616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccdunattributed-themida-x64: 616740a4 — Themida-packed PE32+ with Proton Drive masquerade, self-signed Equalizer APO cert
Executive Summary
A 2.7 MB PE32+ x64 binary packed with Themida, masquerading as Proton Drive via version info and embedded manifest, and signed with a fabricated self-signed certificate bearing the CN Equalizer APO (an open-source audio equalizer project). The entry point sits in a .boot section containing an LZ77 bit-stream decompressor that unpacks an encrypted payload at runtime. Only two imports are exposed (GetModuleHandleA, TranslateMessage). No CAPE detonation was possible; all behavior is inferred from static reverse engineering. Static-only analysis.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd |
| Size | 2,741,184 bytes (2.7 MB) ^[triage.json] |
| Type | PE32+ executable (GUI) x86-64, 8 sections ^[file.txt] |
| Compiler | MSVC 14.29 (VS 2019) linker, C/C++ ^[exiftool.json] ^[rabin2-info.txt] |
| Timestamp | Tue Sep 8 16:47:26 2020 UTC ^[pefile.txt] |
| Packing | Themida (section .themida, .boot entry point, LZ77 decompressor stub) ^[pefile.txt] ^[ghidra:entry] |
| Imports | kernel32.dll.GetModuleHandleA, USER32.dll.TranslateMessage only ^[pefile.txt] |
| Version Info | Proton Drive / Proton AG / ProtonDrive.exe / v6.5.609.101 ^[pefile.txt] ^[exiftool.json] |
| Manifest | name="Proton.AG.ProtonDrive", DPI-aware PerMonitorV2, Windows 7–10 compatibility GUIDs ^[strings.txt] |
| Certificate | Self-signed Equalizer APO (SHA-384, serial 1966469C276CBE8E44292A926BFF27D2, validity May 2026–May 2027), Sectigo timestamp counter-signature ^[terminal:openssl] |
| Overlay | 2.4 MB .boot section (entropy 7.95) with embedded encrypted payload ^[pefile.txt] |
The binary is distributed as PrimeHub.exe (per MalwareBazaar filename). No OpenCTI family label beyond exe, malware-bazaar, signed.
How It Works
Boot & Decompression
The entry point at 0x140430058 (.boot section) is a compact LZ77 bit-stream decompressor written in x64 assembly. Ghidra decompilation reveals a classic bit-reader loop: a control byte is shifted left, and when the carry-out is set, new control bytes are fetched from the input stream. The decompressor emits literal bytes, short back-references (2–3 bytes), and longer copies with explicit length/distance encoding^[ghidra:entry].
The decompressed output is an encrypted PE payload (likely the real malware) that is mapped into memory and executed without ever touching disk. The .themida section is a zero-length placeholder used by the packer to reserve virtual address space for the decrypted image.
Masquerade Layers
- Version info clones Proton AG (Swiss privacy company) — product name
Proton Drive, copyrightCopyright 2023 Proton AG, trademark string includingProtonVPNandProtonMail^[pefile.txt]. - Manifest uses the full Proton assembly identity with Common-Controls dependency and DPI awareness^[strings.txt].
- Certificate hijacks the identity of
Equalizer APO, a legitimate open-source Windows audio equalizer (GPLv2). The cert is self-signed (issuer = subject =Equalizer APO), not stolen from a real CA^[terminal:openssl]. - Filename
PrimeHub.exedoes not match version info, but the Prime/Proton word overlap may be intentional social-engineering overlap.
Resource Surface
The .rsrc section contains six PNG icons (256×256 down to 16×16) extracted by binwalk^[binwalk.txt]. These are generic Windows-application icons, not the Proton Drive branding, suggesting the packer/editor replaced or stripped original artwork.
Decompiled Behavior
Ghidra found only two functions in the .boot section: entry and FUN_1404301df. The latter initializes stack frames before the decompressor runs. The decompressor uses two stack-resident buffers (local_res8 as the source bit-stream pointer, local_res18 as the destination). No Windows API calls are made during decompression; the stub is fully position-independent^[ghidra:entry].
Capa aborted with a packed-file limitation warning — expected for Themida^[capa.txt].
C2 Infrastructure
No C2 strings, IPs, domains, mutexes, or named pipes were recovered from the outer binary. All network behavior is sealed inside the encrypted .boot payload. The LZ77 decompressor must run (or the sample must be unpacked) before any IOCs become visible.
Interesting Tidbits
- The certificate validity window is May 26 2026 – May 26 2027, indicating the signer key was generated recently (post-dating the binary's Sep 2020 compile timestamp by ~6 years). This is common for malware authors who generate fresh self-signed certs at build time to avoid aged-certificate detection heuristics^[terminal:openssl].
- Sectigo timestamp counter-signature (
Sectigo Public Time Stamping CA R36) is present but only proves when the signing occurred, not that the cert is trusted. Windows will still flag the binary as from an unknown publisher on systems with strict Authenticode policies^[terminal:openssl]. - The
.bootMZ carve at offset 9220 is garbage (encrypted), confirming Themida does not store plaintext payload headers^[terminal:python-carve]. - All first five section names are blank (eight spaces), a Themida obfuscation tactic to hinder section-based clustering^[pefile.txt].
How To Mess With It (Homelab Replication)
Toolchain: Themida (Oreans Technologies) or WinLicense with "SecureEngine" enabled. Visual Studio 2019 C++ for the payload. Target: x64 Windows GUI.
Steps:
- Build a trivial x64 PE (e.g., MessageBox hello-world).
- Pack it with Themida, enabling
.bootsection placement and import elimination. - Self-sign the output with
makecert/New-SelfSignedCertificateusing CNEqualizer APO. - Add a version-info resource cloning Proton AG metadata.
- Add an RT_MANIFEST resource with
name="Proton.AG.ProtonDrive".
Verification: Run pefile / rabin2 -I on the output — should show .themida section, two imports, blank section names, and near-maximum section entropies. Compare capa output — should hit the packed-file limitation.
Deployable Signatures
YARA Rule
rule Themida_Packed_Proton_Masquerade {
meta:
description = "Themida-packed PE with Proton Drive version-info masquerade"
author = "PacketPursuit"
date = "2026-08-01"
sha256 = "616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd"
strings:
$proton = "Proton.AG.ProtonDrive" wide ascii
$proton2 = "Proton Drive" wide ascii
$proton3 = "Copyright 2023 Proton AG" wide ascii
$equalizer = "Equalizer APO" wide ascii
$themida_sec = ".themida" ascii
condition:
uint16(0) == 0x5A4D and
($themida_sec at (pe.sections[pe.number_of_sections - 2].name)) and
2 of ($proton*) and
$equalizer
}
Behavioral Fingerprint Statement
This binary presents a heavily Themida-obfuscated x64 PE with only two imports exposed (GetModuleHandleA, TranslateMessage), blank section names on the first five sections, a .themida placeholder section, and a .boot section containing an LZ77 bit-stream decompressor entry point. The version info masquerades as Proton Drive by Proton AG, and the Authenticode signature is a self-signed certificate with CN Equalizer APO and a Sectigo timestamp counter-signature. Network indicators are not recoverable statically — the payload is encrypted and must be decompressed at runtime.
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd |
Hash |
| Filename | PrimeHub.exe |
Filename |
| Version Info | Proton Drive / Proton AG / ProtonDrive.exe |
Masquerade |
| Self-signed CN | Equalizer APO |
Certificate |
| Cert Serial | 1966469C276CBE8E44292A926BFF27D2 |
Certificate |
| Cert SHA-256 fingerprint | ADF7:08C4:9FFD:7CE6:6398:F40F:82C1:54FC:EB3B:E1DD:BDB3:DE59:013D:1224:68B2:3BBE |
Certificate |
| Timestamp CA | Sectigo Public Time Stamping CA R36 |
Counter-signature |
| Entry Point | 0x140430058 (.boot section) |
Address |
| Sections 0–4 names | (8 spaces) |
Packing artefact |
Detection Signatures
| capa rule | ATT&CK |
|---|---|
| packed file limitation (aborted) | T1027.002 — Obfuscated Files or Information: Software Packing |
References
- Artifact:
616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd - Source: MalwareBazaar / OpenCTI
- Related: unattributed, version-info-masquerade, fabricated-certificate-masquerade, themida-packed-boot-lz77
Provenance
This report was generated from static analysis artifacts in raw/analyses/616740a4ece7a72d3dad48c314db9e1f5b2f1cf2916c3de2eb27a707e1cbdccd/: file.txt, exiftool.json, pefile.txt, strings.txt, capa.txt, binwalk.txt, rabin2-info.txt, triage.json, metadata.json. Additional data from manual certificate extraction (openssl asn1parse/x509) and Ghidra decompilation (entry at 0x140430058). CAPE detonation was unavailable (no Windows guest). Tools: rabin2 5.9.8, pefile 2023.2.7, capa 9.1.0, Ghidra 11.2, openssl 3.0.15.