typeanalysisfamilyunattributedconfidencehighpeloadermalware-familyreflective-pe-loaderpeb-walking-api-resolutionxor-not-alphabet-cipherlcg-prng-c2-url-generationcpuid-hypervisor-vm-gatemsvc-pogo-reflective-loaderdropped-by-phorpiex
SHA-256: 8655b3b9b297ef153354a4f9778d7b621dd94adf4ca66d526cd7f0095b7fe5d4

unattributed (blackmatter cluster): 8655b3b9b297 — 20th sibling, .text hash matches majority group, PE checksum 0x2ebd4

Executive Summary

Twentieth confirmed sibling in the MSVC 14.12 PEB-walking reflective-loader cluster distributed via Phorpiex spam infrastructure. Same compilation timestamp (0x631A9665), same linker (MSVC 14.12), same XOR-NOT alphabet cipher key (0x10035fff), and same .text hash (000a9a8b...) as the majority-group siblings (ae02bd22, 21b12514, 7e9bbc5c, e67dbabcd, 2ac8295381, 89dc341bbd). Only deltas are the individualized .data payload and the PE checksum (0x2ebd4). No blackmatter OpenCTI label; upstream tagging is dropped-by-phorpiex only. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • File type: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
  • Size: 149,504 bytes (146 KB) ^[triage.json]
  • Compilation: Fri Sep 9 01:27:01 2022 UTC (0x631A9665) ^[pefile.txt:34]
  • Linker: MSVC 14.12 (VS 2017 15.5+) — MajorLinkerVersion=0xE, MinorLinkerVersion=0xC ^[pefile.txt:45]
  • Subsystem: Windows GUI ^[pefile.txt:66]
  • Mitigations: ASLR (DYNAMIC_BASE), DEP/NX (NX_COMPAT), stack canary (canary=true) ^[pefile.txt:74],^[rabin2-info.txt:6]
  • Signing: Unsigned (signed: false) ^[rabin2-info.txt:27]
  • POGO: IMAGE_DEBUG_TYPE_POGO debug directory present (type 13) ^[terminal:python pefile debug inspection]
  • PE checksum: 0x2ebd4 (unique per-sample) ^[pefile.txt:65]
  • OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar ^[triage.json]
  • Family: Unattributed (blackmatter cluster sibling; blackmatter label is contested/false positive per cluster consensus) ^[entities/blackmatter.md]

How It Works

This sample is a builder-pipeline twin: a shared MSVC 14.12 reflective-loader stub template with a per-sample encrypted payload injected into .data. The stub decrypts the payload, maps it reflectively into RWX memory, and transfers execution. No disk write of the inner payload.

Shared behavior (identical across all 20 siblings) is documented at blackmatter and peb-walking-api-resolution. Per-sample deltas are limited to:

  • .data section contents (individualized encrypted payload)
  • .pdata section contents (exception-table update for payload)
  • PE checksum (builder-computed, unique per sample)

Decompiled Behavior

Radare2 analysis recovered the same control-flow patterns seen in every sibling. Function addresses differ from prior reports due to r2 heuristics, but the instruction sequences match the shared .text hash exactly.

fcn.00419479 — Entry-point orchestrator

^[r2:fcn.00419479]

Near the entry point (0x1946f). Calls fcn.00419000 (.itext thunk), fcn.0040639c (initialization), fcn.00409990 (main logic), and fcn.00417458 (cleanup), then enters the GUI message loop. Standard MSVC CRT init → payload → message-pump pattern.

fcn.0040639c — Initialization + XOR-NOT key setup

^[r2:fcn.0040639c]

Pushes 0xe80c4717, XORs with 0x10035fff to derive the PEB-walker seed / string-decryption key, then passes the result to the API resolver. Identical key-derivation sequence to all prior siblings.

fcn.00405aec — PEB-walking API resolver

^[r2:fcn.00405aec]

Accesses fs:[0x30] (PEB on x86), walks InMemoryOrderModuleList, iterates export tables, and caches resolved API pointers in .data slots. The same function body appears in every sibling with identical instruction bytes. Matches the pattern documented at peb-walking-api-resolution.

Payload decryption and reflective mapping

The .text hash (000a9a8b...) is byte-identical to the majority-group siblings, confirming the 6-round bswap/ror/rol/not decryption loop and the RWX VirtualAlloc + reflective PE mapper are present at the same offsets. See sibling reports for full decompilation: /intel/analyses/89dc341bbd176fbcee31f54884c132faf7c847838609f330249f634b99fd0a0c.html (19th sibling, identical stub) and /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html (primary).

C2 Infrastructure

No hardcoded C2 strings recovered statically. The LCG PRNG C2 URL generation routine (0x19660d / 0x3c6ef35f seeds) is present in the stub but produces runtime-only URLs. No domains, IPs, or URLs in strings.

Interesting Tidbits

  • .text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 matches the majority-group siblings exactly, confirming the same compiler flags and source. ^[terminal:python hash of .text]
  • .data SHA-256 035c5d8e716775c906d7594989ef7b351bc6dbe9bd70071cfb96f8b23c4eb1b5 is unique to this sample — the individualized payload. ^[terminal:python hash of .data]
  • No blackmatter OpenCTI label, only dropped-by-phorpiex. Upstream tagging drift confirms the blackmatter label is not a reliable family marker for this cluster. ^[triage.json]
  • capa and floss both errored during triage (missing signatures and bad CLI invocation respectively), so this analysis relies entirely on radare2 + manual PE inspection. ^[capa.txt],^[floss.txt]
  • .itext section (0x600 bytes, entropy 2.93) contains the decompression/thunk stub, low-entropy confirming it's a fixed template. ^[pefile.txt:112]

How To Mess With It (Homelab Replication)

See the primary cluster analysis at /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html for the full reproduction pipeline. In short:

  1. Compile a MSVC 14.12 x86 PE stub with POGO optimization.
  2. Embed a PE payload in the .data section, encrypted with the 6-round bswap/ror/rol/not cipher.
  3. Implement PEB-walking API resolution and RWX VirtualAlloc mapping.
  4. Run capa on the reproducer and compare to the cluster fingerprint (minimal IAT, GDI/USER32 facade imports, VirtualAlloc+memmove runtime resolution).

Deployable Signatures

YARA rule

rule BlackmatterCluster_ReflectiveLoader
{
    meta:
        description = "MSVC 14.12 PEB-walking reflective-loader cluster (blackmatter siblings)"
        author = "Titus"
        reference = "/intel/analyses/8655b3b9b297ef153354a4f9778d7b621dd94adf4ca66d526cd7f0095b7fe5d4.html"
    strings:
        $peb_walk_sig = { 64 A1 30 00 00 00 }         // mov eax, fs:[0x30]  ; PEB access
        $decrypt_a = { 0F C8 66 C1 C8 0D F7 D0 }      // bswap, ror 0xd, not
        $decrypt_b = { C1 C0 0B 0F C8 33 D0 }        // rol 0xb, bswap, xor
        $decrypt_c = { C1 C0 09 0F C8 F7 D0 }        // rol 9, bswap, not
        $decrypt_d = { C1 C0 07 0F C8 33 D0 }        // rol 7, bswap, xor
        $xor_key = { FF 5F 03 10 }                   // XOR-NOT key fragment 0x10035fff
        $pogo = "POGO" ascii
        $linker_14_12 = { 0E 0C }                    // MajorLinker=14, MinorLinker=12
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        #linker_14_12 >= 1 and
        #pogo >= 1 and
        any of ($decrypt_a, $decrypt_b, $decrypt_c, $decrypt_d) and
        filesize < 200KB
}

IOC list

Indicator Value Notes
SHA-256 8655b3b9b297ef153354a4f9778d7b621dd94adf4ca66d526cd7f0095b7fe5d4 This sample
.text SHA-256 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 Majority-group fingerprint
.data SHA-256 035c5d8e716775c906d7594989ef7b351bc6dbe9bd70071cfb96f8b23c4eb1b5 Unique individualized payload
PE checksum 0x2ebd4 Unique per sample
Compilation Fri Sep 9 01:27:01 2022 UTC Shared across all 20 siblings
XOR key 0x10035fff Alphabet-cipher key (same across cluster)
LCG seeds 0x19660d / 0x3c6ef35f C2 URL PRNG (same across cluster)
Import facade GDI32 (6), USER32 (11), KERNEL32 (8) Minimal IAT, no threat APIs
Distribution dropped-by-phorpiex Phorpiex spam infrastructure

Behavioral fingerprint statement

This binary is a 150 KB PE32 GUI executable compiled with MSVC 14.12 and POGO optimization. Its import table contains only 25 benign GUI/system APIs (GDI32, USER32, KERNEL32). At runtime it resolves threat APIs via PEB-walking export hashing, decrypts a ~40 KB payload in .data using a 6-round bswap/ror/rol/not cipher, maps the decrypted image into RWX memory, and transfers execution without writing to disk. It performs CPUID hypervisor-bit checks and RDTSC timing gates before decryption. No hardcoded C2 — URLs are generated at runtime via an LCG PRNG seeded with 0x19660d/0x3c6ef35f.

Detection Signatures

ATT&CK Technique Evidence Source
T1055 — Process Injection RWX VirtualAlloc + reflective PE mapping into self process ^[r2:fcn.00419479] (orchestrator calls mapper)
T1027 — Obfuscated Files or Information 6-round custom cipher on .data payload Shared .text hash with siblings; see 89dc341bbd report
T1027.002 — Software Packing Runtime decryption + in-memory mapping; no payload on disk Shared .text hash with siblings
T1620 — Reflective Code Loading Manual PE mapping, relocation patching, import resolution Shared .text hash with siblings
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit check + RDTSC timing gate ^[peb-walking-api-resolution]
T1106 — Native API PEB-walking to resolve Nt* / Zw* APIs without imports ^[r2:fcn.00405aec]
T1059.003 — Windows Command Shell Evidence of cmd.exe spawn in sibling dynamic analysis ^[blackmatter]

References

  • Primary cluster analysis: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Sibling 21b12514: /intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html
  • Sibling ae02bd22: /intel/analyses/ae02bd22cede04bdb3d48b0e32a9611c9352f28e2ddaf56af55112fdb8b2cc17.html
  • Sibling 7e9bbc5c: /intel/analyses/7e9bbc5c0e10efd2ae5509243895cc74a242051cd48ad08055e99ac9da0ee781.html
  • Sibling 877f1047: /intel/analyses/877f1047825cb5b73a4812279ac15e8987290c99a5d3a99473a9ec85066fabd6.html
  • Sibling e67dbabcd: /intel/analyses/e67dbabcd48b1294883b07d7724f416a77963c79aaf9d81bed9d7e2d0dcd9731.html
  • Sibling 2ac8295381: /intel/analyses/2ac8295381ebafbe6399707f5435409e859c7c08bf51c666db4438ea5e4a4abb.html
  • Sibling 89dc341bbd: /intel/analyses/89dc341bbd176fbcee31f54884c132faf7c847838609f330249f634b99fd0a0c.html
  • Entity pages: unattributed, blackmatter, peb-walking-api-resolution
  • Delivery: phorpiex

Provenance

  • file.txt — file-type identification (file v5.44)
  • exiftool.json — PE metadata (ExifTool 12.76)
  • pefile.txt — DOS/NT headers, sections, imports, relocations, debug directory (pefile)
  • rabin2-info.txt — radare2 binary summary (r2)
  • strings.txt — ASCII/Unicode strings extraction (strings)
  • triage.json — triage pipeline metadata (custom)
  • metadata.json — OpenCTI connector artifact metadata
  • capa.txt — Mandiant capa (errored: missing signatures)
  • floss.txt — FireEye FLOSS (errored: bad CLI invocation)
  • dynamic-analysis.md — CAPE sandbox (skipped: no Windows guest available)
  • radare2 static analysis: mcp_radare2 with analysis level 3, 519 functions recovered, decompilation of fcn.00419479, fcn.0040639c, fcn.00405aec