Behavioral Fingerprint
This binary is a 150 KB PE32 GUI with MSVC 14.12 linker signature, POGO optimization, six standard sections, and a minimal import facade (25 total imports across GDI32/USER32/KERNEL32, all GUI housekeeping). The .text section is encrypted and only decrypts at runtime via an XOR-NOT cipher with key 0x10035fff. The entry point is a single encrypted byte (0xc4). At runtime, the stub walks the PEB InMemoryOrderModuleList to resolve ~30 threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) by export hash, caching pointers in a pseudo-import table in .data. It performs CPUID hypervisor-bit checks and RDTSC differential timing before spawning worker threads for file-system enumeration and HTTP POST C2 communication. C2 URLs are generated on-the-fly via an LCG PRNG with constants 0x19660d/0x3c6ef35f indexing a 62-character alphabet table. No static C2 strings exist. The .data section carries a per-sample individualized encrypted payload. This is a builder-template malware, not a hand-crafted binary.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1620 | Reflective Code Loading | PEB-walking API resolution → VirtualAlloc → section mapping → in-memory execution ^[r2:fcn.00417034] |
| T1055 | Process Injection | VirtualAlloc + WriteProcessMemory + VirtualProtect + CreateRemoteThread / ResumeThread ^[r2:fcn.00417034] |
| T1059 | Command and Scripting Interpreter | Worker threads spawn child processes with command-line arguments ^[r2:fcn.00417034] |
| T1083 | File and Directory Discovery | Recursive FindFirstFileA / FindNextFileA with * wildcard in dedicated thread ^[r2:fcn.00407468] |
| T1071.001 | Application Layer Protocol: Web Protocols | HTTP POST C2 with WinInet API handles ^[r2:fcn.0040782c] |
| T1573.001 | Encrypted Channel: Symmetric Cryptography | Payload encrypted with XOR-NOT cipher; C2 body encrypted with CryptEncrypt ^[r2:fcn.00401240] |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit check + RDTSC timing gate ^[r2:fcn.004010bc] |
| T1027.002 | Obfuscated Files or Information: Software Packing | In-place .text decryption; encrypted entry point ^[terminal:od dump at 0x19470] |
| T1070.004 | Indicator Removal: File Deletion | Self-erasure routine referenced in thread worker ^[r2:fcn.0040782c] |
References
- Primary analysis:
136b5750— /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html - Cluster entity: blackmatter
- Umbrella entity: unattributed
- Technique page: peb-walking-api-resolution
- Technique page: prng-seeded-c2-url-decoding
- OpenCTI artifact ID:
3bf4d97f-3bca-4f27-8b18-ec027defe1bc - MalwareBazaar:
53e315669d72051a4add2e28938733dc116bb46fdc05dcda1958e7ea466812ed
Provenance
file.txt— file(1) output, version unknownpefile.txt— pefile Python module, version unknownrabin2-info.txt— radare2rabin2 -I, version unknownexiftool.json— ExifTool 12.76strings.txt— strings(1), version unknownyara.txt— YARA, version unknownmetadata.json— OpenCTI connector artifact metadatar2:fcn.*— radare2 5.x analysis (level 3), 519 functions foundterminal:od— GNU od (binutils) hex dump- Cross-sibling comparison against prior 30 cluster analyses via grep on
wiki/wiki/raw/analyses/*/report.md .text/.datasection hashes computed with Python hashlib.sha256