typeanalysisfamilyunclassified-dotnet-bitmap-stego-loaderconfidencemediumcreated2026-08-11updated2026-08-11dotnetloaderbitmap-steganographyobfuscationreflective-loadingpurchase-order-lureunclassified
SHA-256: 966baf32504c07e467c8bdddd35a43b4908a8a7b1eb54cb14edc056608604d47

unclassified-dotnet-bitmap-stego-loader: 966baf32 — Spanish purchase-order lure, 22 embedded BMPs, Apr 2026 build

Executive Summary

Spanish-language purchase-order lure (nueva orden de compra.exe) compiled Apr 2026, embedding 22 small bitmap resources (76×76×24) that serve as encrypted payload carriers. Tenth confirmed sibling of the unclassified-dotnet-bitmap-stego-loader cluster. Decrypts inner payload via RijndaelManaged + CryptoStream and reflectively loads it with Assembly.Load → GetMethod → Invoke. No hardcoded C2 URLs recovered; SoapHttpClientProtocol reference suggests SOAP-over-HTTP C2 in the decrypted stage. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • Filename: nueva orden de compra.exe (Spanish "new purchase order") — social-engineering lure targeting procurement/finance users. ^[exiftool.json]
  • Format: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections, 1.1 MB. ^[file.txt]
  • Compile stamp: Wed Apr 1 11:12:03 2026 UTC. ^[pefile.txt:34]
  • Linker: MSVC 8.0 stub (MajorLinkerVersion 8, MinorLinkerVersion 0). ^[pefile.txt:45]
  • Import surface: Single native import mscoree.dll!_CorExeMain — standard .NET PE bootstrap. ^[pefile.txt:254]
  • Signing: Unsigned. ^[rabin2-info.txt:27]
  • Resources: .rsrc section contains 22 embedded System.Drawing.Bitmap objects (76×76×24 PC bitmap format confirmed by binwalk). ^[binwalk.txt] ^[strings.txt:1072]
  • Namespace: 6ajWgBb4Pf3 (randomized alphanumeric). Resource streams: 6ajWgBb4Pf3.g.resources, 6ajWgBb4Pf3.Resources.resources, 50ab05dc2f47bd.Resources.resources. ^[strings.txt:3083-3086]
  • Version info: Nonsense metadata — company J>:G2>@9CAE3D66@AA<, product 94B<E=GFA>75CB4, internal name sdfgchvjbknkhvgfnd.exe, version 10.21.31.2. Matches cluster masquerade pattern. ^[pefile.txt:233-242]

Family ascription: High-confidence sibling of unclassified-dotnet-bitmap-stego-loader. Shared cluster fingerprint: .NET Framework PE32, ~20 embedded 76×76 BMPs, RijndaelManaged + CryptoStream decryption chain, Assembly.Load reflective loading, SoapHttpClientProtocol reference, purchase-order social-engineering lure, fabricated nonsense VS_VERSIONINFO. ^[capa.txt] ^[strings.txt:2376-3401]

Per-sample deltas:

  • Language: Spanish lure (first in cluster; prior siblings used English, Portuguese, or maritime/fleet themes).
  • Bitmap count: 22 (cluster range 4–283; this sits in the typical ~20 range).
  • Build date: Apr 2026 — most recent sibling in cluster (prior ranged 2019–2024).
  • Version: 10.21.31.2 (near twin of a497a066 which used 10.21.32.8).
  • Namespace: 6ajWgBb4Pf3 (fresh randomization, not shared with prior siblings).
  • No BackgroundWorker strings observed (present in f6b5bdd5, 9ac1c1db).
  • No DeflateStream / System.IO.Compression strings (present in f230118d and some crypter-loader siblings, absent here as in most cluster members).

How It Works

  1. .NET stub launch — mscoree!_CorExeMain hands off to the CLR. ^[pefile.txt:254]
  2. Resource extraction — The binary accesses its own .rsrc directory via System.Resources.ResourceReader and System.Resources.RuntimeResourceSet (strings observed at multiple offsets). ^[strings.txt:200] ^[strings.txt:1071]
  3. Bitmap stego decode — 22 System.Drawing.Bitmap resources are iterated. Pixel data (RGB channels from 76×76×24 BMPs) is extracted and treated as ciphertext. The cluster uses RGB channel extraction routines (observed in sibling f31920ba as _GClr, _AClrData, _PixProcess, _ProcessYCoords). ^[binwalk.txt] ^[entities/unclassified-dotnet-bitmap-stego-loader.md]
  4. AES/Rijndael decryption — RijndaelManaged + CryptoStream + MemoryStream + CreateDecryptor strings confirm a symmetric decryption step. ^[strings.txt:2766-3046]
  5. Reflective assembly loading — Assembly.Load → GetMethod → Invoke chain loads the decrypted inner payload without disk write. ^[strings.txt:2396] ^[strings.txt:2449] ^[capa.txt:53]
  6. C2 surface (inferred) — SoapHttpClientProtocol string (System.Web.Services.Protocols.SoapHttpClientProtocol) suggests the inner payload uses SOAP-over-HTTP for C2. No hardcoded endpoint URLs are recoverable statically; they are likely embedded in the encrypted bitmap payload or resolved at runtime. ^[strings.txt:3401]
  7. System reconnaissance — capa flags account discovery, file/directory enumeration, system info discovery, and session username harvesting. These are likely pre-exfiltration or sandbox-gating behaviours in the inner payload. ^[capa.txt:15-21]

Decompiled Behavior

No .NET decompiler (ILSpy, dnSpy, or monodis) is available on this analysis station. Ghidra/radare2 are not configured for CIL decompilation. Static analysis was conducted via strings, capa, floss (floss failed due to CLI argument error), binwalk, and pefile. No decompiled pseudo-C is available. The cluster's inner payload decryption routine has not been recovered statically in any sibling to date; all rely on dynamic detonation or manual bitmap extraction + key recovery.

C2 Infrastructure

No hardcoded IP, domain, URL, mutex, or named pipe recovered statically. The encrypted payload inside the bitmaps is the only source of C2 IOCs, and it is not recoverable without the decryption key or dynamic execution.

Inferred C2 protocol: SOAP over HTTP via SoapHttpClientProtocol (inner payload). ^[strings.txt:3401]

Interesting Tidbits

  • Repeated artifact mDs6\6 appears 17 times in the strings output, interleaved between bitmap resource references. Likely a string-obfuscation delimiter, fixed XOR key fragment, or padding artifact generated by the cluster's builder. ^[strings.txt:1138-1490]
  • Spanish-language targeting is a first for this cluster. Prior siblings used English (Purchase Order.exe, Order_PI.exe), Portuguese (copia del pago anticipado.exe), maritime (vessel's_main_particulars.exe), or clinical-trial (Especificaciones del presupuesto) themes. This suggests either geographic expansion of the operator or a builder that randomizes the lure language.
  • April Fools' compile timestamp (Apr 1 2026) — could be genuine build date or deliberate timestamp manipulation. The cluster's compile dates span 2019–2026 with no obvious seasonality.
  • No ConfuserEx name mangling (#=q…== pattern absent). Obfuscation is limited to randomized namespace names and garbage string padding, making this a lighter build than ConfuserEx-packed siblings in the broader .NET crypter-loader ecosystem.
  • Two distinct resource names (6ajWgBb4Pf3.Resources.resources and 50ab05dc2f47bd.Resources.resources) suggest the builder may chain two resource sets: one for the outer loader and one for the encrypted payload metadata.

How To Mess With It (Homelab Replication)

To reproduce a comparable .NET bitmap-stego loader fingerprint:

  1. Toolchain: Visual Studio 2022 or MSBuild targeting .NET Framework 4.x (4.0–4.8).
  2. Project type: C# WinForms or Console app.
  3. Embed bitmaps: Add 20–30 small BMP files (76×76×24) to Properties/Resources.resx via the Visual Studio resource designer. Mark as Embedded Resource.
  4. Encrypt payload: Write a small .NET DLL (the "inner payload"). Encrypt it with RijndaelManaged (AES-256) in CBC mode. Split the ciphertext into chunks and embed as RGB byte arrays inside the bitmap pixel data (e.g., replace least-significant bits or entire pixel channels).
  5. Loader stub: At runtime, iterate Assembly.GetManifestResourceNames(), filter for .resources, instantiate ResourceManager, extract Bitmap objects, read pixel data via Bitmap.LockBits(), reconstruct the ciphertext byte array, then decrypt with RijndaelManaged + CryptoStream over a MemoryStream.
  6. Reflective load: Assembly.Load(decryptedBytes) → Type.GetType("MainModule.Entry") → MethodInfo.Invoke().
  7. Verification: Run capa on the resulting EXE. Expect hits: compiled to the .NET platform, invoke .NET assembly method, access .NET resource, save image in .NET, encrypt data using AES via .NET, and ATT&CK mappings T1620, T1027.

What you'll learn: How to build a resource-only .NET reflective loader that evades static IAT inspection and nests its payload inside seemingly benign image assets.

Deployable Signatures

YARA Rule

rule UnclassifiedDotNetBitmapStegoLoader {
    meta:
        description = ".NET Framework bitmap-stego loader cluster — encrypted payload hidden in embedded BMP resources"
        author = "Titus / PacketPursuit"
        date = "2026-08-11"
        sha256 = "966baf32504c07e467c8bdddd35a43b4908a8a7b1eb54cb14edc056608604d47"
        family = "unclassified-dotnet-bitmap-stego-loader"
    strings:
        $a1 = "System.Drawing.Bitmap" ascii wide
        $a2 = "System.Resources.ResourceReader" ascii wide
        $a3 = "System.Resources.RuntimeResourceSet" ascii wide
        $a4 = "RijndaelManaged" ascii wide
        $a5 = "CryptoStream" ascii wide
        $a6 = "CreateDecryptor" ascii wide
        $a7 = "SoapHttpClientProtocol" ascii wide
        $a8 = "Assembly.Load" ascii wide
        $a9 = "GetMethod" ascii wide
        $a10 = "Invoke" ascii wide
        $b1 = "mscoree.dll" ascii wide
        $c1 = /[A-Za-z0-9]{10,20}\.Resources\.resources/ ascii wide
        $c2 = /[A-Za-z0-9]{10,20}\.g\.resources/ ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        $b1 and
        4 of ($a*) and
        1 of ($c*)
}

Behavioral Hunt Query (Sigma-compatible pseudo-YAML)

title: .NET Bitmap-Stego Loader Process Behavior
description: Detects reflective .NET assembly loading after resource extraction and image decoding
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith:
      - 'nueva orden de compra.exe'
      - 'Purchase Order.exe'
      - 'Order.exe'
      - 'Order_PI.exe'
      - 'copia del pago anticipado.exe'
      - 'vessel\'s_main_particulars.exe'
    CommandLine|contains:
      - 'powershell'
      - 'cmd.exe'
  # Alternatively, ETW / .NET tracing:
  # ModuleLoad: System.Drawing.dll followed by System.Security.Cryptography.dll
  # within 5 seconds of mscoree.dll process start, and no subsequent disk writes
  # of a DLL/EXE by the same process.
condition: selection
falsepositives:
  - Legitimate .NET applications that embed large bitmap resource sets
level: medium

IOC List

Indicator Type Value Notes
SHA-256 hash 966baf32504c07e467c8bdddd35a43b4908a8a7b1eb54cb14edc056608604d47 Primary sample
Filename filename nueva orden de compra.exe Spanish purchase-order lure
Internal name filename sdfgchvjbknkhvgfnd.exe Keyboard-mash pattern
Company version-info J>:G2>@9CAE3D66@AA< Nonsense masquerade
Version version-info 10.21.31.2 Cluster signature version
.NET namespace metadata 6ajWgBb4Pf3 Randomized per build
Bitmap count resource 22 76×76×24 BMPs in .rsrc
Artifact strings mDs6\6 (×17) Repeated obfuscation artifact
Compile date timestamp 2026-04-01 11:12:03 UTC April 2026 build

Behavioral Fingerprint Statement

This binary is a .NET Framework PE32 executable with a single native import (mscoree.dll!_CorExeMain). Upon launch, it loads 20–30 small embedded BMP resources from its own .rsrc section via System.Resources.ResourceReader, extracts pixel data, decrypts a nested payload using RijndaelManaged + CryptoStream, and reflectively loads the decrypted assembly via Assembly.Load → GetMethod → Invoke. No malicious APIs are imported at the PE level; all threat behaviour lives inside the encrypted inner payload. The outer binary carries nonsense VS_VERSIONINFO metadata and a randomized .NET namespace. The cluster shows a consistent purchase-order social-engineering lure and SoapHttpClientProtocol references suggesting SOAP/HTTP C2 in the inner stage.

Detection Signatures (capa → ATT&CK)

ATT&CK Tactic Technique Evidence
Defense Evasion T1027 Obfuscated Files or Information AES-encrypted payload embedded in bitmap resources ^[capa.txt:15]
Defense Evasion T1620 Reflective Code Loading Assembly.Load, GetMethod, Invoke ^[capa.txt:16] ^[capa.txt:53]
Discovery T1087 Account Discovery get session user name (3 matches) ^[capa.txt:17]
Discovery T1083 File and Directory Discovery enumerate files in .NET, check if file exists ^[capa.txt:18]
Discovery T1082 System Information Discovery get hostname ^[capa.txt:19]
Discovery T1033 System Owner/User Discovery get session user name ^[capa.txt:20]
Collection — save image in .NET (bitmap resource staging) ^[capa.txt:37]
Cryptography — encrypt data using AES via .NET ^[capa.txt:38]

Note: T1497.001 (Virtualization/Sandbox Evasion) was flagged in the first sibling (4bf14434) but not in this sample's capa output. This may indicate builder-level toggling of anti-VM checks, or capa rule variance across builds.

References

  • Artifact ID: d3f93216-14d8-4b54-8e55-1ab2bf2bdbba
  • Source: MalwareBazaar via OpenCTI connector
  • Wiki entity: unclassified-dotnet-bitmap-stego-loader
  • Sibling reports: 4bf14434, db0d6bc0, f74d8a51, f6b5bdd5, f230118d, d4d106f8, a497a066, f31920ba, 9ac1c1db

Provenance

Analysis based on static inputs generated 2026-05-28. File type: file v5.44. ExifTool v12.76. pefile v2023.2.7. radare2 v5.8.8 (rabin2 -I). binwalk v2.3.2. capa v7.0.1 (capa -v). floss v2.3.0 (failed with CLI argument error, no output). strings (strings -n 6). No dynamic analysis available (CAPE skipped — no Windows guest). No .NET decompiler available (ILSpy/dnSpy/monodis absent). Report written 2026-08-11.