8796e69f738fceb99fd177a5536dbccf5112ffa202a8b05be10ab45e600e289bblackmatter: 8796e69f — 32nd confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster, PE checksum 0x2e93a
Executive Summary
Thirty-second confirmed sibling in the MSVC 14.12 reflective-loader cluster first documented at 136b5750. Identical encrypted .text stub (SHA-256 000a9a8b...), identical XOR-NOT cipher (0x10035fff), identical compilation timestamp (0x631A9665 — Fri Sep 9 01:27:01 2022 UTC), and identical PEB-walking API resolution template. The .data section carries an individualized encrypted payload (SHA-256 580e7e7f...), confirming per-sample customization in a builder pipeline. Tagged dropped-by-phorpiex by OpenCTI but not carrying the blackmatter label — consistent with upstream tagging inconsistency observed across 10+ prior siblings. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 8796e69f738fceb99fd177a5536dbccf5112ffa202a8b05be10ab45e600e289b |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal facade — GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt:249] |
| YARA | Generic PE only; no family-specific hits ^[yara.txt] |
| PE Checksum (stored) | 0x2E93A |
| PE Checksum (computed) | 0x2CC20 — mismatch indicates post-build modification or builder artifact |
| .text SHA-256 | 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 — matches cluster majority group |
| .data SHA-256 | 580e7e7fe0c2c204fa5d676442f7ccd96b1b408d2a9201652ee49081459a3308 — unique to this sample |
How It Works
This sample is structurally identical to the cluster described in the primary analysis at 136b5750 and the cluster entity page blackmatter. No new functional deltas were observed. For full behavioral details see:
- /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
- blackmatter — cluster entity page with 31 prior siblings
Cluster-Fingerprint Confirmation
-
Encrypted entry point: The byte at
0x1946F(declared AddressOfEntryPoint) is0xc4— not a valid x86 instruction start. Actual code is decrypted in-memory at runtime. ^[r2:fcn.00419479] -
Encrypted
.text: First 32 bytes of.textat file offset0x400areff 5f 03 11 55 8b ec 51 ...— decrypt to standard x86 prologue sequences after XOR-NOT cipher with key0x10035fff. ^[pefile.txt:93] -
XOR-NOT alphabet cipher: Same two-step transform (
^ 0x10035fffthen~/ bitwise NOT) observed across all 31 prior siblings. Encrypted alphabet table at0x40d4b0yields the same 62-character ordered alphabet:ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789. ^[r2:fcn.0040d4b0] -
PEB-walking API resolution: No threat APIs in static import table. All ~30+ APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) resolved at runtime by walking PEB InMemoryOrderModuleList and hashing export names. Resolved pointers cached in
.datapseudo-import slots at0x425xxx. ^[r2:fcn.00405aec] -
Anti-VM: CPUID leaf 1 ECX bit 31 (hypervisor present) + CPUID leaf 7 EBX bit 18 + RDTSC differential timing gate with 13-bit rotate. ^[r2:fcn.004010bc]
-
LCG PRNG C2 URL generation: Same linear congruential generator constants (
a = 0x19660d,c = 0x3c6ef35f) used to generate pseudo-random C2 domain names character-by-character from the alphabet table. ^[r2:fcn.0040110c] -
HTTP POST C2: Same encrypted wide-character fragments decoding to
"POST"at runtime, confirming HTTP POST as the C2 verb. ^[r2:fcn.0040cfcc]
C2 Infrastructure
No static C2 strings recoverable — host names and URLs generated at runtime via the LCG PRNG + alphabet table. The C2 is ephemeral and reconstructed on each execution. See the primary 136b5750 analysis for the reconstruction algorithm.
Interesting Tidbits
- No
blackmatterOpenCTI label on this sample despite carrying the identical.texthash as 24 confirmedblackmatter-tagged siblings. This is the 11th sample in the cluster (afterae02bd22,7e9bbc5c,877f1047,e67dbabcd,2ac8295381,89dc341bbd,8655b3b9b2,91e39f6bb60a,65844473d39b,044539a2eacf,53e31566) that carries only thedropped-by-phorpiextag. Upstream tagging inconsistency is now a confirmed pattern. ^[metadata.json] - Individualized
.datapayload: The.datasection hash is unique, confirming the builder pipeline customizes the encrypted payload per sample while sharing the stub. The.textsection is byte-identical across all 32 siblings — a strong builder-template fingerprint. - POGO optimization:
IMAGE_DEBUG_TYPE_POGOdirectory (size 0xF4) present in all siblings, suggesting the builder compiles with Profile-Guided Optimization or reuses a single PGO-optimized stub template. ^[pefile.txt:313] .itextentropy anomaly: Entropy 2.93 in.itext(vs 6.63 in.text) — mostly zeros with a small import descriptor table at the head, consistent with the cluster pattern of minimal static imports. ^[pefile.txt:112]- Section layout invariant: All 32 siblings share the exact same 6-section layout (
.text,.itext,.rdata,.data,.pdata,.reloc) with identical virtual addresses and nearly identical sizes. The only per-sample variance is in.dataand.pdatacontents. - PE checksum mismatch: Stored checksum
0x2E93Adoes not match computed0x2CC20, indicating post-build modification or builder artifact. This is a useful cluster detection heuristic when.textis encrypted and standard checksum verification fails. ^[pefile.txt:65]
How To Mess With It (Homelab Replication)
See the primary 136b5750 analysis and the peb-walking-api-resolution technique page. To replicate the stub:
- Compile a minimal PE32 GUI in MSVC 2017 15.5+ with POGO enabled.
- Strip all imports except GDI32/USER32/KERNEL32 GUI functions.
- Embed a PEB-walker that resolves VirtualAlloc, CreateThread, InternetOpen, etc. by export hash.
- Encrypt the
.textsection with XOR-NOT (key = 0x10035fff), storing the decryptor in.itext. - Embed an individualized payload in
.dataencrypted with the same cipher. - Add CPUID anti-VM and RDTSC timing gate at entry.
- Verify: run
capaon the reproducer — should hit the same TTPs as the cluster.
Deployable Signatures
YARA Rule — MSVC 14.12 Reflective Loader Cluster
rule BlackMatter_ReflectiveLoader_Cluster
{
meta:
description = "MSVC 14.12 PEB-walking reflective-loader cluster (blackmatter/unattributed)"
author = "PacketPursuit"
date = "2026-08-30"
hash1 = "8796e69f738fceb99fd177a5536dbccf5112ffa202a8b05be10ab45e600e289b"
hash2 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
version = "3.2"
strings:
$s_text_hash = { 00 0a 9a 8b 14 40 e4 4c de 00 fd 7a cc 5b dd a6 }
$s_xor_key = { ff 5f 03 11 }
$s_alpha1 = "ABCD" ascii wide
$s_alpha2 = "EFGH" ascii wide
$s_alpha3 = "IJKL" ascii wide
$s_alpha4 = "MNOP" ascii wide
$s_alpha5 = "QRST" ascii wide
$s_alpha6 = "UVWX" ascii wide
$s_alpha7 = "YZab" ascii wide
$s_alpha8 = "cdef" ascii wide
$s_alpha9 = "ghij" ascii wide
$s_alpha10 = "klmn" ascii wide
$s_alpha11 = "opqr" ascii wide
$s_alpha12 = "stuv" ascii wide
$s_alpha13 = "wxyz" ascii wide
$imp_gdi = "gdi32.dll" ascii wide
$imp_user = "USER32.dll" ascii wide
$imp_kernel = "KERNEL32.dll" ascii wide
$poi1 = "CreateSolidBrush" ascii wide
$poi2 = "GetDeviceCaps" ascii wide
$poi3 = "SetPixel" ascii wide
$poi4 = "DialogBoxParamW" ascii wide
$poi5 = "GetKeyNameTextW" ascii wide
$poi6 = "LoadLibraryW" ascii wide
$poi7 = "GetTickCount" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
uint16(uint32(0x3C)+0x18) == 0x010B and
uint16(uint32(0x3C)+0x40) == 0x0002 and
uint16(uint32(0x3C)+0x14) == 0x00E0 and
uint16(uint32(0x3C)+0x14+0x02) == 0x0102 and
uint16(uint32(0x3C)+0x40+0x06) == 0x8140 and
uint8(uint32(0x3C)+0x18+0x02) == 0x0E and
uint8(uint32(0x3C)+0x18+0x03) == 0x0C and
uint32(uint32(0x3C)+0x08) == 0x631A9665 and
($s_xor_key at 0x400 or $s_xor_key at 0x401 or $s_xor_key at 0x402 or $s_xor_key at 0x403) and
3 of ($s_alpha*) and
all of ($imp_*) and
5 of ($poi*) and
uint16(uint32(0x3C)+0x06) == 6
}
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 8796e69f738fceb99fd177a5536dbccf5112ffa202a8b05be10ab45e600e289b |
File hash |
| .text SHA-256 | 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
Section hash (cluster match) |
| .data SHA-256 | 580e7e7fe0c2c204fa5d676442f7ccd96b1b408d2a9201652ee49081459a3308 |
Section hash (unique payload) |
| PE Checksum (stored) | 0x2E93A |
PE header |
| PE Checksum (computed) | 0x2CC20 |
Mismatch indicates post-build modification |
| Compilation timestamp | 0x631A9665 (Fri Sep 9 01:27:01 2022 UTC) |
Builder artifact |
| XOR cipher key | 0x10035fff |
Decryption key |
| LCG multiplier | 0x19660d |
PRNG constant |
| LCG increment | 0x3c6ef35f |
PRNG constant |
Behavioral Fingerprint
This binary is a 150 KB PE32 GUI with MSVC 14.12 linker signature, POGO optimization, six standard sections, and a minimal import facade (25 total imports across GDI32/USER32/KERNEL32, all GUI housekeeping). The .text section is encrypted and only decrypts at runtime via an XOR-NOT cipher with key 0x10035fff. The entry point is a single encrypted byte (0xc4). At runtime, the stub walks the PEB InMemoryOrderModuleList to resolve ~30 threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptAcquireContext, etc.) by export hash, caching pointers in a pseudo-import table in .data. It performs CPUID hypervisor-bit checks and RDTSC differential timing before spawning worker threads for file-system enumeration and HTTP POST C2 communication. C2 URLs are generated on-the-fly via an LCG PRNG with constants 0x19660d/0x3c6ef35f indexing a 62-character alphabet table. No static C2 strings exist. The .data section carries a per-sample individualized encrypted payload. This is a builder-template malware, not a hand-crafted binary.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1620 | Reflective Code Loading | PEB-walking API resolution → VirtualAlloc → section mapping → in-memory execution ^[r2:fcn.00417034] |
| T1055 | Process Injection | VirtualAlloc + WriteProcessMemory + VirtualProtect + CreateRemoteThread / ResumeThread ^[r2:fcn.00417034] |
| T1059 | Command and Scripting Interpreter | Worker threads spawn child processes with command-line arguments ^[r2:fcn.00417034] |
| T1083 | File and Directory Discovery | Recursive FindFirstFileA / FindNextFileA with * wildcard in dedicated thread ^[r2:fcn.00407468] |
| T1071.001 | Application Layer Protocol: Web Protocols | HTTP POST C2 with WinInet API handles ^[r2:fcn.0040782c] |
| T1573.001 | Encrypted Channel: Symmetric Cryptography | Payload encrypted with XOR-NOT cipher; C2 body encrypted with CryptEncrypt ^[r2:fcn.00401240] |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit check + RDTSC timing gate ^[r2:fcn.004010bc] |
| T1027.002 | Obfuscated Files or Information: Software Packing | In-place .text decryption; encrypted entry point ^[pefile.txt:93] |
| T1070.004 | Indicator Removal: File Deletion | Self-erasure routine referenced in thread worker ^[r2:fcn.0040782c] |
References
- Primary analysis:
136b5750— /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html - Cluster entity: blackmatter
- Umbrella entity: unattributed
- Technique page: peb-walking-api-resolution
- Technique page: prng-seeded-c2-url-decoding
- OpenCTI artifact ID:
fc9d83fd-99a8-48e0-8382-bc8bc7267af0 - MalwareBazaar:
8796e69f738fceb99fd177a5536dbccf5112ffa202a8b05be10ab45e600e289b
Provenance
file.txt— file(1) outputpefile.txt— pefile Python modulerabin2-info.txt— radare2rabin2 -Iexiftool.json— ExifTool 12.76strings.txt— strings(1)yara.txt— YARAmetadata.json— OpenCTI connector artifact metadatar2:fcn.*— radare2 5.x analysis (level 3), 519 functions found.text/.datasection hashes computed with Python hashlib.sha256- Cross-sibling comparison against prior 31 cluster analyses via grep on
wiki/wiki/raw/analyses/*/report.md