typeanalysisfamilyunattributedconfidencemediumcreated2026-08-27updated2026-08-27pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 7e9bbc5c0e10efd2ae5509243895cc74a242051cd48ad08055e99ac9da0ee781

unattributed: 7e9bbc5c — fifteenth confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster

Executive Summary

A 150 KB PE32 GUI binary compiled with MSVC 14.12 (VS 2017 15.5+) on 9 Sep 2022. It is the fifteenth confirmed sibling in the reflective-loader cluster first characterised by 136b5750. The .text section hash matches siblings 21b12514 and ae02bd22, confirming the same compiled stub template; .data and PE checksum differ, indicating an individualized encrypted payload injected by the builder pipeline. OpenCTI labels are dropped-by-phorpiex and malware-bazaar — no contested blackmatter tag on this sample, consistent with delivery via Phorpiex spam infrastructure rather than a true BlackMatter ransomware payload. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 7e9bbc5c0e10efd2ae5509243895cc74a242051cd48ad08055e99ac9da0ee781
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) ^[pefile.txt:249]
YARA Generic PE only; no family-specific hits ^[yara.txt]
OpenCTI labels dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
Family (triage) null — no family attribution ^[triage.json]

The binary is not packed and carries no overlay. The import table is a facade: threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptEncrypt, etc.) are resolved at runtime via PEB-walking through InMemoryOrderModuleList, with pointers cached in a pseudo-import table inside the .data section.

How It Works

Stub Template (Shared with Siblings)

All structural behaviour is identical to the cluster stub described in the primary analysis for 136b5750 and the sibling reports for 21b12514 and ae02bd22. In brief:

  • Entry point at 0x1946F (RVA) delegates through the MSVC C runtime in .itext to the orchestrator at ~0x417034. ^[r2:fcn.0041946f]
  • PEB-walking API resolver loads kernel32 by iterating InMemoryOrderModuleList, hashes export names, and caches ~30+ threat APIs in .data slots (0x425000–0x425fff). ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
  • XOR-NOT string cipher at 0x401240: buf[i] ^= 0x10035fff; buf[i] = ~buf[i];. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
  • Alphabet table built at 0x40d4b0 from 16 encrypted DWORDs, decrypting to ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
  • Anti-VM gate at 0x4010bc: CPUID leaf 1 ECX[31] (hypervisor bit), leaf 7 EBX[18], plus RDTSC rotate-13 differential timing. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
  • LCG PRNG at 0x40110c: seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. Used for runtime C2 URL generation. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
  • Threading model: file-system enumeration thread (0x407468) and C2 communication thread (0x40782c), with a reflective PE loader / memory mapper at 0x406668. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

Per-Sample Delta

Attribute 7e9bbc5c (this) ae02bd22 (sibling) 21b12514 (sibling) 136b5750 (sibling)
PE Checksum 0x2688E 0x2BE18 0x2F55C 0x2BC5A
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 cfbda2c44e51b3b0b00bcbbc767c62a2 cfbda2c44e51b3b0b00bcbbc767c62a2 299ed0bc52def60ad9927e69f2bba088
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 be2dc068760039090865f3696066df5249a7601a1cf9be26bcb7096af81ef121
.data SHA-256 6e67c2dba575a363a341eff397fa1295442dcfe8c26521d972b1c28ad36a84ac c6dbe40d3a1e6170cc459627629a3c6ee7969afb1bf14ae35e84b4f3ea45cf5f be2dc068760039090865f3696066df5249a7601a1cf9be26bcb7096af81ef121 f2e9b4366a834733f0f70dc638c2b4d41e966577b23ddea199787e52f112a45f

The .text hash match with ae02bd22 and 21b12514 confirms all three samples share the exact same compiled stub template. The .data hash divergence confirms the builder injects a per-sample encrypted payload. The PE checksum is unique, expected because checksum covers the entire image including .data. ^[pefile.txt]

Decompiled Behavior

Radare2 decompilation of the POGO-optimized entry point (0x41946f) yields a 1-byte chop stub — the MSVC C runtime entry trampoline is heavily optimised and the decompiler loses the context. The real logic is recovered at fcn.0040639c and onward, identical to the sibling analysis. For full decompiled pseudocode, pseudo-import slot map, and control-flow details, see the primary analysis: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html. ^[r2:fcn.0041946f]

C2 Infrastructure

No static C2 URLs, domains, or IPs are recoverable. All network indicators are generated at runtime by the LCG PRNG and encoded via the base-62 alphabet table. C2 communication uses WinInet-style HTTP POST with encrypted body data (CryptEncrypt / CryptDecrypt). See the primary sibling analysis for the reconstructed C2 wire format. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

Interesting Tidbits

  • OpenCTI label gap: This sample is tagged dropped-by-phorpiex but not blackmatter, unlike the majority of cluster siblings. This further confirms the blackmatter label is inconsistently applied by the upstream connector and is not a reliable family signal. ^[metadata.json]
  • No version-info masquerade: The binary carries no VS_VERSIONINFO resource at all (resource directory size = 0). ^[pefile.txt:207]
  • capa / floss failure: Both tools failed during triage — capa due to missing signatures, floss due to argument parsing errors. Pipeline artefacts, not binary anti-analysis measures. ^[capa.txt] ^[floss.txt]
  • Three-sibling .text twin: This is the first sample in the cluster whose .text hash matches two prior siblings (ae02bd22, 21b12514), confirming the stub template was re-used across at least three builder runs before the .text changed in 136b5750.

How To Mess With It (Homelab Replication)

See the primary sibling analysis for a full replication recipe. The stub template is MSVC 14.12 C++ with POGO (/LTCG:PGOptimize), compiled for x86 Windows GUI. To reproduce the behavioural fingerprint:

  1. Build a 32-bit PE with MSVC 14.12, enable /guard:cf and /LTCG:PGOptimize.
  2. Implement PEB-walking InMemoryOrderModuleList traversal with export-name hashing.
  3. Encrypt all strings with XOR-NOT (key = 0x10035fff), store in .data.
  4. Add CPUID leaf 1/7 checks and RDTSC differential timing gate.
  5. Implement LCG PRNG (0x19660d/0x3c6ef35f) for runtime URL generation.
  6. Compile with minimal static imports (GDI32/USER32/KERNEL32 facade only).
  7. Run capa on the reproducer and compare capability hits to sibling reports.

Deployable Signatures

YARA Rule — MSVC 14.12 POGO Reflective Loader Stub

rule MSVC_1412_Pogo_ReflectiveLoader_Stub
{
    meta:
        description = "MSVC 14.12 POGO reflective loader stub with PEB-walking, XOR-NOT crypto, and CPUID anti-VM"
        author = "PacketPursuit SOC"
        date = "2026-08-27"
        sha256 = "7e9bbc5c0e10efd2ae5509243895cc74a242051cd48ad08055e99ac9da0ee781"
    strings:
        $peb_walk_prologue = { 64 A1 30 00 00 00 }           // mov eax, fs:[0x30]  (PEB)
        $xor_not_key = { 3D FF 5F 03 10 }                   // cmp eax, 0x10035fff (key material)
        $lcg_mul = { 0D 60 96 19 00 }                       // 0x19660d multiplier
        $lcg_inc = { 35 5F F3 6E 3C }                        // 0x3c6ef35f increment
        $cpuid_leaf1 = { 0F A2 81 E1 00 00 00 80 }          // cpuid; test ecx, 0x80000000
        $pogo_debug = { 0D 00 00 00 00 F4 00 00 00 }       // IMAGE_DEBUG_TYPE_POGO header
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x18) == 0x10B and              // PE32
        uint8(uint32(0x3C)+0x5D) == 0x0E and               // MajorLinkerVersion = 14
        uint8(uint32(0x3C)+0x5E) == 0x0C and               // MinorLinkerVersion = 12
        filesize <= 200KB and
        #peb_walk_prologue >= 1 and
        #pogo_debug >= 1 and
        (
            $xor_not_key or
            ($lcg_mul and $lcg_inc) or
            $cpuid_leaf1
        )
}

IOC List

Indicator Value Type
SHA-256 7e9bbc5c0e10efd2ae5509243895cc74a242051cd48ad08055e99ac9da0ee781 Hash
SHA-1 5d12d573caddd78d39ef56deaf9afe44636ae19b Hash ^[pefile.txt:95]
MD5 717d31fa2fcb93200633181a60d4c2a3 Hash ^[pefile.txt:93]
PE Timestamp 0x631A9665 (Fri Sep 9 01:27:01 2022 UTC) Compilation
PE Checksum 0x2688E Header
XOR-NOT Key 0x10035fff Crypto
LCG Multiplier 0x19660d PRNG
LCG Increment 0x3c6ef35f PRNG
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 Section hash
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 Section hash
.data SHA-256 6e67c2dba575a363a341eff397fa1295442dcfe8c26521d972b1c28ad36a84ac Section hash
Pseudo-import region 0x425000–0x425fff (.data VA) Runtime table
Anti-VM CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 Evasion
Delivery label dropped-by-phorpiex OpenCTI tag

Behavioral Fingerprint Statement

This binary is a 150 KB PE32 GUI with exactly six sections (.text, .itext, .rdata, .data, .pdata, .reloc), a POGO debug directory, linker version 14.12, and a static import surface of only 25 API imports across GDI32, USER32, and KERNEL32. On execution, it resolves threat APIs via PEB-walking, spawns dual worker threads for file-system enumeration and HTTP C2, and maps a reflective payload into self-allocated memory. The payload is encrypted in .data with a per-sample unique hash. Network C2 is generated at runtime via an LCG PRNG and transmitted over HTTP POST with encrypted bodies. VM/sandbox evasion is enforced by CPUID hypervisor-bit checks and RDTSC timing gates.

Detection Signatures (ATT&CK Mapping)

Technique Implementation Evidence
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation Sibling analysis ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

References

  • Artifact ID: 5a043321-0861-4068-8b12-a1f3d0b422fc ^[triage.json]
  • Primary structural analysis (stub template): ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
  • Sibling delta analysis: ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html]
  • Fourteenth sibling: ^[/intel/analyses/ae02bd22cede04bdb3d48b0e32a9611c9352f28e2ddaf56af55112fdb8b2cc17.html]
  • Cluster catalogue (contested blackmatter label): blackmatter
  • Delivery infrastructure: phorpiex
  • API resolution technique: peb-walking-api-resolution
  • Umbrella entity for unattributed samples: unattributed

Provenance

Analysis derived from file, exiftool, pefile, rabin2, radare2, yara, binwalk, capa (errored), and floss (errored) outputs captured in raw/analyses/7e9bbc5c0e10efd2ae5509243895cc74a242051cd48ad08055e99ac9da0ee781/. Cluster traits verified by cross-referencing section hashes against siblings 136b5750, 21b12514, ae02bd22, 3b42403b, 0017ecc5, 73841818, a2dca6ef, 34ca794e, cdc7d79a, and others. Report drafted 2026-08-27.