78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfdd52f85: 78434b53 — Themida-packed Ubisoft Connect masquerade with fabricated Lightshot certificate
A 3.3 MB PE32+ x64 binary tagged dropped-by-amadey and d52f85. The outer binary is heavily packed with Themida/WinLicense (.boot entry, .themida placeholder, blank section names, 3 imports) and masquerades as Ubisoft Connect v4.1.9718.720 via forged version-info and embedded PNG icons. A fabricated self-signed Authenticode certificate with CN=Lightshot (post-dated 2026) accompanies a DigiCert timestamp counter-signature. The actual malicious payload lives inside the encrypted .boot decompressor and is not recoverable without runtime detonation or unpacking. This is the second distinct build morph observed under the d52f85 Amadey distribution label, confirming the label covers heterogeneous payloads.
What It Is
- SHA-256:
78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd - Size: 3,338,576 bytes ^[file.txt]
- Type: PE32+ executable (GUI) x86-64, 8 sections ^[file.txt]
- Compile timestamp: Fri May 25 16:50:04 2018 UTC ^[pefile.txt:40]
- Linker: MSVC 14.29 (VS 2019 toolchain) per exiftool ^[exiftool.json:18]
- Entry point:
0x1404CA058inside.bootsection ^[pefile.txt:56] - Packing: Themida/WinLicense —
.themidaplaceholder section,.bootdecompressor stub, blank section names, 3 imports ^[pefile.txt], ^[capa.txt] - Signing: Self-signed certificate CN=
Lightshot(valid 2026-05-26 to 2029-05-26), with DigiCert Trusted G4 timestamp counter-signature ^[strings.txt:5005-5049], ^[rabin2-info.txt:27] - Masquerade: VS_VERSIONINFO claims "Ubisoft Connect" v4.1.9718.720 by "Ubisoft Entertainment" ^[pefile.txt:327-335]
- Icons: Six PNG icons (256×256 down to 16×16) in
.rsrc^[binwalk.txt] - Dynamic: CAPE skipped — no Windows guest available ^[dynamic-analysis.md]
How It Works
The .boot section implements a Themida SecureEngine decompressor. At runtime it reads a bit-encoded LZ77 stream from the packed payload, reconstructs the original PE in memory, resolves imports manually, and transfers control. The outer PE has no meaningful API surface — only GetModuleHandleA, GetActiveWindow, and BitBlt are imported ^[pefile.txt:358-378]. The actual malicious behavior (C2, persistence, payload type) is entirely hidden inside the encrypted/compressed payload and cannot be determined from static analysis alone.
The social-engineering layer is substantial: the binary carries a complete Ubisoft Connect version-info block, XML assembly manifest with DPI-awareness settings, and six PNG icon resources at standard Windows sizes ^[binwalk.txt]. This is designed to pass casual inspection as a legitimate game launcher.
The Authenticode signature block contains a self-signed certificate with CN=Lightshot — the name of a legitimate screenshot tool — issued on 2026-05-26, eight years after the PE compile timestamp ^[pefile.txt:40], ^[strings.txt:5005-5049]. A valid DigiCert timestamp counter-signature is present, which proves when signing occurred but does not grant trust. This is a clear case of fabricated certificate masquerade.
Decompiled Behavior
Radare2 analysis recovered 816 functions inside .boot, but the entry point (0x1404ca058) is a compact bit-stream decompressor loop ^[r2:entry0]. The routine initializes a control byte (dl = 0x80), shifts left to test carry-out, and branches between literal emission and back-reference decoding. Back-references use variable-length bit fields for length and distance. No Windows API calls occur during the decompression loop; the stub writes to a destination buffer pointed to by rdi. After decompression, a secondary function (fcn.1404ca1df) performs what appears to be import table reconstruction and memory mapping before jumping to the decrypted original entry point. The decompiler output is heavily obfuscated with orphan labels and self-modifying control flow, consistent with Themida's anti-disassembly.
C2 Infrastructure
No C2 indicators recoverable from static analysis. The Themida packing encrypts all strings, imports, and network configuration. A detonated sample or unpacked dump would be required to extract C2.
Interesting Tidbits
- The compile timestamp (May 2018) and certificate validity start (May 2026) are separated by eight years, confirming the certificate was fabricated long after compilation ^[pefile.txt:40], ^[strings.txt:5005].
- The
.themidasection has raw size 0 but virtual size0x44C000— it reserves nearly 4.5 MB of virtual address space for the decrypted payload ^[pefile.txt:204-221]. - Section 6 flags are
0xE0000060(CODE | INIT_DATA | EXEC | READ | WRITE) on.themida— unusual for a placeholder, but Themida uses this to mark the region where decrypted code will be mapped. - The
BitBltimport is likely a Themida artifact for GUI initialization, not actual malware functionality. - Six PNG resources in
.rsrc(256×256, 128×128, 64×64, 48×48, 32×32, 16×16) are standard Windows icon sizes, suggesting the icon was extracted from a real Ubisoft Connect binary.
How To Mess With It (Homelab Replication)
- Obtain Themida/WinLicense trial and pack a benign x64 PE with Eliminate imports enabled.
- Verify
.themidaand.bootsections appear, import count drops to ≤3. - Compare
capaoutput — should hit the packed-file limitation warning. - For full reproduction of the masquerade layer, use Resource Hacker to inject Ubisoft Connect version-info and PNG icons.
- Generate a self-signed certificate with CN=
Lightshotusingmakecert.exeor OpenSSL, timestamp with a DigiCert TSA, and embed viasigntool sign /f.
Verification step: Run capa on the packed output — it should emit the packed-file limitation warning identical to ^[capa.txt].
Deployable Signatures
YARA
rule d52f85_themida_ubisoft_masquerade {
meta:
description = "Themida-packed PE masquerading as Ubisoft Connect with fabricated Lightshot cert"
author = "PacketPursuit"
date = "2026-08-03"
sha256 = "78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd"
strings:
$ubisoft1 = "Ubisoft.Entertainment.UbisoftConnect" wide ascii
$ubisoft2 = "Ubisoft Connect" wide ascii
$lightshot = "Lightshot" wide ascii
$themida = ".themida" ascii
$boot = ".boot" ascii
$digicert_ts = "DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1" ascii
condition:
uint16(0) == 0x5A4D and
$themida and $boot and
(($ubisoft1 or $ubisoft2) and $lightshot) or
($digicert_ts and $lightshot)
}
Behavioral fingerprint
A PE32+ x64 binary with .themida and .boot sections, entry point in .boot, ≤3 imports (typically GetModuleHandleA), and a VS_VERSIONINFO block claiming "Ubisoft Connect" by "Ubisoft Entertainment". The Authenticode signature contains a self-signed certificate with CN=Lightshot and a DigiCert timestamp counter-signature. At runtime, the .boot stub allocates RWX memory, decrypts/decompresses the payload, and resolves APIs manually before transferring control. No disk writes are required for the inner payload.
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd |
Hash |
| Compile timestamp | 2018-05-25 16:50:04 UTC | Metadata |
| Certificate CN | Lightshot |
Cert subject |
| Certificate serial | 0x143ddb5398fc33a6425295169779a34c |
Cert serial |
| Certificate validity | 2026-05-26 → 2029-05-26 | Cert window |
| Version-info product | Ubisoft Connect v4.1.9718.720 | Masquerade |
| Version-info company | Ubisoft Entertainment | Masquerade |
| Timestamp CA | DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1 | Counter-signature |
Detection Signatures
| Technique | ID | Evidence |
|---|---|---|
| Obfuscated Files or Information | T1027.002 | Themida/WinLicense packing with .boot LZ77 decompressor ^[capa.txt] |
| Masquerading | T1036.005 | Ubisoft Connect version-info, manifest, and PNG icon set ^[pefile.txt:327-335], ^[binwalk.txt] |
| Code Signing | T1553.002 | Fabricated self-signed CN=Lightshot certificate with DigiCert timestamp ^[strings.txt:5005-5049] |
References
- OpenCTI artifact:
cb1a6866-fdc9-4e7e-8810-8df6955c0e80 - MalwareBazaar tags:
d52f85,dropped-by-amadey - Related wiki pages: d52f85, themida-packed-boot-lz77, fabricated-certificate-masquerade, version-info-masquerade
Provenance
- File type identification:
filev5.45 ^[file.txt] - PE parsing:
pefile(Python) ^[pefile.txt] - Metadata extraction:
exiftoolv12.76 ^[exiftool.json] - Strings extraction:
strings(GNU binutils) ^[strings.txt] - Capability detection: Mandiant flare-capa ^[capa.txt]
- Binary analysis: radare2 v5.9.2, analysis level 3, 816 functions recovered ^[rabin2-info.txt], ^[r2:entry0]
- Certificate parsing: Python
cryptographyon PEDIRECTORY_ENTRY_SECURITY^[strings.txt:5005-5049] - Embedded artifact scan: binwalk v2.3.4 ^[binwalk.txt]