typeanalysisfamilyblackmatterconfidencemediumcreated2026-07-29updated2026-07-29pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: 9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a

blackmatter: 9d8526b0 — confirmed twin of unattributed MSVC 14.12 reflective loader (136b5750)

Executive Summary

A 150 KB PE32 GUI binary with the exact same compilation timestamp, linker version, section layout, and encrypted .data payload structure as 136b5750 — the unattributed MSVC 14.12 reflective loader with PEB-walking API resolution, XOR-NOT alphabet cipher, CPUID anti-VM, and LCG-based C2 URL generation. OpenCTI tags this sample as blackmatter and dropped-by-phorpiex. The binary is not BlackMatter ransomware (no encryption routines, no ransom-note artifacts, no dark-web leak-site references); it is a second-stage reflective loader dropped by Phorpiex infrastructure. Static-only analysis.

What It Is

Field Value
SHA-256 9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal: GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI housekeeping ^[pefile.txt:249]
YARA Generic PE only ^[yara.txt]

Cluster Relationship

This sample is a confirmed binary twin of 136b5750 (unattributed MSVC reflective loader) and the five other "blackmatter" samples in the corpus (0b525c35, 370415c8, c527ebf0, d715b248, f8850a32). All share:

  • Identical compilation timestamp (0x631A9665, Sep 9 2022 01:27:01 UTC)
  • Identical linker version (14.12)
  • Identical section layout (.text, .itext, .rdata, .data, .pdata, .reloc)
  • Identical .text section size (0x17E00) and MD5 (cfbda2c44e51b3b0b00bcbbc767c62a2)
  • Identical .data entropy (~7.988) and high-entropy encrypted payload structure
  • Identical XOR key 0x10035fff used for string/pointer encryption
  • Identical POGO debug metadata

The only deltas between siblings are:

  • PE checksum (this sample: 0x32784; 136b5750: 0x2BC5A)
  • .data section hashes (individualized encrypted payload per sample)
  • .pdata section hashes (runtime function pointer tables differ per payload)
  • Unique strings recovered from .data (different encrypted blobs, decoded at runtime)

This confirms a builder pipeline that compiles a shared stub once, then injects individualized encrypted payloads into the .data section, recomputes the PE checksum, and distributes each build with a different hash. ^[pefile.txt] ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

How It Works

All behavioral analysis for this binary is identical to 136b5750. See the primary report for full decompiled details:

/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html

Key behaviors (summarized):

  1. Entry Point (0x419470) → delegates to runtime orchestrator at 0x417034.
  2. PEB-Walking API Resolution — walks InMemoryOrderModuleList via fs:[0x30], resolves ~30+ threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptEncrypt) by hash, caches in .data pseudo-import table at 0x425xxx. ^[techniques/peb-walking-api-resolution.md]
  3. String Encryption — XOR 0x10035fff then NOT; builds a base-62 alphabet table (A-Z a-z 0-9) from encrypted DWORD arrays. C2 URLs and User-Agent strings are generated at runtime via LCG PRNG + alphabet lookup. ^[r2:fcn.00401240] ^[r2:fcn.0040d4b0]
  4. Anti-VM — CPUID leaf 1 ECX[31] (hypervisor bit) and leaf 7 EBX[18]; RDTSC differential timing with rotate-13. ^[r2:fcn.004010bc]
  5. LCG PRNG — seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. ^[r2:fcn.0040110c]
  6. Network / C2 — HTTP POST body assembly with encrypted payload; WinInet handle allocation. No hard-coded domains — all runtime-generated. ^[r2:fcn.0040cfcc] ^[r2:fcn.0040782c]
  7. File-System Enumeration — recursive "*" wildcard enumeration via resolved FindFirstFile/FindNextFile. ^[r2:fcn.00407468]
  8. Reflective Loader — VirtualAlloc → write decrypted payload → VirtualProtect → thread creation. ^[r2:fcn.00406668]

Decompiled Behavior

See 136b5750 report for the full function table. Notable functions in this twin:

Address Role
0x4010bc Anti-debug/VM gate (CPUID + RDTSC)
0x40110c LCG PRNG
0x401240 XOR-NOT decrypt stub
0x405da0 Pseudo-import table installer (multiple encrypted slots)
0x405aec PEB-walking export resolver
0x406668 Reflective PE mapper
0x409990 Secondary orchestrator (thread spawning, flag gates)
0x417034 Main orchestrator (PEB-walk, thread creation)
0x417458 Module loader with XOR-decrypted slot names

C2 Infrastructure

No hard-coded C2 endpoints. Runtime-generated via LCG + alphabet table. See 136b5750 report for detailed inference. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]

Interesting Tidbits

  • BlackMatter mislabel: OpenCTI tags this as blackmatter, but static analysis shows zero ransomware-specific behavior (no file-encryption loops, no ransom-note string fragments, no Tor C2). The label likely originates from a shared dropper infrastructure or false-positive clustering. This is a loader, not ransomware. ^[metadata.json] ^[triage.json]
  • Phorpiex drop linkage: The dropped-by-phorpiex tag is accurate in the delivery-chain sense — Phorpiex spam infrastructure drops this binary — but the payload itself is a distinct, heavier reflective loader unrelated to Phorpiex's own thin downloader stubs. ^[phorpiex.md]
  • POGO optimization on a crimeware loader is unusual; suggests a builder pipeline that treats compilation as a CI step with full MSVC release optimization. ^[pefile.txt:313]
  • GUI subsystem with no GUI logic: The USER32/GDI32 imports and Windows GUI subsystem are decoys or minimal scaffolding. No CreateWindow, no message loop, no GDI drawing in the decompiled entry path. ^[file.txt]

How To Mess With It (Homelab Replication)

See 136b5750 report — identical stub template. Reproduce the PEB-walker, XOR-NOT cipher, LCG PRNG, and CPUID anti-VM gate. Per-sample customization is limited to the encrypted .data payload blob.

Deployable Signatures

YARA Rule

rule blackmatter_9d8526b0_msvc_pe32_reflective_loader
{
    meta:
        description = "MSVC 14.12 PE32 reflective loader twin (blackmatter OpenCTI label) with PEB-walking API resolution and XOR-NOT string crypto"
        author = "PacketPursuit"
        date = "2026-07-29"
        sha256 = "9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a"
    strings:
        $xor_not_key = { 81 31 FF 5F 03 10 }
        $lcg_mul = { 0D 66 19 00 00 }
        $lcg_inc = { 35 3C EF C6 03 }
        $lcg_mask = { 25 FF FF FF 07 }
        $alphabet_1 = { 41 BB BF EA }
        $alphabet_2 = { 45 E6 BB A7 }
        $post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + 0x18) == 0x10B and
        2 of ($xor_not_*) and
        2 of ($lcg_*) and
        2 of ($alphabet_*) and
        $post_wide
}

Behavioral Fingerprint

This binary presents a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by export hash, caching pointers in a .data pseudo-import table. It allocates RWX memory, maps a decrypted payload, and spawns parallel threads for file-system enumeration (FindFirstFile with "*" wildcard) and HTTP POST C2 communication. The POST body is encrypted; C2 domain and User-Agent are generated at runtime via a seeded LCG PRNG indexing a base-62 alphabet table. VM execution triggers altered paths via CPUID hypervisor-bit checks and RDTSC timing gates.

IOCs

Indicator Value Notes
SHA-256 9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a This sample
SHA-256 (twin) 136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51 Primary analysis
SHA-256 (siblings) 0b525c35..., 370415c8..., c527ebf0..., d715b248..., f8850a32... Same stub, different .data payload
Compilation Sep 9 2022 01:27:01 UTC Timestamp 0x631A9665 (shared across cluster)
Linker 14.12 VS 2017 15.5+
TLSH C3E37D21F612D0B3C87718F13736B1B2F39E8D2C29A56907DAD80F99BC658236F05997 .data entropy-high
XOR Key 0x10035fff String + pointer encryption
LCG multiplier 0x19660d PRNG constant
LCG increment 0x3c6ef35f PRNG constant
Pseudo-import region 0x425000–0x425fff (.data VA) Decrypted at runtime

Detection Signatures

ATT&CK Technique Implementation
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18])
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling

References

  • OpenCTI artifact: 83a7ab8e-b3d2-4537-bda4-8d2ad868a6cf, labels: blackmatter, dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
  • Primary analysis (confirmed twin): /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Related entity pages: blackmatter, unattributed, phorpiex
  • Technique page: peb-walking-api-resolution

Provenance

Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt, strings.txt) and radare2 decompilation (analysis level 3) of the binary at <sample 9d8526b0ecc2.bin>. CAPA failed due to missing signature database; floss failed due to incorrect CLI invocation. CAPE dynamic analysis skipped — no Windows guest available. Behavioral claims are statically inferred or derived from the confirmed-twin 136b5750 report.