833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334ghostpulse: 833bffd0 — Qt5 x64 dropper with encrypted texture_mon.yaml payload, EaseUS masquerade
Executive Summary
A 12 MB 7-Zip SFX archive that extracts a Qt5-based x64 payload (CommunicMes.exe) to %TEMP% and executes it. The inner PE masquerades as EaseUS Partition Manager (PELetterAdjust) but carries no legitimate EaseUS branding. It is bundled with two high-entropy sidecar files — texture_mon.yaml (9.8 MB, entropy 7.90) and physics1024.map (34 KB, entropy 5.49) — strongly suspected to be encrypted payload and key material loaded at runtime by the Qt5 application. No CAPE detonation available (no Windows guest); all behavior inferred from static extraction and header analysis.
What It Is
- Outer container: 7-Zip SFX stub (
7ZSfxMod_x86.exe, Oleg Scherbakov, 2010), MSVC linker v8.0, compiled 2010-06-27 ^[exiftool.json] - Archive: LZMA-compressed 7z solid archive embedded at offset
0x2df4a; 11 files extracted ^[binwalk.txt] ^[sfx-config.json] - Inner payload:
CommunicMes.exe— PE32+ x64, MSVC 14.26 (VS 2019), timestamp0x685dfe37(2025-06-27), 8 sections, no exports, no Authenticode signature ^[file.txt] ^[pefile.txt] - PDB path:
D:\EPM\EPM19.9_release\Output\Release_x64\PELetterAdjust.pdb— masquerades as EaseUS Partition Master development build ^[strings.txt:36] - Qt5 dependency: Links against
Qt5Core.dll(stock library, compiled 2020-11-06, MSVC 14.26) plus UCRT/VCRT redistributables ^[pefile.txt] - Sidecar files:
texture_mon.yaml(9.8 MB, entropy 7.90) andphysics1024.map(34 KB, entropy 5.49) — filenames masquerade as graphics/physics game assets ^[file.txt]
How It Works
Stage 1 — SFX Extraction
The outer binary is a legitimate 7-Zip SFX mod configured to silently extract (Progress=no, GUIFlags=8) to %TEMP% and immediately run "%%T\\CommunicMes.exe". ^[sfx-config.json] The 7z archive contains the Qt5 runtime, MSVC redistributables, and three attacker-controlled files: CommunicMes.exe, texture_mon.yaml, and physics1024.map.
Stage 2 — Qt5 Payload Execution
CommunicMes.exe is a Qt5 GUI application compiled for x64 with a minimal import surface: Qt5Core (string/QProcess/QFile/QDir/QStorageInfo APIs), KERNEL32 (process/thread/time APIs), SHELL32 (CommandLineToArgvW), and the UCRT/VCRT runtime. ^[pefile.txt] There are no direct crypto, networking, or injection imports — all malicious behavior is expected to be dynamically resolved or implemented inside the encrypted sidecar files.
Stage 3 — Encrypted Sidecar Loading
texture_mon.yaml is 9.8 MB with Shannon entropy of 7.90 (near-random), strongly consistent with encrypted payload data. physics1024.map is 34 KB with entropy 5.49, consistent with a configuration file or decryption key schedule. Both filenames use game-asset masquerade (texture/physics + .yaml/.map) to blend with legitimate Qt5 resource directories. The string .texture_mon.yaml is present in the CommunicMes.exe .rdata section ^[strings.txt], confirming runtime reference.
Decompiled Behavior
radare2 analysis of CommunicMes.exe reveals standard MSVC C++ CRT initialization (__initterm_e, __initterm) followed by a short user function tree (34 functions total). ^[r2:entry0] The most complex function (fcn.1400013c0, 649 bytes) manipulates QList/QHash data structures and calls QProcess::startDetached — consistent with spawning child processes. No direct obfuscation, control-flow flattening, or anti-debug code is present in the extracted binary.
Notable strings in .rdata:
X:\Program Files\Other\Tools\EPM.bat— batch path for EaseUS masqueradediskpart.exe /s %1,assign letter=%1,remove letter=%1— disk-partition manipulation commands, matching EPM brandingTexturePattern,.texture_mon.yaml— confirms runtime reference to the encrypted payload file- DigiCert certificate chain strings inside Qt5Core.dll (legitimate library signing chain)
C2 Infrastructure
No static C2 indicators recovered. The CommunicMes.exe contains no hardcoded URLs, IPs, domains, or mutex names in plaintext. Network connectivity, if any, is expected to be:
- Encrypted inside
texture_mon.yamland decrypted at runtime - Or communicated via the Qt5 network stack (QNetworkAccessManager, not imported directly but available through Qt5Core)
The absence of observable C2 strings is consistent with a modular loader pattern where the real C2 config is delivered inside the encrypted sidecar.
Interesting Tidbits
-
EaseUS masquerade depth: The PDB path references EPM19.9 (EaseUS Partition Master v19.9), a real product. The executable's strings reference
diskpart.exe, volume assignment, and partition logic — all thematically consistent with a disk-manager tool. ^[strings.txt] -
Qt5 as evasion surface: Bundling the entire Qt5 runtime (~6 MB for Qt5Core.dll alone) inflates the payload and buries malicious imports inside a massive legitimate library surface. EDR solutions that whitelist Qt5 applications may miss process-spawning calls routed through
QProcess::startDetached. -
Family scale: The corpus contains 49 ghostpulse-labeled samples. Each uses a different inner-executable name (CommunicMes.exe, PortTransactor.exe, PuTool.exe, DecAlpha64.exe, Data_D.exe, CommuniBi.exe, WizardDa42.exe, InjectoBan.exe, AurModule.exe, IntegratoFlux.exe, GeneratorB64.exe, etc.) but all share the same outer SFX + Qt5 runtime + high-entropy sidecar pattern.
-
CommunicMas.exe variant naming: The inner executable names appear algorithmically generated — compound words or pseudo-technical portmanteaus (Communic+Mes, Port+Transactor, Communi+Bi, Injecto+Ban) — suggesting automated builder tooling.
-
No packing on inner binary: Unlike many loaders, the inner PE is not packed or obfuscated. Its only protection is the encrypted sidecar file. This keeps the loader small (~109 KB) and the heavy payload external.
How To Mess With It (Homelab Replication)
Reproducing the dropper pattern:
- Build a Qt5 C++ console/GUI app with MSVC 2019+ and link dynamically against Qt5Core.dll
- In the app, open a hardcoded sidecar file (e.g.,
texture_mon.yaml) from the application directory, decrypt it in-memory with AES-256-CBC or RC4, and reflectively execute or drop the result - Compile with
/SUBSYSTEM:WINDOWSto suppress console window - Package with 7-Zip SFX (
7zSfxMod) into a self-extracting archive withRunProgram="%%T\\YourApp.exe" - Bundle Qt5Core.dll, UCRT, VCRT, and your encrypted sidecar
Detection target for your own VMs: The resulting binary will have:
- A 7-Zip SFX outer stub with
RunProgramconfig - An inner x64 PE importing Qt5Core.dll
- No exports and no Authenticode signature
- Companion files with >7.5 entropy and non-standard extensions (.yaml, .map)
Deployable Signatures
YARA Rule — GhostPulse SFX Loader
rule GhostPulse_SFX_Qt5_Loader {
meta:
description = "Detects GhostPulse family 7-Zip SFX dropper with Qt5 inner payload"
author = "PacketPursuit"
date = "2026-07-28"
sha256 = "833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334"
strings:
$sfx1 = "7ZSfxMod" ascii
$sfx2 = "7-Zip SFX" wide
$runprog = /RunProgram="%%T\\[A-Za-z]{5,20}\.exe"/ wide
$qt5 = "Qt5Core.dll" ascii
$yaml = ".texture_mon.yaml" ascii
$map = ".physics1024.map" ascii
condition:
uint16(0) == 0x5A4D and
filesize > 5MB and filesize < 25MB and
($sfx1 or $sfx2) and
$runprog and
($qt5 or $yaml or $map)
}
YARA Rule — CommunicMes Inner Payload
rule GhostPulse_Qt5_Inner {
meta:
description = "Detects GhostPulse inner Qt5 payload with EPM masquerade"
author = "PacketPursuit"
date = "2026-07-28"
sha256 = "dd4469b6bb8bf5ce4dd8560cecf1cfc16272f18f26960a4569d636b8b02aec96"
strings:
$pdb = "PELetterAdjust.pdb" ascii
$epm = "EPM19.9_release" ascii
$tex = "TexturePattern" ascii
$yaml = ".texture_mon.yaml" ascii
$diskpart = "diskpart.exe /s %1" ascii
condition:
uint16(0) == 0x5A4D and
pe.machine == pe.MACHINE_AMD64 and
2 of ($pdb, $epm, $tex, $yaml, $diskpart)
}
Behavioral Hunt Query (Sigma)
title: GhostPulse Qt5 Encrypted Sidecar Execution
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'CommunicMes.exe'
- 'PortTransactor.exe'
- 'PuTool.exe'
- 'DecAlpha64.exe'
- 'Data_D.exe'
- 'CommuniBi.exe'
- 'WizardDa42.exe'
- 'InjectoBan.exe'
- 'AurModule.exe'
- 'IntegratoFlux.exe'
- 'GeneratorB64.exe'
ParentImage|endswith:
- '\\7zSfxMod.exe'
- '\\7z.exe'
sidecar:
- TargetFilename|endswith:
- 'texture_mon.yaml'
- 'physics1024.map'
condition: selection or sidecar
falsepositives:
- Unknown
level: high
IOC List
| Type | Value | Context |
|---|---|---|
| SHA-256 (outer) | 833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334 |
7-Zip SFX dropper |
| SHA-256 (inner) | dd4469b6bb8bf5ce4dd8560cecf1cfc16272f18f26960a4569d636b8b02aec96 |
CommunicMes.exe |
| SHA-256 (sidecar) | 840c209e0d4a54ddc4f726bc4dcf163ccf8f929ae66b1a6ddd191c8d488ea9c5 |
texture_mon.yaml (encrypted) |
| SHA-256 (sidecar) | cccf57e73ad1d23b674c0c6a64d10fc108a4dce2b569f09db86595c0e06845a8 |
physics1024.map (config/key) |
| PDB path | D:\EPM\EPM19.9_release\Output\Release_x64\PELetterAdjust.pdb |
Masquerade artifact |
| File paths | %TEMP%\CommunicMes.exe |
Extracted payload |
| File paths | %TEMP%\texture_mon.yaml |
Encrypted sidecar |
| File paths | %TEMP%\physics1024.map |
Config/key sidecar |
| File paths | %TEMP%\Qt5Core.dll |
Bundled Qt5 runtime |
Detection Signatures
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Masquerading | T1036.005 | EaseUS Partition Manager PDB path and diskpart strings |
| Ingress Tool Transfer | T1105 | 7-Zip SFX extracts payload from embedded archive |
| Encrypted Payload | T1027.002 | texture_mon.yaml (9.8 MB, entropy 7.90) |
| Data Obfuscation | T1027 | physics1024.map suspected key material |
| Process Injection (inferred) | T1055 | QProcess::startDetached used for child execution |
References
- ghostpulse — Entity page for this family
- Sample source: OpenCTI / MalwareBazaar, artifact ID
8a3503df-0c27-48a5-9151-9136e8a30cd8 - EaseUS Partition Manager (legitimate): https://www.easeus.com/partition-manager/
- 7-Zip SFX Mod (legitimate): https://github.com/chrislake/7zsfxmod
Provenance
- Outer binary analysis:
filev5.44,exiftoolv12.76,pefilePython module,binwalkv2.3.4,radare2v5.x - Archive extraction:
7zv23.01,ddoffset 188234 (0x2df4a) - Inner binary analysis:
filev5.44,pefilePython module,radare2v5.x - Entropy calculation: Python 3
math.entropyvia custom script - Capa: signatures path missing — no results ^[capa.txt]
- Floss: CLI argument error — no results ^[floss.txt]
- Dynamic analysis: Skipped — CAPE has no Windows guest available for PE32 platform ^[dynamic-analysis.md]