9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8ablackmatter: 9d8526b0 — confirmed twin of unattributed MSVC 14.12 reflective loader (136b5750)
Executive Summary
A 150 KB PE32 GUI binary with the exact same compilation timestamp, linker version, section layout, and encrypted .data payload structure as 136b5750 — the unattributed MSVC 14.12 reflective loader with PEB-walking API resolution, XOR-NOT alphabet cipher, CPUID anti-VM, and LCG-based C2 URL generation. OpenCTI tags this sample as blackmatter and dropped-by-phorpiex. The binary is not BlackMatter ransomware (no encryption routines, no ransom-note artifacts, no dark-web leak-site references); it is a second-stage reflective loader dropped by Phorpiex infrastructure. Static-only analysis.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal: GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI housekeeping ^[pefile.txt:249] |
| YARA | Generic PE only ^[yara.txt] |
Cluster Relationship
This sample is a confirmed binary twin of 136b5750 (unattributed MSVC reflective loader) and the five other "blackmatter" samples in the corpus (0b525c35, 370415c8, c527ebf0, d715b248, f8850a32). All share:
- Identical compilation timestamp (
0x631A9665, Sep 9 2022 01:27:01 UTC) - Identical linker version (14.12)
- Identical section layout (
.text,.itext,.rdata,.data,.pdata,.reloc) - Identical
.textsection size (0x17E00) and MD5 (cfbda2c44e51b3b0b00bcbbc767c62a2) - Identical
.dataentropy (~7.988) and high-entropy encrypted payload structure - Identical XOR key
0x10035fffused for string/pointer encryption - Identical POGO debug metadata
The only deltas between siblings are:
- PE checksum (this sample:
0x32784;136b5750:0x2BC5A) .datasection hashes (individualized encrypted payload per sample).pdatasection hashes (runtime function pointer tables differ per payload)- Unique strings recovered from
.data(different encrypted blobs, decoded at runtime)
This confirms a builder pipeline that compiles a shared stub once, then injects individualized encrypted payloads into the .data section, recomputes the PE checksum, and distributes each build with a different hash. ^[pefile.txt] ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
How It Works
All behavioral analysis for this binary is identical to 136b5750. See the primary report for full decompiled details:
/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
Key behaviors (summarized):
- Entry Point (
0x419470) → delegates to runtime orchestrator at0x417034. - PEB-Walking API Resolution — walks
InMemoryOrderModuleListviafs:[0x30], resolves ~30+ threat APIs (VirtualAlloc, CreateThread, InternetOpen, CryptEncrypt) by hash, caches in.datapseudo-import table at0x425xxx. ^[techniques/peb-walking-api-resolution.md] - String Encryption — XOR
0x10035fffthen NOT; builds a base-62 alphabet table (A-Z a-z 0-9) from encrypted DWORD arrays. C2 URLs and User-Agent strings are generated at runtime via LCG PRNG + alphabet lookup. ^[r2:fcn.00401240] ^[r2:fcn.0040d4b0] - Anti-VM — CPUID leaf 1 ECX[31] (hypervisor bit) and leaf 7 EBX[18]; RDTSC differential timing with rotate-13. ^[r2:fcn.004010bc]
- LCG PRNG —
seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. ^[r2:fcn.0040110c] - Network / C2 — HTTP POST body assembly with encrypted payload; WinInet handle allocation. No hard-coded domains — all runtime-generated. ^[r2:fcn.0040cfcc] ^[r2:fcn.0040782c]
- File-System Enumeration — recursive
"*"wildcard enumeration via resolved FindFirstFile/FindNextFile. ^[r2:fcn.00407468] - Reflective Loader — VirtualAlloc → write decrypted payload → VirtualProtect → thread creation. ^[r2:fcn.00406668]
Decompiled Behavior
See 136b5750 report for the full function table. Notable functions in this twin:
| Address | Role |
|---|---|
0x4010bc |
Anti-debug/VM gate (CPUID + RDTSC) |
0x40110c |
LCG PRNG |
0x401240 |
XOR-NOT decrypt stub |
0x405da0 |
Pseudo-import table installer (multiple encrypted slots) |
0x405aec |
PEB-walking export resolver |
0x406668 |
Reflective PE mapper |
0x409990 |
Secondary orchestrator (thread spawning, flag gates) |
0x417034 |
Main orchestrator (PEB-walk, thread creation) |
0x417458 |
Module loader with XOR-decrypted slot names |
C2 Infrastructure
No hard-coded C2 endpoints. Runtime-generated via LCG + alphabet table. See 136b5750 report for detailed inference. ^[/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html]
Interesting Tidbits
- BlackMatter mislabel: OpenCTI tags this as
blackmatter, but static analysis shows zero ransomware-specific behavior (no file-encryption loops, no ransom-note string fragments, no Tor C2). The label likely originates from a shared dropper infrastructure or false-positive clustering. This is a loader, not ransomware. ^[metadata.json] ^[triage.json] - Phorpiex drop linkage: The
dropped-by-phorpiextag is accurate in the delivery-chain sense — Phorpiex spam infrastructure drops this binary — but the payload itself is a distinct, heavier reflective loader unrelated to Phorpiex's own thin downloader stubs. ^[phorpiex.md] - POGO optimization on a crimeware loader is unusual; suggests a builder pipeline that treats compilation as a CI step with full MSVC release optimization. ^[pefile.txt:313]
- GUI subsystem with no GUI logic: The USER32/GDI32 imports and
Windows GUIsubsystem are decoys or minimal scaffolding. NoCreateWindow, no message loop, no GDI drawing in the decompiled entry path. ^[file.txt]
How To Mess With It (Homelab Replication)
See 136b5750 report — identical stub template. Reproduce the PEB-walker, XOR-NOT cipher, LCG PRNG, and CPUID anti-VM gate. Per-sample customization is limited to the encrypted .data payload blob.
Deployable Signatures
YARA Rule
rule blackmatter_9d8526b0_msvc_pe32_reflective_loader
{
meta:
description = "MSVC 14.12 PE32 reflective loader twin (blackmatter OpenCTI label) with PEB-walking API resolution and XOR-NOT string crypto"
author = "PacketPursuit"
date = "2026-07-29"
sha256 = "9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a"
strings:
$xor_not_key = { 81 31 FF 5F 03 10 }
$lcg_mul = { 0D 66 19 00 00 }
$lcg_inc = { 35 3C EF C6 03 }
$lcg_mask = { 25 FF FF FF 07 }
$alphabet_1 = { 41 BB BF EA }
$alphabet_2 = { 45 E6 BB A7 }
$post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C) + 0x18) == 0x10B and
2 of ($xor_not_*) and
2 of ($lcg_*) and
2 of ($alphabet_*) and
$post_wide
}
Behavioral Fingerprint
This binary presents a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by export hash, caching pointers in a
.datapseudo-import table. It allocates RWX memory, maps a decrypted payload, and spawns parallel threads for file-system enumeration (FindFirstFilewith"*"wildcard) and HTTP POST C2 communication. The POST body is encrypted; C2 domain and User-Agent are generated at runtime via a seeded LCG PRNG indexing a base-62 alphabet table. VM execution triggers altered paths via CPUID hypervisor-bit checks and RDTSC timing gates.
IOCs
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | 9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a |
This sample |
| SHA-256 (twin) | 136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51 |
Primary analysis |
| SHA-256 (siblings) | 0b525c35..., 370415c8..., c527ebf0..., d715b248..., f8850a32... |
Same stub, different .data payload |
| Compilation | Sep 9 2022 01:27:01 UTC | Timestamp 0x631A9665 (shared across cluster) |
| Linker | 14.12 | VS 2017 15.5+ |
| TLSH | C3E37D21F612D0B3C87718F13736B1B2F39E8D2C29A56907DAD80F99BC658236F05997 |
.data entropy-high |
| XOR Key | 0x10035fff |
String + pointer encryption |
| LCG multiplier | 0x19660d |
PRNG constant |
| LCG increment | 0x3c6ef35f |
PRNG constant |
| Pseudo-import region | 0x425000–0x425fff (.data VA) |
Decrypted at runtime |
Detection Signatures
| ATT&CK Technique | Implementation |
|---|---|
| T1055 — Process Injection | Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation |
| T1071.001 — Application Layer Protocol: Web Protocols | HTTP POST C2 with encrypted body; WinInet API resolution |
| T1027 — Obfuscated Files or Information | XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation |
| T1497.001 — Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) |
| T1497.002 — Virtualization/Sandbox Evasion: User Activity Based | RDTSC differential timing gate |
| T1083 — File and Directory Discovery | Recursive "*" enumeration via FindFirstFile / FindNextFile |
| T1573.001 — Encrypted Channel: Symmetric Cryptography | CryptEncrypt / CryptDecrypt for C2 payload body |
| T1105 — Ingress Tool Transfer | Downloader / payload retrieval via HTTP POST response handling |
References
- OpenCTI artifact:
83a7ab8e-b3d2-4537-bda4-8d2ad868a6cf, labels:blackmatter,dropped-by-phorpiex,exe,malware-bazaar^[metadata.json] - Primary analysis (confirmed twin): /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
- Related entity pages: blackmatter, unattributed, phorpiex
- Technique page: peb-walking-api-resolution
Provenance
Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt, strings.txt) and radare2 decompilation (analysis level 3) of the binary at <sample 9d8526b0ecc2.bin>. CAPA failed due to missing signature database; floss failed due to incorrect CLI invocation. CAPE dynamic analysis skipped — no Windows guest available. Behavioral claims are statically inferred or derived from the confirmed-twin 136b5750 report.