typeanalysisfamilyd52f85confidencemediumcreated2026-08-03updated2026-08-03pepackerthemidamasqueradingsigningevasiondefense-evasion
SHA-256: 78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd

d52f85: 78434b53 — Themida-packed Ubisoft Connect masquerade with fabricated Lightshot certificate

A 3.3 MB PE32+ x64 binary tagged dropped-by-amadey and d52f85. The outer binary is heavily packed with Themida/WinLicense (.boot entry, .themida placeholder, blank section names, 3 imports) and masquerades as Ubisoft Connect v4.1.9718.720 via forged version-info and embedded PNG icons. A fabricated self-signed Authenticode certificate with CN=Lightshot (post-dated 2026) accompanies a DigiCert timestamp counter-signature. The actual malicious payload lives inside the encrypted .boot decompressor and is not recoverable without runtime detonation or unpacking. This is the second distinct build morph observed under the d52f85 Amadey distribution label, confirming the label covers heterogeneous payloads.

What It Is

  • SHA-256: 78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd
  • Size: 3,338,576 bytes ^[file.txt]
  • Type: PE32+ executable (GUI) x86-64, 8 sections ^[file.txt]
  • Compile timestamp: Fri May 25 16:50:04 2018 UTC ^[pefile.txt:40]
  • Linker: MSVC 14.29 (VS 2019 toolchain) per exiftool ^[exiftool.json:18]
  • Entry point: 0x1404CA058 inside .boot section ^[pefile.txt:56]
  • Packing: Themida/WinLicense — .themida placeholder section, .boot decompressor stub, blank section names, 3 imports ^[pefile.txt], ^[capa.txt]
  • Signing: Self-signed certificate CN=Lightshot (valid 2026-05-26 to 2029-05-26), with DigiCert Trusted G4 timestamp counter-signature ^[strings.txt:5005-5049], ^[rabin2-info.txt:27]
  • Masquerade: VS_VERSIONINFO claims "Ubisoft Connect" v4.1.9718.720 by "Ubisoft Entertainment" ^[pefile.txt:327-335]
  • Icons: Six PNG icons (256×256 down to 16×16) in .rsrc ^[binwalk.txt]
  • Dynamic: CAPE skipped — no Windows guest available ^[dynamic-analysis.md]

How It Works

The .boot section implements a Themida SecureEngine decompressor. At runtime it reads a bit-encoded LZ77 stream from the packed payload, reconstructs the original PE in memory, resolves imports manually, and transfers control. The outer PE has no meaningful API surface — only GetModuleHandleA, GetActiveWindow, and BitBlt are imported ^[pefile.txt:358-378]. The actual malicious behavior (C2, persistence, payload type) is entirely hidden inside the encrypted/compressed payload and cannot be determined from static analysis alone.

The social-engineering layer is substantial: the binary carries a complete Ubisoft Connect version-info block, XML assembly manifest with DPI-awareness settings, and six PNG icon resources at standard Windows sizes ^[binwalk.txt]. This is designed to pass casual inspection as a legitimate game launcher.

The Authenticode signature block contains a self-signed certificate with CN=Lightshot — the name of a legitimate screenshot tool — issued on 2026-05-26, eight years after the PE compile timestamp ^[pefile.txt:40], ^[strings.txt:5005-5049]. A valid DigiCert timestamp counter-signature is present, which proves when signing occurred but does not grant trust. This is a clear case of fabricated certificate masquerade.

Decompiled Behavior

Radare2 analysis recovered 816 functions inside .boot, but the entry point (0x1404ca058) is a compact bit-stream decompressor loop ^[r2:entry0]. The routine initializes a control byte (dl = 0x80), shifts left to test carry-out, and branches between literal emission and back-reference decoding. Back-references use variable-length bit fields for length and distance. No Windows API calls occur during the decompression loop; the stub writes to a destination buffer pointed to by rdi. After decompression, a secondary function (fcn.1404ca1df) performs what appears to be import table reconstruction and memory mapping before jumping to the decrypted original entry point. The decompiler output is heavily obfuscated with orphan labels and self-modifying control flow, consistent with Themida's anti-disassembly.

C2 Infrastructure

No C2 indicators recoverable from static analysis. The Themida packing encrypts all strings, imports, and network configuration. A detonated sample or unpacked dump would be required to extract C2.

Interesting Tidbits

  • The compile timestamp (May 2018) and certificate validity start (May 2026) are separated by eight years, confirming the certificate was fabricated long after compilation ^[pefile.txt:40], ^[strings.txt:5005].
  • The .themida section has raw size 0 but virtual size 0x44C000 — it reserves nearly 4.5 MB of virtual address space for the decrypted payload ^[pefile.txt:204-221].
  • Section 6 flags are 0xE0000060 (CODE | INIT_DATA | EXEC | READ | WRITE) on .themida — unusual for a placeholder, but Themida uses this to mark the region where decrypted code will be mapped.
  • The BitBlt import is likely a Themida artifact for GUI initialization, not actual malware functionality.
  • Six PNG resources in .rsrc (256×256, 128×128, 64×64, 48×48, 32×32, 16×16) are standard Windows icon sizes, suggesting the icon was extracted from a real Ubisoft Connect binary.

How To Mess With It (Homelab Replication)

  1. Obtain Themida/WinLicense trial and pack a benign x64 PE with Eliminate imports enabled.
  2. Verify .themida and .boot sections appear, import count drops to ≤3.
  3. Compare capa output — should hit the packed-file limitation warning.
  4. For full reproduction of the masquerade layer, use Resource Hacker to inject Ubisoft Connect version-info and PNG icons.
  5. Generate a self-signed certificate with CN=Lightshot using makecert.exe or OpenSSL, timestamp with a DigiCert TSA, and embed via signtool sign /f.

Verification step: Run capa on the packed output — it should emit the packed-file limitation warning identical to ^[capa.txt].

Deployable Signatures

YARA

rule d52f85_themida_ubisoft_masquerade {
    meta:
        description = "Themida-packed PE masquerading as Ubisoft Connect with fabricated Lightshot cert"
        author = "PacketPursuit"
        date = "2026-08-03"
        sha256 = "78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd"
    strings:
        $ubisoft1 = "Ubisoft.Entertainment.UbisoftConnect" wide ascii
        $ubisoft2 = "Ubisoft Connect" wide ascii
        $lightshot = "Lightshot" wide ascii
        $themida = ".themida" ascii
        $boot = ".boot" ascii
        $digicert_ts = "DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1" ascii
    condition:
        uint16(0) == 0x5A4D and
        $themida and $boot and
        (($ubisoft1 or $ubisoft2) and $lightshot) or
        ($digicert_ts and $lightshot)
}

Behavioral fingerprint

A PE32+ x64 binary with .themida and .boot sections, entry point in .boot, ≤3 imports (typically GetModuleHandleA), and a VS_VERSIONINFO block claiming "Ubisoft Connect" by "Ubisoft Entertainment". The Authenticode signature contains a self-signed certificate with CN=Lightshot and a DigiCert timestamp counter-signature. At runtime, the .boot stub allocates RWX memory, decrypts/decompresses the payload, and resolves APIs manually before transferring control. No disk writes are required for the inner payload.

IOC list

Indicator Value Type
SHA-256 78434b53d284d4537e6d44a9373da8ef86d15c0cd36f32ce695dfd82db7eccfd Hash
Compile timestamp 2018-05-25 16:50:04 UTC Metadata
Certificate CN Lightshot Cert subject
Certificate serial 0x143ddb5398fc33a6425295169779a34c Cert serial
Certificate validity 2026-05-26 → 2029-05-26 Cert window
Version-info product Ubisoft Connect v4.1.9718.720 Masquerade
Version-info company Ubisoft Entertainment Masquerade
Timestamp CA DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1 Counter-signature

Detection Signatures

Technique ID Evidence
Obfuscated Files or Information T1027.002 Themida/WinLicense packing with .boot LZ77 decompressor ^[capa.txt]
Masquerading T1036.005 Ubisoft Connect version-info, manifest, and PNG icon set ^[pefile.txt:327-335], ^[binwalk.txt]
Code Signing T1553.002 Fabricated self-signed CN=Lightshot certificate with DigiCert timestamp ^[strings.txt:5005-5049]

References

Provenance

  • File type identification: file v5.45 ^[file.txt]
  • PE parsing: pefile (Python) ^[pefile.txt]
  • Metadata extraction: exiftool v12.76 ^[exiftool.json]
  • Strings extraction: strings (GNU binutils) ^[strings.txt]
  • Capability detection: Mandiant flare-capa ^[capa.txt]
  • Binary analysis: radare2 v5.9.2, analysis level 3, 816 functions recovered ^[rabin2-info.txt], ^[r2:entry0]
  • Certificate parsing: Python cryptography on PE DIRECTORY_ENTRY_SECURITY ^[strings.txt:5005-5049]
  • Embedded artifact scan: binwalk v2.3.4 ^[binwalk.txt]