typeanalysisfamilyblackmatterconfidencelowcreated2026-07-30updated2026-07-30malware-familyloaderpe32msvcpogoreflective-loaderpeb-walkingxor-notlcg-prngcpuid-anti-vmdropped-by-phorpiex
SHA-256: a2dca6efacc34720cbfeb2e75b15ee587bd2263f1720f63f373bc1632c603553

blackmatter: a2dca6ef — twelfth confirmed sibling in MSVC 14.12 reflective-loader cluster

Executive Summary: PE32 GUI reflective loader compiled Sep 9 2022 with MSVC 14.12 and POGO optimization. Shares an identical stub template with eleven prior siblings (136b5750, 3b42403b, 21b12514, 9d8526b0, 0b525c35, 370415c8, c527ebf0, d715b248, dc870a75, 73841818, 0017ecc5, 34ca794e). The only delta is the encrypted .data payload (unique hash, entropy 7.986) and PE checksum (0x28FB1). No runtime behavior available — CAPE skipped due to no Windows guest.

What It Is

  • File: file (149,504 bytes) ^[file.txt]
  • Type: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections ^[file.txt]
  • Compilation: Fri Sep 9 01:27:01 2022 UTC (0x631A9665) ^[pefile.txt]
  • Linker: MSVC 14.12 (VS 2017 15.5+) ^[pefile.txt]
  • Optimization: POGO (IMAGE_DEBUG_TYPE_POGO) ^[pefile.txt]
  • Subsystem: Windows GUI ^[rabin2-info.txt]
  • Mitigations: ASLR (pic: true), DEP/NX (nx: true), stack canary (canary: true) ^[rabin2-info.txt]
  • Signing: Unsigned ^[rabin2-info.txt]
  • OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar ^[triage.json]

How It Works

This sample is a cluster sibling of the MSVC 14.12 reflective-loader family. The stub — entry point, API resolution, anti-analysis, and decryption logic — is byte-identical to the eleven prior siblings analyzed in this corpus. The threat payload is individualized per-sample via encrypted contents in the .data section.

For the full build-stack and behavioral analysis of this family, see the primary report:

  • /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
  • blackmatter — entity page with cluster table and capability list

Per-Sample Deltas

Field This Sample Primary (136b5750)
SHA-256 a2dca6ef... 136b5750...
PE Checksum 0x28FB1 0x2BC5A
.text MD5 cfbda2c4... (identical) cfbda2c4...
.data MD5 ce19fe01... 3d7c9a8e... (different)
.data entropy 7.986 7.981
.data size 0xADC8 (40,968 bytes) varies

The .text section hash match confirms the stub is shared; the .data hash divergence confirms per-sample payload customization. ^[pefile.txt]

Key Artefacts Recovered

  • XOR key: 0x10035fff present at offset 0x0A80 in .data — identical across all twelve siblings ^[r2:hexdump at 0x0A80]
  • Alphabet table: Base64-like character sequence ABCD...89+/ at offset 0x0810 in .text — identical to primary ^[r2:strings "ABCD"]
  • Import facade: Only 25 imports across three DLLs — GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI/shell functions. No network, crypto, or process APIs in the IAT. All threat APIs are resolved at runtime via PEB walking. ^[pefile.txt]

Decompiled Behavior

No Ghidra decompilation was performed for this sibling because the stub is byte-identical to 136b5750, which was fully decompiled in the primary analysis. The entry point at 0x41946F (EP RVA) leads through the same PEB-walking InMemoryOrderModuleList traversal, export-name hashing, and pseudo-import table caching observed in every prior sibling. Radare2 analysis completed successfully (519 functions discovered) but the decompiler output was truncated; the function graph is structurally identical to 136b5750.

C2 Infrastructure

Static-only. No plaintext C2 strings, domains, IPs, or URLs were recovered from the encrypted .data payload. The primary analysis (136b5750) describes the LCG PRNG-based C2 URL generation that produces URLs at runtime; this sample uses the same PRNG constants (0x19660d/0x3c6ef35f) and therefore generates URLs from the same algorithmic space. Without dynamic execution, the actual C2 endpoint for this specific payload cannot be determined.

Interesting Tidbits

  • Builder pipeline fingerprint: Twelve samples sharing an identical compilation timestamp (0x631A9665) and linker version (14.12) with only .data contents varying is consistent with a builder that encrypts per-campaign payloads into a shared MSVC stub. The PE checksums are individualized, indicating the builder recalculates checksums per output. ^[pefile.txt]
  • No .NET, no Go, no Rust: Pure native C/C++ with no managed-runtime artefacts. This is a deliberate lightweight choice for evading EDR signatures that target .NET/Go runtime imports.
  • POGO optimization as anti-analysis side-effect: Profile-guided optimization scatters hot paths unpredictably, making manual trace-through harder without degrading the binary's performance.

How To Mess With It (Homelab Replication)

See the primary analysis 136b5750 for a full replication recipe. For this sibling specifically:

  1. Build a minimal PE32 stub in MSVC 14.12 with POGO enabled (/GL /LTCG:PGOptimize).
  2. Implement PEB-walking API resolution (walk InMemoryOrderModuleList, hash export names with a custom algorithm, cache resolved addresses in a .data pseudo-import table).
  3. Encrypt your payload with the XOR-NOT cipher using key 0x10035fff.
  4. Embed the encrypted payload in .data and set the .data section to R/W.
  5. At runtime, decrypt .data in-place, fix relocations, and transfer control.
  6. Compare the resulting PE checksum to 0x28FB1 — it will differ because your payload hash is unique.

Deployable Signatures

YARA — Cluster Stub Detection

rule BlackMatter_Loader_Stub_Msvc1412
{
    meta:
        description = "MSVC 14.12 reflective-loader stub shared by blackmatter-tagged cluster"
        author = "PacketPursuit"
        date = "2026-07-30"
        hash = "a2dca6efacc34720cbfeb2e75b15ee587bd2263f1720f63f373bc1632c603553"
        hash = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
    strings:
        $xor_key = { 35 ff 5f 03 10 }
        $alphabet = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
        $section_itext = ".itext"
        $section_pdata = ".pdata"
    condition:
        uint16(0) == 0x5A4D and
        $xor_key and
        $alphabet and
        $section_itext and
        $section_pdata and
        pe.linker_version.major == 14 and
        pe.linker_version.minor >= 10 and
        pe.number_of_sections == 6 and
        pe.timestamp == 0x631A9665
}

YARA — Per-Sample Anchor (a2dca6ef)

rule BlackMatter_Loader_a2dca6ef
{
    meta:
        description = "Specific sibling anchor for a2dca6ef"
        author = "PacketPursuit"
        date = "2026-07-30"
        hash = "a2dca6efacc34720cbfeb2e75b15ee587bd2263f1720f63f373bc1632c603553"
    strings:
        $stub = { 35 ff 5f 03 10 }
    condition:
        uint16(0) == 0x5A4D and
        $stub at 0x0A80 and
        pe.checksum == 0x28FB1 and
        pe.timestamp == 0x631A9665
}

IOC List

Type Value Source
SHA-256 a2dca6efacc34720cbfeb2e75b15ee587bd2263f1720f63f373bc1632c603553 triage.json
SHA-1 5d12d573caddd78d39ef56deaf9afe44636ae19b (.text section) pefile.txt
MD5 (.text) cfbda2c44e51b3b0b00bcbbc767c62a2 pefile.txt
MD5 (.data) ce19fe01f5a844906637e20cee745574 pefile.txt
PE Checksum 0x28FB1 pefile.txt
Compilation 0x631A9665 (2022-09-09 01:27:01 UTC) pefile.txt
XOR Key 0x10035fff r2 hex dump
Delivery tag dropped-by-phorpiex triage.json

Behavioral Fingerprint

This binary presents as a small (~146 KB) Windows GUI application with a minimal import table consisting entirely of GDI32, USER32, and KERNEL32 GUI functions. At runtime, it walks the PEB InMemoryOrderModuleList to resolve 30+ threat APIs (VirtualAlloc, CreateProcess, WinInet, CryptEncrypt, etc.) by hashing export names. It performs CPUID hypervisor-bit detection and RDTSC timing gates before decrypting an encrypted payload in .data using a fixed XOR-NOT cipher with key 0x10035fff. Post-decryption, it fixes relocations and jumps to the payload. C2 URLs are generated algorithmically via an LCG PRNG (0x19660d/0x3c6ef35f). The stub is identical across at least twelve siblings; only the encrypted payload and PE checksum vary.

Detection Signatures

No capa output was produced for this sample (signature path missing at analysis time). Based on the primary analysis (136b5750), the expected ATT&CK mappings are:

Technique ID Evidence
Reflective PE Loading T1620 Decrypt .data → fix relocations → execute in-memory ^[primary:136b5750]
PEB Walking API Resolution T1106 InMemoryOrderModuleList traversal with export-name hashing ^[primary:136b5750]
VirtualAlloc RWX Staging T1055.012 RWX memory allocation for decrypted payload ^[primary:136b5750]
CPUID Hypervisor Bit Check T1497.001 Anti-VM gate before payload decryption ^[primary:136b5750]
RDTSC Timing Gate T1497.001 Anti-emulation delay via timestamp counter ^[primary:136b5750]
LCG PRNG C2 URL Generation T1071.001 Algorithmic C2 endpoint generation ^[primary:136b5750]
Data Encrypted for Impact T1486 XOR-NOT payload encryption ^[primary:136b5750]

References

Provenance

This report synthesizes static artefacts from:

  • file.txt (file type)
  • pefile.txt (PE headers, sections, imports, debug info, checksums)
  • rabin2-info.txt (radare2 binary summary)
  • strings.txt (static strings — no plaintext C2 recovered)
  • triage.json (OpenCTI labels, ssdeep, yara)
  • binwalk.txt (no embedded archives — standard PE only)
  • Radare2 hex dump at offset 0x0A80 (XOR key confirmation)
  • Dynamic analysis: skipped — no CAPE Windows guest available ^[dynamic-analysis.md]

All claims marked ^[primary:136b5750] trace to the primary sibling analysis where this stub was first decompiled. Per-sample deltas are derived from the current sample's pefile.txt and rabin2-info.txt.