typeanalysisfamilyghostpulseconfidencemediumcreated2026-07-28updated2026-07-28malware-familyloaderqt5peevasionc2
SHA-256: 833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334

ghostpulse: 833bffd0 — Qt5 x64 dropper with encrypted texture_mon.yaml payload, EaseUS masquerade

Executive Summary

A 12 MB 7-Zip SFX archive that extracts a Qt5-based x64 payload (CommunicMes.exe) to %TEMP% and executes it. The inner PE masquerades as EaseUS Partition Manager (PELetterAdjust) but carries no legitimate EaseUS branding. It is bundled with two high-entropy sidecar files — texture_mon.yaml (9.8 MB, entropy 7.90) and physics1024.map (34 KB, entropy 5.49) — strongly suspected to be encrypted payload and key material loaded at runtime by the Qt5 application. No CAPE detonation available (no Windows guest); all behavior inferred from static extraction and header analysis.

What It Is

  • Outer container: 7-Zip SFX stub (7ZSfxMod_x86.exe, Oleg Scherbakov, 2010), MSVC linker v8.0, compiled 2010-06-27 ^[exiftool.json]
  • Archive: LZMA-compressed 7z solid archive embedded at offset 0x2df4a; 11 files extracted ^[binwalk.txt] ^[sfx-config.json]
  • Inner payload: CommunicMes.exe — PE32+ x64, MSVC 14.26 (VS 2019), timestamp 0x685dfe37 (2025-06-27), 8 sections, no exports, no Authenticode signature ^[file.txt] ^[pefile.txt]
  • PDB path: D:\EPM\EPM19.9_release\Output\Release_x64\PELetterAdjust.pdb — masquerades as EaseUS Partition Master development build ^[strings.txt:36]
  • Qt5 dependency: Links against Qt5Core.dll (stock library, compiled 2020-11-06, MSVC 14.26) plus UCRT/VCRT redistributables ^[pefile.txt]
  • Sidecar files: texture_mon.yaml (9.8 MB, entropy 7.90) and physics1024.map (34 KB, entropy 5.49) — filenames masquerade as graphics/physics game assets ^[file.txt]

How It Works

Stage 1 — SFX Extraction

The outer binary is a legitimate 7-Zip SFX mod configured to silently extract (Progress=no, GUIFlags=8) to %TEMP% and immediately run "%%T\\CommunicMes.exe". ^[sfx-config.json] The 7z archive contains the Qt5 runtime, MSVC redistributables, and three attacker-controlled files: CommunicMes.exe, texture_mon.yaml, and physics1024.map.

Stage 2 — Qt5 Payload Execution

CommunicMes.exe is a Qt5 GUI application compiled for x64 with a minimal import surface: Qt5Core (string/QProcess/QFile/QDir/QStorageInfo APIs), KERNEL32 (process/thread/time APIs), SHELL32 (CommandLineToArgvW), and the UCRT/VCRT runtime. ^[pefile.txt] There are no direct crypto, networking, or injection imports — all malicious behavior is expected to be dynamically resolved or implemented inside the encrypted sidecar files.

Stage 3 — Encrypted Sidecar Loading

texture_mon.yaml is 9.8 MB with Shannon entropy of 7.90 (near-random), strongly consistent with encrypted payload data. physics1024.map is 34 KB with entropy 5.49, consistent with a configuration file or decryption key schedule. Both filenames use game-asset masquerade (texture/physics + .yaml/.map) to blend with legitimate Qt5 resource directories. The string .texture_mon.yaml is present in the CommunicMes.exe .rdata section ^[strings.txt], confirming runtime reference.

Decompiled Behavior

radare2 analysis of CommunicMes.exe reveals standard MSVC C++ CRT initialization (__initterm_e, __initterm) followed by a short user function tree (34 functions total). ^[r2:entry0] The most complex function (fcn.1400013c0, 649 bytes) manipulates QList/QHash data structures and calls QProcess::startDetached — consistent with spawning child processes. No direct obfuscation, control-flow flattening, or anti-debug code is present in the extracted binary.

Notable strings in .rdata:

  • X:\Program Files\Other\Tools\EPM.bat — batch path for EaseUS masquerade
  • diskpart.exe /s %1, assign letter=%1, remove letter=%1 — disk-partition manipulation commands, matching EPM branding
  • TexturePattern, .texture_mon.yaml — confirms runtime reference to the encrypted payload file
  • DigiCert certificate chain strings inside Qt5Core.dll (legitimate library signing chain)

C2 Infrastructure

No static C2 indicators recovered. The CommunicMes.exe contains no hardcoded URLs, IPs, domains, or mutex names in plaintext. Network connectivity, if any, is expected to be:

  1. Encrypted inside texture_mon.yaml and decrypted at runtime
  2. Or communicated via the Qt5 network stack (QNetworkAccessManager, not imported directly but available through Qt5Core)

The absence of observable C2 strings is consistent with a modular loader pattern where the real C2 config is delivered inside the encrypted sidecar.

Interesting Tidbits

  1. EaseUS masquerade depth: The PDB path references EPM19.9 (EaseUS Partition Master v19.9), a real product. The executable's strings reference diskpart.exe, volume assignment, and partition logic — all thematically consistent with a disk-manager tool. ^[strings.txt]

  2. Qt5 as evasion surface: Bundling the entire Qt5 runtime (~6 MB for Qt5Core.dll alone) inflates the payload and buries malicious imports inside a massive legitimate library surface. EDR solutions that whitelist Qt5 applications may miss process-spawning calls routed through QProcess::startDetached.

  3. Family scale: The corpus contains 49 ghostpulse-labeled samples. Each uses a different inner-executable name (CommunicMes.exe, PortTransactor.exe, PuTool.exe, DecAlpha64.exe, Data_D.exe, CommuniBi.exe, WizardDa42.exe, InjectoBan.exe, AurModule.exe, IntegratoFlux.exe, GeneratorB64.exe, etc.) but all share the same outer SFX + Qt5 runtime + high-entropy sidecar pattern.

  4. CommunicMas.exe variant naming: The inner executable names appear algorithmically generated — compound words or pseudo-technical portmanteaus (Communic+Mes, Port+Transactor, Communi+Bi, Injecto+Ban) — suggesting automated builder tooling.

  5. No packing on inner binary: Unlike many loaders, the inner PE is not packed or obfuscated. Its only protection is the encrypted sidecar file. This keeps the loader small (~109 KB) and the heavy payload external.

How To Mess With It (Homelab Replication)

Reproducing the dropper pattern:

  1. Build a Qt5 C++ console/GUI app with MSVC 2019+ and link dynamically against Qt5Core.dll
  2. In the app, open a hardcoded sidecar file (e.g., texture_mon.yaml) from the application directory, decrypt it in-memory with AES-256-CBC or RC4, and reflectively execute or drop the result
  3. Compile with /SUBSYSTEM:WINDOWS to suppress console window
  4. Package with 7-Zip SFX (7zSfxMod) into a self-extracting archive with RunProgram="%%T\\YourApp.exe"
  5. Bundle Qt5Core.dll, UCRT, VCRT, and your encrypted sidecar

Detection target for your own VMs: The resulting binary will have:

  • A 7-Zip SFX outer stub with RunProgram config
  • An inner x64 PE importing Qt5Core.dll
  • No exports and no Authenticode signature
  • Companion files with >7.5 entropy and non-standard extensions (.yaml, .map)

Deployable Signatures

YARA Rule — GhostPulse SFX Loader

rule GhostPulse_SFX_Qt5_Loader {
    meta:
        description = "Detects GhostPulse family 7-Zip SFX dropper with Qt5 inner payload"
        author = "PacketPursuit"
        date = "2026-07-28"
        sha256 = "833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334"
    strings:
        $sfx1 = "7ZSfxMod" ascii
        $sfx2 = "7-Zip SFX" wide
        $runprog = /RunProgram="%%T\\[A-Za-z]{5,20}\.exe"/ wide
        $qt5 = "Qt5Core.dll" ascii
        $yaml = ".texture_mon.yaml" ascii
        $map = ".physics1024.map" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize > 5MB and filesize < 25MB and
        ($sfx1 or $sfx2) and
        $runprog and
        ($qt5 or $yaml or $map)
}

YARA Rule — CommunicMes Inner Payload

rule GhostPulse_Qt5_Inner {
    meta:
        description = "Detects GhostPulse inner Qt5 payload with EPM masquerade"
        author = "PacketPursuit"
        date = "2026-07-28"
        sha256 = "dd4469b6bb8bf5ce4dd8560cecf1cfc16272f18f26960a4569d636b8b02aec96"
    strings:
        $pdb = "PELetterAdjust.pdb" ascii
        $epm = "EPM19.9_release" ascii
        $tex = "TexturePattern" ascii
        $yaml = ".texture_mon.yaml" ascii
        $diskpart = "diskpart.exe /s %1" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.machine == pe.MACHINE_AMD64 and
        2 of ($pdb, $epm, $tex, $yaml, $diskpart)
}

Behavioral Hunt Query (Sigma)

title: GhostPulse Qt5 Encrypted Sidecar Execution
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - 'CommunicMes.exe'
      - 'PortTransactor.exe'
      - 'PuTool.exe'
      - 'DecAlpha64.exe'
      - 'Data_D.exe'
      - 'CommuniBi.exe'
      - 'WizardDa42.exe'
      - 'InjectoBan.exe'
      - 'AurModule.exe'
      - 'IntegratoFlux.exe'
      - 'GeneratorB64.exe'
    ParentImage|endswith:
      - '\\7zSfxMod.exe'
      - '\\7z.exe'
  sidecar:
    - TargetFilename|endswith:
        - 'texture_mon.yaml'
        - 'physics1024.map'
  condition: selection or sidecar
falsepositives:
  - Unknown
level: high

IOC List

Type Value Context
SHA-256 (outer) 833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334 7-Zip SFX dropper
SHA-256 (inner) dd4469b6bb8bf5ce4dd8560cecf1cfc16272f18f26960a4569d636b8b02aec96 CommunicMes.exe
SHA-256 (sidecar) 840c209e0d4a54ddc4f726bc4dcf163ccf8f929ae66b1a6ddd191c8d488ea9c5 texture_mon.yaml (encrypted)
SHA-256 (sidecar) cccf57e73ad1d23b674c0c6a64d10fc108a4dce2b569f09db86595c0e06845a8 physics1024.map (config/key)
PDB path D:\EPM\EPM19.9_release\Output\Release_x64\PELetterAdjust.pdb Masquerade artifact
File paths %TEMP%\CommunicMes.exe Extracted payload
File paths %TEMP%\texture_mon.yaml Encrypted sidecar
File paths %TEMP%\physics1024.map Config/key sidecar
File paths %TEMP%\Qt5Core.dll Bundled Qt5 runtime

Detection Signatures

Technique ATT&CK ID Evidence
Masquerading T1036.005 EaseUS Partition Manager PDB path and diskpart strings
Ingress Tool Transfer T1105 7-Zip SFX extracts payload from embedded archive
Encrypted Payload T1027.002 texture_mon.yaml (9.8 MB, entropy 7.90)
Data Obfuscation T1027 physics1024.map suspected key material
Process Injection (inferred) T1055 QProcess::startDetached used for child execution

References

  • ghostpulse — Entity page for this family
  • Sample source: OpenCTI / MalwareBazaar, artifact ID 8a3503df-0c27-48a5-9151-9136e8a30cd8
  • EaseUS Partition Manager (legitimate): https://www.easeus.com/partition-manager/
  • 7-Zip SFX Mod (legitimate): https://github.com/chrislake/7zsfxmod

Provenance

  • Outer binary analysis: file v5.44, exiftool v12.76, pefile Python module, binwalk v2.3.4, radare2 v5.x
  • Archive extraction: 7z v23.01, dd offset 188234 (0x2df4a)
  • Inner binary analysis: file v5.44, pefile Python module, radare2 v5.x
  • Entropy calculation: Python 3 math.entropy via custom script
  • Capa: signatures path missing — no results ^[capa.txt]
  • Floss: CLI argument error — no results ^[floss.txt]
  • Dynamic analysis: Skipped — CAPE has no Windows guest available for PE32 platform ^[dynamic-analysis.md]