966baf32504c07e467c8bdddd35a43b4908a8a7b1eb54cb14edc056608604d47unclassified-dotnet-bitmap-stego-loader: 966baf32 — Spanish purchase-order lure, 22 embedded BMPs, Apr 2026 build
Executive Summary
Spanish-language purchase-order lure (nueva orden de compra.exe) compiled Apr 2026, embedding 22 small bitmap resources (76×76×24) that serve as encrypted payload carriers. Tenth confirmed sibling of the unclassified-dotnet-bitmap-stego-loader cluster. Decrypts inner payload via RijndaelManaged + CryptoStream and reflectively loads it with Assembly.Load → GetMethod → Invoke. No hardcoded C2 URLs recovered; SoapHttpClientProtocol reference suggests SOAP-over-HTTP C2 in the decrypted stage. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- Filename:
nueva orden de compra.exe(Spanish "new purchase order") — social-engineering lure targeting procurement/finance users. ^[exiftool.json] - Format: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections, 1.1 MB. ^[file.txt]
- Compile stamp: Wed Apr 1 11:12:03 2026 UTC. ^[pefile.txt:34]
- Linker: MSVC 8.0 stub (MajorLinkerVersion 8, MinorLinkerVersion 0). ^[pefile.txt:45]
- Import surface: Single native import
mscoree.dll!_CorExeMain— standard .NET PE bootstrap. ^[pefile.txt:254] - Signing: Unsigned. ^[rabin2-info.txt:27]
- Resources:
.rsrcsection contains 22 embeddedSystem.Drawing.Bitmapobjects (76×76×24 PC bitmap format confirmed by binwalk). ^[binwalk.txt] ^[strings.txt:1072] - Namespace:
6ajWgBb4Pf3(randomized alphanumeric). Resource streams:6ajWgBb4Pf3.g.resources,6ajWgBb4Pf3.Resources.resources,50ab05dc2f47bd.Resources.resources. ^[strings.txt:3083-3086] - Version info: Nonsense metadata — company
J>:G2>@9CAE3D66@AA<, product94B<E=GFA>75CB4, internal namesdfgchvjbknkhvgfnd.exe, version10.21.31.2. Matches cluster masquerade pattern. ^[pefile.txt:233-242]
Family ascription: High-confidence sibling of unclassified-dotnet-bitmap-stego-loader. Shared cluster fingerprint: .NET Framework PE32, ~20 embedded 76×76 BMPs, RijndaelManaged + CryptoStream decryption chain, Assembly.Load reflective loading, SoapHttpClientProtocol reference, purchase-order social-engineering lure, fabricated nonsense VS_VERSIONINFO. ^[capa.txt] ^[strings.txt:2376-3401]
Per-sample deltas:
- Language: Spanish lure (first in cluster; prior siblings used English, Portuguese, or maritime/fleet themes).
- Bitmap count: 22 (cluster range 4–283; this sits in the typical ~20 range).
- Build date: Apr 2026 — most recent sibling in cluster (prior ranged 2019–2024).
- Version:
10.21.31.2(near twin ofa497a066which used10.21.32.8). - Namespace:
6ajWgBb4Pf3(fresh randomization, not shared with prior siblings). - No
BackgroundWorkerstrings observed (present inf6b5bdd5,9ac1c1db). - No
DeflateStream/System.IO.Compressionstrings (present inf230118dand some crypter-loader siblings, absent here as in most cluster members).
How It Works
- .NET stub launch —
mscoree!_CorExeMainhands off to the CLR. ^[pefile.txt:254] - Resource extraction — The binary accesses its own
.rsrcdirectory viaSystem.Resources.ResourceReaderandSystem.Resources.RuntimeResourceSet(strings observed at multiple offsets). ^[strings.txt:200] ^[strings.txt:1071] - Bitmap stego decode — 22
System.Drawing.Bitmapresources are iterated. Pixel data (RGB channels from 76×76×24 BMPs) is extracted and treated as ciphertext. The cluster uses RGB channel extraction routines (observed in siblingf31920baas_GClr,_AClrData,_PixProcess,_ProcessYCoords). ^[binwalk.txt] ^[entities/unclassified-dotnet-bitmap-stego-loader.md] - AES/Rijndael decryption —
RijndaelManaged+CryptoStream+MemoryStream+CreateDecryptorstrings confirm a symmetric decryption step. ^[strings.txt:2766-3046] - Reflective assembly loading —
Assembly.Load→GetMethod→Invokechain loads the decrypted inner payload without disk write. ^[strings.txt:2396] ^[strings.txt:2449] ^[capa.txt:53] - C2 surface (inferred) —
SoapHttpClientProtocolstring (System.Web.Services.Protocols.SoapHttpClientProtocol) suggests the inner payload uses SOAP-over-HTTP for C2. No hardcoded endpoint URLs are recoverable statically; they are likely embedded in the encrypted bitmap payload or resolved at runtime. ^[strings.txt:3401] - System reconnaissance —
capaflags account discovery, file/directory enumeration, system info discovery, and session username harvesting. These are likely pre-exfiltration or sandbox-gating behaviours in the inner payload. ^[capa.txt:15-21]
Decompiled Behavior
No .NET decompiler (ILSpy, dnSpy, or monodis) is available on this analysis station. Ghidra/radare2 are not configured for CIL decompilation. Static analysis was conducted via strings, capa, floss (floss failed due to CLI argument error), binwalk, and pefile. No decompiled pseudo-C is available. The cluster's inner payload decryption routine has not been recovered statically in any sibling to date; all rely on dynamic detonation or manual bitmap extraction + key recovery.
C2 Infrastructure
No hardcoded IP, domain, URL, mutex, or named pipe recovered statically. The encrypted payload inside the bitmaps is the only source of C2 IOCs, and it is not recoverable without the decryption key or dynamic execution.
Inferred C2 protocol: SOAP over HTTP via SoapHttpClientProtocol (inner payload). ^[strings.txt:3401]
Interesting Tidbits
- Repeated artifact
mDs6\6appears 17 times in the strings output, interleaved between bitmap resource references. Likely a string-obfuscation delimiter, fixed XOR key fragment, or padding artifact generated by the cluster's builder. ^[strings.txt:1138-1490] - Spanish-language targeting is a first for this cluster. Prior siblings used English (
Purchase Order.exe,Order_PI.exe), Portuguese (copia del pago anticipado.exe), maritime (vessel's_main_particulars.exe), or clinical-trial (Especificaciones del presupuesto) themes. This suggests either geographic expansion of the operator or a builder that randomizes the lure language. - April Fools' compile timestamp (Apr 1 2026) — could be genuine build date or deliberate timestamp manipulation. The cluster's compile dates span 2019–2026 with no obvious seasonality.
- No ConfuserEx name mangling (
#=q…==pattern absent). Obfuscation is limited to randomized namespace names and garbage string padding, making this a lighter build than ConfuserEx-packed siblings in the broader.NETcrypter-loader ecosystem. - Two distinct resource names (
6ajWgBb4Pf3.Resources.resourcesand50ab05dc2f47bd.Resources.resources) suggest the builder may chain two resource sets: one for the outer loader and one for the encrypted payload metadata.
How To Mess With It (Homelab Replication)
To reproduce a comparable .NET bitmap-stego loader fingerprint:
- Toolchain: Visual Studio 2022 or MSBuild targeting .NET Framework 4.x (4.0–4.8).
- Project type: C# WinForms or Console app.
- Embed bitmaps: Add 20–30 small BMP files (76×76×24) to
Properties/Resources.resxvia the Visual Studio resource designer. Mark asEmbedded Resource. - Encrypt payload: Write a small .NET DLL (the "inner payload"). Encrypt it with
RijndaelManaged(AES-256) in CBC mode. Split the ciphertext into chunks and embed as RGB byte arrays inside the bitmap pixel data (e.g., replace least-significant bits or entire pixel channels). - Loader stub: At runtime, iterate
Assembly.GetManifestResourceNames(), filter for.resources, instantiateResourceManager, extractBitmapobjects, read pixel data viaBitmap.LockBits(), reconstruct the ciphertext byte array, then decrypt withRijndaelManaged+CryptoStreamover aMemoryStream. - Reflective load:
Assembly.Load(decryptedBytes)→Type.GetType("MainModule.Entry")→MethodInfo.Invoke(). - Verification: Run
capaon the resulting EXE. Expect hits:compiled to the .NET platform,invoke .NET assembly method,access .NET resource,save image in .NET,encrypt data using AES via .NET, and ATT&CK mappingsT1620,T1027.
What you'll learn: How to build a resource-only .NET reflective loader that evades static IAT inspection and nests its payload inside seemingly benign image assets.
Deployable Signatures
YARA Rule
rule UnclassifiedDotNetBitmapStegoLoader {
meta:
description = ".NET Framework bitmap-stego loader cluster — encrypted payload hidden in embedded BMP resources"
author = "Titus / PacketPursuit"
date = "2026-08-11"
sha256 = "966baf32504c07e467c8bdddd35a43b4908a8a7b1eb54cb14edc056608604d47"
family = "unclassified-dotnet-bitmap-stego-loader"
strings:
$a1 = "System.Drawing.Bitmap" ascii wide
$a2 = "System.Resources.ResourceReader" ascii wide
$a3 = "System.Resources.RuntimeResourceSet" ascii wide
$a4 = "RijndaelManaged" ascii wide
$a5 = "CryptoStream" ascii wide
$a6 = "CreateDecryptor" ascii wide
$a7 = "SoapHttpClientProtocol" ascii wide
$a8 = "Assembly.Load" ascii wide
$a9 = "GetMethod" ascii wide
$a10 = "Invoke" ascii wide
$b1 = "mscoree.dll" ascii wide
$c1 = /[A-Za-z0-9]{10,20}\.Resources\.resources/ ascii wide
$c2 = /[A-Za-z0-9]{10,20}\.g\.resources/ ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
$b1 and
4 of ($a*) and
1 of ($c*)
}
Behavioral Hunt Query (Sigma-compatible pseudo-YAML)
title: .NET Bitmap-Stego Loader Process Behavior
description: Detects reflective .NET assembly loading after resource extraction and image decoding
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith:
- 'nueva orden de compra.exe'
- 'Purchase Order.exe'
- 'Order.exe'
- 'Order_PI.exe'
- 'copia del pago anticipado.exe'
- 'vessel\'s_main_particulars.exe'
CommandLine|contains:
- 'powershell'
- 'cmd.exe'
# Alternatively, ETW / .NET tracing:
# ModuleLoad: System.Drawing.dll followed by System.Security.Cryptography.dll
# within 5 seconds of mscoree.dll process start, and no subsequent disk writes
# of a DLL/EXE by the same process.
condition: selection
falsepositives:
- Legitimate .NET applications that embed large bitmap resource sets
level: medium
IOC List
| Indicator | Type | Value | Notes |
|---|---|---|---|
| SHA-256 | hash | 966baf32504c07e467c8bdddd35a43b4908a8a7b1eb54cb14edc056608604d47 |
Primary sample |
| Filename | filename | nueva orden de compra.exe |
Spanish purchase-order lure |
| Internal name | filename | sdfgchvjbknkhvgfnd.exe |
Keyboard-mash pattern |
| Company | version-info | J>:G2>@9CAE3D66@AA< |
Nonsense masquerade |
| Version | version-info | 10.21.31.2 |
Cluster signature version |
| .NET namespace | metadata | 6ajWgBb4Pf3 |
Randomized per build |
| Bitmap count | resource | 22 | 76×76×24 BMPs in .rsrc |
| Artifact | strings | mDs6\6 (×17) |
Repeated obfuscation artifact |
| Compile date | timestamp | 2026-04-01 11:12:03 UTC |
April 2026 build |
Behavioral Fingerprint Statement
This binary is a .NET Framework PE32 executable with a single native import (mscoree.dll!_CorExeMain). Upon launch, it loads 20–30 small embedded BMP resources from its own .rsrc section via System.Resources.ResourceReader, extracts pixel data, decrypts a nested payload using RijndaelManaged + CryptoStream, and reflectively loads the decrypted assembly via Assembly.Load → GetMethod → Invoke. No malicious APIs are imported at the PE level; all threat behaviour lives inside the encrypted inner payload. The outer binary carries nonsense VS_VERSIONINFO metadata and a randomized .NET namespace. The cluster shows a consistent purchase-order social-engineering lure and SoapHttpClientProtocol references suggesting SOAP/HTTP C2 in the inner stage.
Detection Signatures (capa → ATT&CK)
| ATT&CK Tactic | Technique | Evidence |
|---|---|---|
| Defense Evasion | T1027 Obfuscated Files or Information | AES-encrypted payload embedded in bitmap resources ^[capa.txt:15] |
| Defense Evasion | T1620 Reflective Code Loading | Assembly.Load, GetMethod, Invoke ^[capa.txt:16] ^[capa.txt:53] |
| Discovery | T1087 Account Discovery | get session user name (3 matches) ^[capa.txt:17] |
| Discovery | T1083 File and Directory Discovery | enumerate files in .NET, check if file exists ^[capa.txt:18] |
| Discovery | T1082 System Information Discovery | get hostname ^[capa.txt:19] |
| Discovery | T1033 System Owner/User Discovery | get session user name ^[capa.txt:20] |
| Collection | — | save image in .NET (bitmap resource staging) ^[capa.txt:37] |
| Cryptography | — | encrypt data using AES via .NET ^[capa.txt:38] |
Note: T1497.001 (Virtualization/Sandbox Evasion) was flagged in the first sibling (4bf14434) but not in this sample's capa output. This may indicate builder-level toggling of anti-VM checks, or capa rule variance across builds.
References
- Artifact ID:
d3f93216-14d8-4b54-8e55-1ab2bf2bdbba - Source: MalwareBazaar via OpenCTI connector
- Wiki entity: unclassified-dotnet-bitmap-stego-loader
- Sibling reports:
4bf14434,db0d6bc0,f74d8a51,f6b5bdd5,f230118d,d4d106f8,a497a066,f31920ba,9ac1c1db
Provenance
Analysis based on static inputs generated 2026-05-28. File type: file v5.44. ExifTool v12.76. pefile v2023.2.7. radare2 v5.8.8 (rabin2 -I). binwalk v2.3.2. capa v7.0.1 (capa -v). floss v2.3.0 (failed with CLI argument error, no output). strings (strings -n 6). No dynamic analysis available (CAPE skipped — no Windows guest). No .NET decompiler available (ILSpy/dnSpy/monodis absent). Report written 2026-08-11.