73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729blackmatter: 73841818 — Ninth confirmed MSVC 14.12 reflective-loader sibling, individualized .data payload
Executive Summary
A 150 KB PE32 GUI binary compiled with MSVC 14.12 on 9 Sep 2022. Confirmed ninth sibling in the blackmatter-tagged reflective-loader cluster (see [blackmatter](/intel/families/blackmatter.html) entity page). Identical stub template to siblings 136b5750, 21b12514, dc870a75, et al. — shared .text/.itext/.rdata sections, XOR-NOT string cipher (0x10035fff), PEB-walking API resolution, CPUID anti-VM, and LCG PRNG. The only delta is the individualized encrypted payload in .data and unique .pdata/.reloc contents, yielding a distinct PE checksum (0x000306CE). Static-only analysis; CAPE skipped.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729 |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5 or newer ^[pefile.txt:33] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Imports | Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI housekeeping ^[pefile.txt:249] |
| YARA | Generic PE only; no family-specific hits ^[yara.txt] |
| PE Checksum | 0x000306CE (individualized vs 0x0002BC5A on sibling 136b5750) ^[pefile.txt:66] |
How It Works
This sample is a byte-for-byte twin of the 136b5750 stub through the .text, .itext, and .rdata sections. The .text MD5 (cfbda2c44e51b3b0b00bcbbc767c62a2) matches all eight prior siblings exactly. The .data section (MD5 abc466d71ab9203ed419eacae411a4eb) and .pdata/.reloc contents are individualized per sample — consistent with a builder pipeline that injects per-sample encrypted payloads into a shared stub.
Shared behavior is documented in full on the [blackmatter](/intel/families/blackmatter.html) entity page and the primary analysis */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html*. What follows are the per-sample deltas confirmed in this build.
Per-Sample Deltas
| Section | 73841818 MD5 |
136b5750 MD5 |
Match? |
|---|---|---|---|
.text |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
Yes |
.itext |
6f4cd57381bb5584c0a0755384d25180 |
6f4cd57381bb5584c0a0755384d25180 |
Yes |
.rdata |
bd829aa493ecd52fe5bec776d207f206 |
bd829aa493ecd52fe5bec776d207f206 |
Yes |
.data |
abc466d71ab9203ed419eacae411a4eb |
(unique per sample) | No |
.pdata |
8ffe62e92508a1eee50654d38389467b |
(unique per sample) | No |
.reloc |
3f87e4c23650dfad0bee7da98889ba94 |
(unique per sample) | No |
| PE Checksum | 0x000306CE |
0x0002BC5A |
No |
The .data section is a high-entropy (7.99) encrypted payload region. Like its siblings, this sample resolves threat APIs at runtime via PEB-walking and caches them in .data pseudo-import slots. The slot layout and XOR key (0x10035fff) are identical to the cluster.
Decrypt Stub (0x401240)
Identical to all siblings. Called 147 times across the binary, performing dword-wise XOR 0x10035fff then bitwise NOT: ^[r2:fcn.00401240]
void decrypt_dwords(uint32_t *buf, int count) {
for (int i = 0; i < count; i++) {
buf[i] ^= 0x10035fff;
buf[i] = ~buf[i];
}
}
PEB-Walking API Resolution (0x405aec)
Identical stub. Walks InMemoryOrderModuleList from fs:[0x30], hashes exports, resolves pointers, and caches them. The initialization routine at 0x40639c populates the same pseudo-import table slots (0x425xxx region) with encrypted pointers for VirtualAlloc, CreateThread, InternetOpen, CryptEncrypt, etc. ^[r2:fcn.00405aec] ^[r2:fcn.0040639c]
LCG PRNG (0x40110c)
Same constants across all siblings: multiplier 0x19660d, increment 0x3c6ef35f, mask 0x7ffffff. ^[r2:fcn.0040110c]
Anti-VM / Anti-Debug (0x4010bc)
Same CPUID leaf 1 ECX[31] + leaf 7 EBX[18] hypervisor-bit checks and RDTSC rotate-13 timing gate. ^[r2:fcn.004010bc]
Decompiled Behavior
| Address | Role | Key Observations |
|---|---|---|
0x4010bc |
Anti-debug/VM gate | CPUID hypervisor bits + RDTSC rotate-13 timing ^[r2:fcn.004010bc] |
0x40110c |
LCG PRNG | Multiplier 0x19660d, increment 0x3c6ef35f, mask 0x7ffffff ^[r2:fcn.0040110c] |
0x401240 |
Decrypt stub | XOR 0x10035fff then NOT; 147 xrefs ^[r2:fcn.00401240] |
0x405aec |
PEB walker | fs:[0x30] → module list → export hash resolution ^[r2:fcn.00405aec] |
0x40639c |
Import init | Populates pseudo-import table with encrypted API pointers ^[r2:fcn.0040639c] |
All function behaviors, control-flow patterns, and cross-reference graphs match the primary 136b5750 analysis within the .text stub. No novel functions or divergent logic were observed.
C2 Infrastructure
No hard-coded C2 endpoints survive in the binary. Same runtime-generation scheme as the cluster: LCG PRNG + base-62 alphabet table → character-by-character assembly of domain, path, and User-Agent. HTTP POST verb decrypted at 0x40cfcc. Payload body encrypted via CryptEncrypt before transmission. See [blackmatter](/intel/families/blackmatter.html) for the full C2 inference.
Interesting Tidbits
- Identical
.texthash across nine samples: The stub is a compiled template, not per-sample recompiled. Only.data/.pdata/.relocchange. This is a builder pipeline, not hand-customized binaries. ^[pefile.txt] - PE checksum individualized:
0x000306CEdiffers from0x0002BC5A(136b5750) and0x0002A237(dc870a75). The checksum covers the entire image, so even small.datadeltas propagate. ^[pefile.txt:66] - POGO optimization persists: All nine samples carry
IMAGE_DEBUG_TYPE_POGOmetadata, confirming a single optimized release build used as the template. ^[pefile.txt:313] - OpenCTI label
dropped-by-phorpiex: Same delivery infrastructure as the rest of the cluster. The payload itself is not Phorpiex-authored; it is a second-stage reflective loader dropped by Phorpiex spam campaigns. ^[metadata.json]
How To Mess With It (Homelab Replication)
See the primary analysis */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html* and the [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html) technique page for full replication notes. The stub behavior is identical; any reproducer built for 136b5750 will match this sample's static fingerprint.
Deployable Signatures
YARA Rule (Updated for Cluster)
rule blackmatter_msvc1412_reflective_loader
{
meta:
description = "MSVC 14.12 reflective loader cluster with XOR-NOT string crypto and PEB-walking API resolution"
author = "PacketPursuit"
date = "2026-07-29"
sha256_1 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
sha256_2 = "73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729"
sha256_3 = "21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c"
sha256_4 = "dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4"
strings:
$xor_not_key = { 3D FF 5F 03 10 }
$xor_not_op = { 81 31 FF 5F 03 10 }
$lcg_mul = { 0D 66 19 00 00 }
$lcg_inc = { 35 3C EF C6 03 }
$lcg_mask = { 25 FF FF FF 07 }
$alphabet_1 = { 41 BB BF EA }
$alphabet_2 = { 45 E6 BB A7 }
$alphabet_3 = { 49 EA B7 A3 }
$post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C) + 0x18) == 0x10B and
3 of ($xor_not_*) and
2 of ($lcg_*) and
2 of ($alphabet_*) and
$post_wide
}
Behavioral Fingerprint
This binary loads with a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within the first 5 seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve
VirtualAlloc,CreateThread,InternetOpen, and cryptographic APIs by hash. It allocates RWX memory, copies a decrypted payload into it, and spawns a file-system enumeration thread (FindFirstFilewith"*"wildcard) alongside a network thread that assembles an HTTP POST request. The POST body is encrypted with a session key imported viaCryptImportKey. C2 domain and User-Agent are generated at runtime using a seeded LCG PRNG and a base-62 alphabet table. If executed inside a VM, CPUID leaf 1 ECX[31] or leaf 7 EBX[18] hypervisor bits cause altered code paths or early termination.
IOCs
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | 73841818b8e0513e14f50d5e4b58061f3b3772f12926b6ceafe35df114231729 |
This sample |
| SHA-1 | 17fa3b3394842596de86ddcc72af6fe8348c4dd1 |
Full binary |
| MD5 | d7793d7c599abbe1d2c4c3883a9caa84 |
Full binary |
| Compilation | Sep 9 2022 01:27:01 UTC | Timestamp 0x631A9665 (shared with all siblings) |
| Linker | 14.12 | VS 2017 15.5+ |
| TLSH | 4FE36D21F622D0B3C83718F137367571B39E8D6C29A96807DAE80F9DBCA58232F15597 |
|
| XOR Key | 0x10035fff |
Used for string + pointer encryption |
| LCG multiplier | 0x19660d |
PRNG constant |
| LCG increment | 0x3c6ef35f |
PRNG constant |
| Anti-VM | CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 | Static detection targets |
| Pseudo-import region | 0x425000–0x425fff (.data VA) |
Decrypted at runtime |
Detection Signatures
| ATT&CK Technique | Implementation |
|---|---|
| T1055 — Process Injection | Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation ^[r2:fcn.00406668] (inferred from cluster) |
| T1071.001 — Application Layer Protocol: Web Protocols | HTTP POST C2 with encrypted body; WinInet API resolution ^[r2:fcn.0040cfcc] (inferred from cluster) |
| T1027 — Obfuscated Files or Information | XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation ^[r2:fcn.00401240] |
| T1497.001 — Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) ^[r2:fcn.004010bc] |
| T1497.002 — Virtualization/Sandbox Evasion: User Activity Based | RDTSC differential timing gate ^[r2:fcn.004010bc] |
| T1083 — File and Directory Discovery | Recursive "*" enumeration via FindFirstFile / FindNextFile (inferred from cluster) |
| T1573.001 — Encrypted Channel: Symmetric Cryptography | CryptEncrypt / CryptDecrypt for C2 payload body (inferred from cluster) |
| T1105 — Ingress Tool Transfer | Downloader / payload retrieval via HTTP POST response handling (inferred from cluster) |
References
- OpenCTI artifact:
800b862d-47bc-4b5b-8001-c867d93c5c2f, labels:dropped-by-phorpiex,exe,malware-bazaar^[metadata.json] - Primary cluster analysis:
*/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html* - Cluster entity page:
[blackmatter](/intel/families/blackmatter.html) - Delivery infrastructure:
[phorpiex](/intel/families/phorpiex.html) - Technique page:
[peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html)
Provenance
Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt) and radare2 decompilation (analysis level 4) of the binary at <sample 73841818b8e0.bin>. CAPA and floss failed due to missing signature database and incorrect CLI invocation, respectively. CAPE dynamic analysis skipped — no Windows guest available. Section-by-section hash comparison against sibling 136b5750 confirms byte-for-byte stub identity with individualized payload sections. All behavioral claims that rely on cluster-shared logic are marked "inferred from cluster."