typeanalysisfamilyblackmatterconfidencelowcreated2026-07-29updated2026-07-29pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729

blackmatter: 73841818 — Ninth confirmed MSVC 14.12 reflective-loader sibling, individualized .data payload

Executive Summary

A 150 KB PE32 GUI binary compiled with MSVC 14.12 on 9 Sep 2022. Confirmed ninth sibling in the blackmatter-tagged reflective-loader cluster (see [blackmatter](/intel/families/blackmatter.html) entity page). Identical stub template to siblings 136b5750, 21b12514, dc870a75, et al. — shared .text/.itext/.rdata sections, XOR-NOT string cipher (0x10035fff), PEB-walking API resolution, CPUID anti-VM, and LCG PRNG. The only delta is the individualized encrypted payload in .data and unique .pdata/.reloc contents, yielding a distinct PE checksum (0x000306CE). Static-only analysis; CAPE skipped.

What It Is

Field Value
SHA-256 73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5 or newer ^[pefile.txt:33] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Imports Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI housekeeping ^[pefile.txt:249]
YARA Generic PE only; no family-specific hits ^[yara.txt]
PE Checksum 0x000306CE (individualized vs 0x0002BC5A on sibling 136b5750) ^[pefile.txt:66]

How It Works

This sample is a byte-for-byte twin of the 136b5750 stub through the .text, .itext, and .rdata sections. The .text MD5 (cfbda2c44e51b3b0b00bcbbc767c62a2) matches all eight prior siblings exactly. The .data section (MD5 abc466d71ab9203ed419eacae411a4eb) and .pdata/.reloc contents are individualized per sample — consistent with a builder pipeline that injects per-sample encrypted payloads into a shared stub.

Shared behavior is documented in full on the [blackmatter](/intel/families/blackmatter.html) entity page and the primary analysis */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html*. What follows are the per-sample deltas confirmed in this build.

Per-Sample Deltas

Section 73841818 MD5 136b5750 MD5 Match?
.text cfbda2c44e51b3b0b00bcbbc767c62a2 cfbda2c44e51b3b0b00bcbbc767c62a2 Yes
.itext 6f4cd57381bb5584c0a0755384d25180 6f4cd57381bb5584c0a0755384d25180 Yes
.rdata bd829aa493ecd52fe5bec776d207f206 bd829aa493ecd52fe5bec776d207f206 Yes
.data abc466d71ab9203ed419eacae411a4eb (unique per sample) No
.pdata 8ffe62e92508a1eee50654d38389467b (unique per sample) No
.reloc 3f87e4c23650dfad0bee7da98889ba94 (unique per sample) No
PE Checksum 0x000306CE 0x0002BC5A No

The .data section is a high-entropy (7.99) encrypted payload region. Like its siblings, this sample resolves threat APIs at runtime via PEB-walking and caches them in .data pseudo-import slots. The slot layout and XOR key (0x10035fff) are identical to the cluster.

Decrypt Stub (0x401240)

Identical to all siblings. Called 147 times across the binary, performing dword-wise XOR 0x10035fff then bitwise NOT: ^[r2:fcn.00401240]

void decrypt_dwords(uint32_t *buf, int count) {
    for (int i = 0; i < count; i++) {
        buf[i] ^= 0x10035fff;
        buf[i] = ~buf[i];
    }
}

PEB-Walking API Resolution (0x405aec)

Identical stub. Walks InMemoryOrderModuleList from fs:[0x30], hashes exports, resolves pointers, and caches them. The initialization routine at 0x40639c populates the same pseudo-import table slots (0x425xxx region) with encrypted pointers for VirtualAlloc, CreateThread, InternetOpen, CryptEncrypt, etc. ^[r2:fcn.00405aec] ^[r2:fcn.0040639c]

LCG PRNG (0x40110c)

Same constants across all siblings: multiplier 0x19660d, increment 0x3c6ef35f, mask 0x7ffffff. ^[r2:fcn.0040110c]

Anti-VM / Anti-Debug (0x4010bc)

Same CPUID leaf 1 ECX[31] + leaf 7 EBX[18] hypervisor-bit checks and RDTSC rotate-13 timing gate. ^[r2:fcn.004010bc]

Decompiled Behavior

Address Role Key Observations
0x4010bc Anti-debug/VM gate CPUID hypervisor bits + RDTSC rotate-13 timing ^[r2:fcn.004010bc]
0x40110c LCG PRNG Multiplier 0x19660d, increment 0x3c6ef35f, mask 0x7ffffff ^[r2:fcn.0040110c]
0x401240 Decrypt stub XOR 0x10035fff then NOT; 147 xrefs ^[r2:fcn.00401240]
0x405aec PEB walker fs:[0x30] → module list → export hash resolution ^[r2:fcn.00405aec]
0x40639c Import init Populates pseudo-import table with encrypted API pointers ^[r2:fcn.0040639c]

All function behaviors, control-flow patterns, and cross-reference graphs match the primary 136b5750 analysis within the .text stub. No novel functions or divergent logic were observed.

C2 Infrastructure

No hard-coded C2 endpoints survive in the binary. Same runtime-generation scheme as the cluster: LCG PRNG + base-62 alphabet table → character-by-character assembly of domain, path, and User-Agent. HTTP POST verb decrypted at 0x40cfcc. Payload body encrypted via CryptEncrypt before transmission. See [blackmatter](/intel/families/blackmatter.html) for the full C2 inference.

Interesting Tidbits

  • Identical .text hash across nine samples: The stub is a compiled template, not per-sample recompiled. Only .data/.pdata/.reloc change. This is a builder pipeline, not hand-customized binaries. ^[pefile.txt]
  • PE checksum individualized: 0x000306CE differs from 0x0002BC5A (136b5750) and 0x0002A237 (dc870a75). The checksum covers the entire image, so even small .data deltas propagate. ^[pefile.txt:66]
  • POGO optimization persists: All nine samples carry IMAGE_DEBUG_TYPE_POGO metadata, confirming a single optimized release build used as the template. ^[pefile.txt:313]
  • OpenCTI label dropped-by-phorpiex: Same delivery infrastructure as the rest of the cluster. The payload itself is not Phorpiex-authored; it is a second-stage reflective loader dropped by Phorpiex spam campaigns. ^[metadata.json]

How To Mess With It (Homelab Replication)

See the primary analysis */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html* and the [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html) technique page for full replication notes. The stub behavior is identical; any reproducer built for 136b5750 will match this sample's static fingerprint.

Deployable Signatures

YARA Rule (Updated for Cluster)

rule blackmatter_msvc1412_reflective_loader
{
    meta:
        description = "MSVC 14.12 reflective loader cluster with XOR-NOT string crypto and PEB-walking API resolution"
        author = "PacketPursuit"
        date = "2026-07-29"
        sha256_1 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
        sha256_2 = "73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729"
        sha256_3 = "21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c"
        sha256_4 = "dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4"
    strings:
        $xor_not_key = { 3D FF 5F 03 10 }
        $xor_not_op = { 81 31 FF 5F 03 10 }
        $lcg_mul = { 0D 66 19 00 00 }
        $lcg_inc = { 35 3C EF C6 03 }
        $lcg_mask = { 25 FF FF FF 07 }
        $alphabet_1 = { 41 BB BF EA }
        $alphabet_2 = { 45 E6 BB A7 }
        $alphabet_3 = { 49 EA B7 A3 }
        $post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + 0x18) == 0x10B and
        3 of ($xor_not_*) and
        2 of ($lcg_*) and
        2 of ($alphabet_*) and
        $post_wide
}

Behavioral Fingerprint

This binary loads with a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within the first 5 seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by hash. It allocates RWX memory, copies a decrypted payload into it, and spawns a file-system enumeration thread (FindFirstFile with "*" wildcard) alongside a network thread that assembles an HTTP POST request. The POST body is encrypted with a session key imported via CryptImportKey. C2 domain and User-Agent are generated at runtime using a seeded LCG PRNG and a base-62 alphabet table. If executed inside a VM, CPUID leaf 1 ECX[31] or leaf 7 EBX[18] hypervisor bits cause altered code paths or early termination.

IOCs

Indicator Value Notes
SHA-256 73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729 This sample
SHA-1 17fa3b3394842596de86ddcc72af6fe8348c4dd1 Full binary
MD5 d7793d7c599abbe1d2c4c3883a9caa84 Full binary
Compilation Sep 9 2022 01:27:01 UTC Timestamp 0x631A9665 (shared with all siblings)
Linker 14.12 VS 2017 15.5+
TLSH 4FE36D21F622D0B3C83718F137367571B39E8D6C29A96807DAE80F9DBCA58232F15597
XOR Key 0x10035fff Used for string + pointer encryption
LCG multiplier 0x19660d PRNG constant
LCG increment 0x3c6ef35f PRNG constant
Anti-VM CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 Static detection targets
Pseudo-import region 0x425000–0x425fff (.data VA) Decrypted at runtime

Detection Signatures

ATT&CK Technique Implementation
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation ^[r2:fcn.00406668] (inferred from cluster)
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution ^[r2:fcn.0040cfcc] (inferred from cluster)
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation ^[r2:fcn.00401240]
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) ^[r2:fcn.004010bc]
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate ^[r2:fcn.004010bc]
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile (inferred from cluster)
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body (inferred from cluster)
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling (inferred from cluster)

References

  • OpenCTI artifact: 800b862d-47bc-4b5b-8001-c867d93c5c2f, labels: dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
  • Primary cluster analysis: */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html*
  • Cluster entity page: [blackmatter](/intel/families/blackmatter.html)
  • Delivery infrastructure: [phorpiex](/intel/families/phorpiex.html)
  • Technique page: [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html)

Provenance

Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt) and radare2 decompilation (analysis level 4) of the binary at <sample 73841818b8e0.bin>. CAPA and floss failed due to missing signature database and incorrect CLI invocation, respectively. CAPE dynamic analysis skipped — no Windows guest available. Section-by-section hash comparison against sibling 136b5750 confirms byte-for-byte stub identity with individualized payload sections. All behavioral claims that rely on cluster-shared logic are marked "inferred from cluster."