91e39f6bb60a3860e6d1dc1fb711a8865281407614d5d106d03678c8723f2ddfunattributed: 91e39f6bb60a — 21st confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster
Executive Summary
A 150 KB PE32 GUI binary compiled with MSVC 14.12 (VS 2017 15.5+) on 9 Sep 2022. It is the 21st confirmed sibling in the reflective-loader cluster first characterised by 136b5750. The .text section hash matches the majority-group stub template shared by siblings ae02bd22, 21b12514, 7e9bbc5c, e67dbabcd, 2ac8295381, 89dc341bbd, and 8655b3b9b2; .data and PE checksum differ, indicating an individualized encrypted payload injected by the builder pipeline. OpenCTI labels are dropped-by-phorpiex and malware-bazaar — the contested blackmatter tag was not applied, consistent with the cluster's delivery via Phorpiex spam infrastructure rather than a true BlackMatter ransomware payload. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 91e39f6bb60a3860e6d1dc1fb711a8865281407614d5d106d03678c8723f2ddf |
| SHA-1 | 5d12d573caddd78d39ef56deaf9afe44636ae19b ^[pefile.txt:95] |
| MD5 | 717d31fa2fcb93200633181a60d4c2a3 ^[pefile.txt:93] |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) ^[pefile.txt:249] |
| YARA | Generic PE only; no family-specific hits ^[yara.txt] |
| OpenCTI labels | dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json] |
| Family (triage) | null — no family attribution ^[triage.json] |
The binary is not packed and carries no overlay. The import table is a facade: threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptEncrypt, etc.) are resolved at runtime via PEB-walking through InMemoryOrderModuleList, with pointers cached in a pseudo-import table inside the .data section.
How It Works
Stub Template (Shared with Siblings)
All structural behaviour is identical to the cluster stub described in the primary analysis for 136b5750 and the sibling report for 21b12514. In brief:
- Entry point at
0x1946F(RVA) delegates through the MSVC C runtime in.itextto the orchestrator at~0x417034. ^[r2:fcn.0041946f] - PEB-walking API resolver loads kernel32 by iterating
InMemoryOrderModuleList, hashes export names, and caches ~30+ threat APIs in.dataslots (0x425000–0x425fff). ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] - XOR-NOT string cipher at
0x401240:buf[i] ^= 0x10035fff; buf[i] = ~buf[i];. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html] - Alphabet table built at
0x40d4b0from 16 encrypted DWORDs, decrypting toABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html] - Anti-VM gate at
0x4010bc: CPUID leaf 1 ECX[31] (hypervisor bit), leaf 7 EBX[18], plus RDTSC rotate-13 differential timing. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] - LCG PRNG at
0x40110c:seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. Used for runtime C2 URL generation. ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html] - Threading model: file-system enumeration thread (
0x407468) and C2 communication thread (0x40782c), with a reflective PE loader / memory mapper at0x406668. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
Per-Sample Delta
| Attribute | 91e39f6bb60a (this) | 8655b3b9b2 (20th sibling) | ae02bd22 (14th sibling) |
|---|---|---|---|
| PE Checksum | 0x33158 |
0x2EBD4 |
0x2BE18 |
.text MD5 |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
.text SHA-256 |
000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
.data SHA-256 |
108818f3fd84a18bcfa9e00c5fc0f2707e643e31364c3bbb94be05ef7b7185e7 |
035c5d8e... |
c6dbe40d... |
The .text hash match with the majority group confirms this sample shares the exact same compiled stub template. The .data hash divergence confirms the builder injects a per-sample encrypted payload. The PE checksum differs, which is expected because checksum covers the entire image including .data. ^[pefile.txt]
Decompiled Behavior
Radare2 decompilation of the POGO-optimized entry point (0x41946f) yields a 1-byte chop stub — the MSVC C runtime entry trampoline is heavily optimised and the decompiler loses the context. The real logic is recovered at fcn.0040639c and onward, identical to the sibling analysis. For full decompiled pseudocode, pseudo-import slot map, and control-flow details, see the primary analysis: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html. ^[r2:fcn.0041946f]
C2 Infrastructure
No static C2 URLs, domains, or IPs are recoverable. All network indicators are generated at runtime by the LCG PRNG and encoded via the base-62 alphabet table. C2 communication uses WinInet-style HTTP POST with encrypted body data (CryptEncrypt / CryptDecrypt). See the primary sibling analysis for the reconstructed C2 wire format. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
Interesting Tidbits
- OpenCTI label gap: This sample is tagged
dropped-by-phorpiexbut notblackmatter, consistent with the 18th–20th siblings and confirming theblackmatterlabel is inconsistently applied by the upstream connector and is not a reliable family signal. ^[metadata.json] .itextsparse layout: The.itextsection is 0x600 bytes on disk but only 0x546 bytes of code; the remainder is zero-padded. The entry-point RVA0x1946Ffalls at offset0x46Fwithin.itext, preceded by ~1 KB of padding. Consistent with POGO link-time code generation placing cold paths at the section tail. ^[pefile.txt]- capa / floss failure: Both tools failed during triage — capa due to missing signatures, floss due to argument parsing errors. This is a pipeline artefact, not a binary anti-analysis measure. ^[capa.txt] ^[floss.txt]
- No version-info masquerade: Unlike many Phorpiex-delivered samples, this binary carries no
VS_VERSIONINFOresource at all (resource directory size = 0). ^[pefile.txt:207] - 21st sibling: Extends the known cluster from 20 to 21 confirmed samples, all sharing the Sep 9 2022 compilation timestamp — a single builder batch or a heavily reused template.
How To Mess With It (Homelab Replication)
See the primary sibling analysis for a full replication recipe. The stub template is MSVC 14.12 C++ with POGO (/LTCG:PGOptimize), compiled for x86 Windows GUI. To reproduce the behavioural fingerprint:
- Build a 32-bit PE with MSVC 14.12, enable
/guard:cfand/LTCG:PGOptimize. - Implement PEB-walking
InMemoryOrderModuleListtraversal with export-name hashing. - Encrypt all strings with XOR-NOT (
key = 0x10035fff), store in.data. - Add CPUID leaf 1/7 checks and RDTSC differential timing gate.
- Implement LCG PRNG (
0x19660d/0x3c6ef35f) for runtime URL generation. - Compile with minimal static imports (GDI32/USER32/KERNEL32 facade only).
- Run
capaon the reproducer and compare capability hits to sibling reports.
Deployable Signatures
YARA Rule — MSVC 14.12 POGO Reflective Loader Stub
rule MSVC_1412_Pogo_ReflectiveLoader_Stub
{
meta:
description = "MSVC 14.12 POGO reflective loader stub with PEB-walking, XOR-NOT crypto, and CPUID anti-VM"
author = "PacketPursuit SOC"
date = "2026-08-29"
sha256 = "91e39f6bb60a3860e6d1dc1fb711a8865281407614d5d106d03678c8723f2ddf"
strings:
$peb_walk_prologue = { 64 A1 30 00 00 00 } // mov eax, fs:[0x30] (PEB)
$xor_not_key = { 3D FF 5F 03 10 } // cmp eax, 0x10035fff (key material)
$lcg_mul = { 0D 60 96 19 00 } // 0x19660d multiplier
$lcg_inc = { 35 5F F3 6E 3C } // 0x3c6ef35f increment
$cpuid_leaf1 = { 0F A2 81 E1 00 00 00 80 } // cpuid; test ecx, 0x80000000
$pogo_debug = { 0D 00 00 00 00 F4 00 00 00 } // IMAGE_DEBUG_TYPE_POGO header
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
uint16(uint32(0x3C)+0x18) == 0x10B and // PE32
uint8(uint32(0x3C)+0x5D) == 0x0E and // MajorLinkerVersion = 14
uint8(uint32(0x3C)+0x5E) == 0x0C and // MinorLinkerVersion = 12
filesize <= 200KB and
#peb_walk_prologue >= 1 and
#pogo_debug >= 1 and
(
$xor_not_key or
($lcg_mul and $lcg_inc) or
$cpuid_leaf1
)
}
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 91e39f6bb60a3860e6d1dc1fb711a8865281407614d5d106d03678c8723f2ddf |
Hash |
| SHA-1 | 5d12d573caddd78d39ef56deaf9afe44636ae19b |
Hash ^[pefile.txt:95] |
| MD5 | 717d31fa2fcb93200633181a60d4c2a3 |
Hash ^[pefile.txt:93] |
| PE Timestamp | 0x631A9665 (Fri Sep 9 01:27:01 2022 UTC) |
Compilation |
| PE Checksum | 0x33158 |
Header |
| XOR-NOT Key | 0x10035fff |
Crypto |
| LCG Multiplier | 0x19660d |
PRNG |
| LCG Increment | 0x3c6ef35f |
PRNG |
.text MD5 |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
Section hash |
.text SHA-256 |
000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
Section hash |
.data SHA-256 |
108818f3fd84a18bcfa9e00c5fc0f2707e643e31364c3bbb94be05ef7b7185e7 |
Section hash |
| Pseudo-import region | 0x425000–0x425fff (.data VA) |
Runtime table |
| Anti-VM | CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 | Evasion |
| Delivery label | dropped-by-phorpiex |
OpenCTI tag |
Behavioral Fingerprint Statement
This binary is a 150 KB PE32 GUI with exactly six sections (.text, .itext, .rdata, .data, .pdata, .reloc), a POGO debug directory, linker version 14.12, and a static import surface of only 25 API imports across GDI32, USER32, and KERNEL32. On execution, it resolves threat APIs via PEB-walking, spawns dual worker threads for file-system enumeration and HTTP C2, and maps a reflective payload into self-allocated memory. The payload is encrypted in .data with a per-sample unique hash. Network C2 is generated at runtime via an LCG PRNG and transmitted over HTTP POST with encrypted bodies. VM/sandbox evasion is enforced by CPUID hypervisor-bit checks and RDTSC timing gates.
Detection Signatures (ATT&CK Mapping)
| Technique | Implementation | Evidence |
|---|---|---|
| T1055 — Process Injection | Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation |
Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] |
| T1071.001 — Application Layer Protocol: Web Protocols | HTTP POST C2 with encrypted body; WinInet API resolution | Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] |
| T1027 — Obfuscated Files or Information | XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation | Sibling analysis ^[/intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html] |
| T1497.001 — Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) | Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] |
| T1497.002 — Virtualization/Sandbox Evasion: User Activity Based | RDTSC differential timing gate | Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] |
| T1083 — File and Directory Discovery | Recursive "*" enumeration via FindFirstFile / FindNextFile |
Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] |
| T1573.001 — Encrypted Channel: Symmetric Cryptography | CryptEncrypt / CryptDecrypt for C2 payload body |
Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] |
| T1105 — Ingress Tool Transfer | Downloader / payload retrieval via HTTP POST response handling | Primary sibling analysis ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html] |
References
- Artifact ID:
dccfba0a-42da-4ff3-9445-9aa81abf7d6e^[triage.json] - Primary structural analysis (stub template): /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
- Sibling delta analysis: /intel/analyses/21b12514e8d728ac9c1381540af63aa2501ed5351e21bf9a90162233f9f85b2c.html
- 20th sibling (most recent prior): /intel/analyses/8655b3b9b297ef153354a4f9778d7b621dd94adf4ca66d526cd7f0095b7fe5d4.html
- Cluster catalogue (contested
blackmatterlabel): blackmatter - Delivery infrastructure: phorpiex
- API resolution technique: peb-walking-api-resolution
- PRNG C2 technique: prng-seeded-c2-url-decoding
- Umbrella entity for unattributed samples: unattributed
Provenance
Analysis derived from file, exiftool, pefile, rabin2, radare2, yara, binwalk, capa (errored), and floss (errored) outputs captured in raw/analyses/91e39f6bb60a3860e6d1dc1fb711a8865281407614d5d106d03678c8723f2ddf/. Cluster traits verified by cross-referencing section hashes against siblings 136b5750, 21b12514, 3b42403b, 0017ecc5, 73841818, a2dca6ef, 34ca794e, cdc7d79a, 877f1047, 7e9bbc5c, e67dbabcd, 2ac8295381, 89dc341bbd, 8655b3b9b2, and ae02bd22. Report drafted 2026-08-29.