typeanalysisfamilyunattributedconfidencehighcreated2026-08-28updated2026-08-28pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 65844473d39bb5b0cc86715b2da6da6fbb8dc12730d5a6caf972d132d74542f0

unattributed: 65844473d39b — 22nd confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster

Executive Summary

A 150 KB PE32 GUI binary compiled with MSVC 14.12 (VS 2017 15.5+) on 9 Sep 2022. It is the 22nd confirmed sibling in the reflective-loader cluster first characterised by 136b5750. The .text section hash matches the majority-group stub template shared by siblings ae02bd22, 21b12514, 7e9bbc5c, e67dbabcd, 2ac8295381, 89dc341bbd, 8655b3b9b2, and 91e39f6bb60a; .data and PE checksum differ, indicating an individualized encrypted payload injected by the builder pipeline. OpenCTI labels are dropped-by-phorpiex and malware-bazaar — the contested blackmatter tag was not applied, consistent with the cluster's delivery via Phorpiex spam infrastructure rather than a true BlackMatter ransomware payload. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 65844473d39bb5b0cc86715b2da6da6fbb8dc12730d5a6caf972d132d74542f0
SHA-1 5d12d573caddd78d39ef56deaf9afe44636ae19b ^[pefile.txt:95]
MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 ^[pefile.txt:93]
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) ^[pefile.txt:249]
YARA Generic PE only; no family-specific hits ^[yara.txt]
OpenCTI labels dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
Family (triage) null — no family attribution ^[triage.json]

The binary is not packed and carries no overlay. The import table is a facade: threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptEncrypt, etc.) are resolved at runtime via PEB-walking through InMemoryOrderModuleList, with pointers cached in a pseudo-import table inside the .data section.

How It Works

Stub Template (Shared with Siblings)

All structural behaviour is identical to the cluster stub described in the primary analysis for 136b5750 and the sibling reports for 21b12514, 2ac8295381, 89dc341bbd, 8655b3b9b2, and 91e39f6bb60a. In brief:

  • Entry point at 0x1946F (RVA) delegates through the MSVC C runtime in .itext to the orchestrator at ~0x417034. ^[r2:fcn.0041946f]
  • PEB-walking API resolver loads kernel32 by iterating InMemoryOrderModuleList, hashes export names, and caches ~30+ threat APIs in .data slots (0x425000–0x425fff). ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
  • XOR-NOT string cipher at 0x401240: buf[i] ^= 0x10035fff; buf[i] = ~buf[i];. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
  • Alphabet table built at 0x40d4b0 from 16 encrypted DWORDs, decrypting to ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
  • Anti-VM gate at 0x4010bc: CPUID leaf 1 ECX[31] (hypervisor bit), leaf 7 EBX[18], plus RDTSC rotate-13 differential timing. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
  • LCG PRNG at 0x40110c: seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. Used for runtime C2 URL generation. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
  • Threading model: file-system enumeration thread (0x407468) and C2 communication thread (0x40782c), with a reflective PE loader / memory mapper at 0x406668. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

Per-Sample Delta

Attribute 65844473d39b (this) 91e39f6bb60a (21st sibling) 8655b3b9b2 (20th sibling)
PE Checksum 0x2b4ee 0x33158 0x2EBD4
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 cfbda2c44e51b3b0b00bcbbc767c62a2 cfbda2c44e51b3b0b00bcbbc767c62a2
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369
.data SHA-256 cca2478b8a97dd88718d4d7bffc8d0d31f38ac93e3aba43120059c66b89edea9 108818f3fd84a18bcfa9e00c5fc0f2707e643e31364c3bbb94be05ef7b7185e7 035c5d8e...

The .text hash match with the majority group confirms this sample shares the exact same compiled stub template. The .data hash divergence confirms the builder injects a per-sample encrypted payload. The PE checksum differs, which is expected because checksum covers the entire image including .data. ^[pefile.txt]

Decompiled Behavior

Radare2 decompilation of the POGO-optimized entry point (0x41946f) yields a 1-byte chop stub — the MSVC C runtime entry trampoline is heavily optimised and the decompiler loses the context. The real logic is recovered at fcn.0040639c and onward, identical to the sibling analysis. For full decompiled pseudocode, pseudo-import slot map, and control-flow details, see the primary analysis: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html. ^[r2:fcn.0041946f]

C2 Infrastructure

No static C2 URLs, domains, or IPs are recoverable. All network indicators are generated at runtime by the LCG PRNG and encoded via the base-62 alphabet table. C2 communication uses WinInet-style HTTP POST with encrypted body data (CryptEncrypt / CryptDecrypt). See the primary sibling analysis for the reconstructed C2 wire format. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

Interesting Tidbits

  • OpenCTI label gap: This sample is tagged dropped-by-phorpiex but not blackmatter, consistent with the 18th–21st siblings and confirming the blackmatter label is inconsistently applied by the upstream connector and is not a reliable family signal. ^[metadata.json]
  • .itext sparse layout: The .itext section is 0x600 bytes on disk but only 0x546 bytes of code; the remainder is zero-padded. The entry-point RVA 0x1946F falls at offset 0x46F within .itext, preceded by ~1 KB of padding. Consistent with POGO link-time code generation placing cold paths at the section tail. ^[pefile.txt]
  • capa / floss failure: Both tools failed during triage — capa due to missing signatures, floss due to argument parsing errors. This is a pipeline artefact, not a binary anti-analysis measure. ^[capa.txt] ^[floss.txt]
  • No version-info masquerade: Unlike many Phorpiex-delivered samples, this binary carries no VS_VERSIONINFO resource at all (resource directory size = 0). ^[pefile.txt:207]
  • 22nd sibling: Extends the known cluster from 21 to 22 confirmed samples, all sharing the Sep 9 2022 compilation timestamp — a single builder batch or a heavily reused template.

How To Mess With It (Homelab Replication)

See the primary sibling analysis for a full replication recipe. The stub template is MSVC 14.12 C++ with POGO (/LTCG:PGOptimize), compiled for x86 Windows GUI. To reproduce the behavioural fingerprint:

  1. Build a 32-bit PE with MSVC 14.12, enable /guard:cf and /LTCG:PGOptimize.
  2. Implement PEB-walking InMemoryOrderModuleList traversal with export-name hashing.
  3. Encrypt all strings with XOR-NOT (key = 0x10035fff), store in .data.
  4. Add CPUID leaf 1/7 checks and RDTSC differential timing gate.
  5. Implement LCG PRNG (0x19660d/0x3c6ef35f) for runtime URL generation.
  6. Compile with minimal static imports (GDI32/USER32/KERNEL32 facade only).
  7. Run capa on the reproducer and compare capability hits to sibling reports.

Deployable Signatures

YARA Rule — MSVC 14.12 POGO Reflective Loader Stub

rule MSVC_1412_Pogo_ReflectiveLoader_Stub
{
    meta:
        description = "MSVC 14.12 POGO reflective loader stub with PEB-walking, XOR-NOT crypto, and CPUID anti-VM"
        author = "PacketPursuit SOC"
        date = "2026-08-28"
        sha256 = "65844473d39bb5b0cc86715b2da6da6fbb8dc12730d5a6caf972d132d74542f0"
    strings:
        $peb_walk_prologue = { 64 A1 30 00 00 00 }           // mov eax, fs:[0x30]  (PEB)
        $xor_not_key = { 3D FF 5F 03 10 }                   // cmp eax, 0x10035fff (key material)
        $lcg_mul = { 0D 60 96 19 00 }                       // 0x19660d multiplier
        $lcg_inc = { 35 5F F3 6E 3C }                        // 0x3c6ef35f increment
        $cpuid_leaf1 = { 0F A2 81 E1 00 00 00 80 }          // cpuid; test ecx, 0x80000000
        $pogo_debug = { 0D 00 00 00 00 F4 00 00 00 }       // IMAGE_DEBUG_TYPE_POGO header
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x18) == 0x10B and              // PE32
        uint8(uint32(0x3C)+0x5D) == 0x0E and               // MajorLinkerVersion = 14
        uint8(uint32(0x3C)+0x5E) == 0x0C and               // MinorLinkerVersion = 12
        filesize <= 200KB and
        #peb_walk_prologue >= 1 and
        #pogo_debug >= 1 and
        (
            $xor_not_key or
            ($lcg_mul and $lcg_inc) or
            $cpuid_leaf1
        )
}

IOC List

Indicator Value Type
SHA-256 65844473d39bb5b0cc86715b2da6da6fbb8dc12730d5a6caf972d132d74542f0 Hash
SHA-1 5d12d573caddd78d39ef56deaf9afe44636ae19b Hash ^[pefile.txt:95]
MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 Hash ^[pefile.txt:93]
PE Timestamp 0x631A9665 (Fri Sep 9 01:27:01 2022 UTC) Compilation
PE Checksum 0x2b4ee Header
XOR-NOT Key 0x10035fff Crypto
LCG Multiplier 0x19660d PRNG
LCG Increment 0x3c6ef35f PRNG
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 Section hash
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 Section hash
.data SHA-256 cca2478b8a97dd88718d4d7bffc8d0d31f38ac93e3aba43120059c66b89edea9 Section hash
Pseudo-import region 0x425000–0x425fff (.data VA) Runtime table
Anti-VM CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 Evasion
Delivery label dropped-by-phorpiex OpenCTI tag

Behavioral Fingerprint Statement

This binary is a 150 KB PE32 GUI with exactly six sections (.text, .itext, .rdata, .data, .pdata, .reloc), a POGO debug directory, linker version 14.12, and a static import surface of only 25 API imports across GDI32, USER32, and KERNEL32. On execution, it resolves threat APIs via PEB-walking, spawns dual worker threads for file-system enumeration and HTTP C2, and maps a reflective payload into self-allocated memory. The payload is encrypted in .data with a per-sample unique hash. Network C2 is generated at runtime via an LCG PRNG and transmitted over HTTP POST with encrypted bodies. VM/sandbox evasion is enforced by CPUID hypervisor-bit checks and RDTSC timing gates.

Detection Signatures (ATT&CK Mapping)

Technique Implementation Evidence
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation Sibling analysis ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

References

  • Artifact ID: 90397b36-6746-43ae-8b32-4d0d4a40625b ^[triage.json]
  • Primary structural analysis (stub template): /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Sibling delta analysis: /intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html
  • 20th sibling (prior): /intel/analyses/8655b3b9b297ef153354a4f9778d7b621dd94adf4ca66d526cd7f0095b7fe5d4.html
  • 21st sibling (prior): /intel/analyses/91e39f6bb60a3860e6d1dc1fb711a8865281407614d5d106d03678c8723f2ddf.html
  • Cluster catalogue (contested blackmatter label): blackmatter
  • Delivery infrastructure: phorpiex
  • API resolution technique: peb-walking-api-resolution
  • PRNG C2 technique: prng-seeded-c2-url-decoding
  • Umbrella entity for unattributed samples: unattributed

Provenance

Analysis derived from file, exiftool, pefile, rabin2, radare2, yara, binwalk, capa (errored), and floss (errored) outputs captured in raw/analyses/65844473d39bb5b0cc86715b2da6da6fbb8dc12730d5a6caf972d132d74542f0/. Cluster traits verified by cross-referencing section hashes against siblings 136b5750, 21b12514, 3b42403b, 0017ecc5, 73841818, a2dca6ef, 34ca794e, cdc7d79a, 877f1047, 7e9bbc5c, e67dbabcd, 2ac8295381, 89dc341bbd, 8655b3b9b2, 91e39f6bb60a, and ae02bd22. Report drafted 2026-08-28.