a2dca6efacc34720cbfeb2e75b15ee587bd2263f1720f63f373bc1632c603553blackmatter: a2dca6ef — twelfth confirmed sibling in MSVC 14.12 reflective-loader cluster
Executive Summary: PE32 GUI reflective loader compiled Sep 9 2022 with MSVC 14.12 and POGO optimization. Shares an identical stub template with eleven prior siblings (136b5750, 3b42403b, 21b12514, 9d8526b0, 0b525c35, 370415c8, c527ebf0, d715b248, dc870a75, 73841818, 0017ecc5, 34ca794e). The only delta is the encrypted .data payload (unique hash, entropy 7.986) and PE checksum (0x28FB1). No runtime behavior available — CAPE skipped due to no Windows guest.
What It Is
- File:
file(149,504 bytes) ^[file.txt] - Type: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections ^[file.txt]
- Compilation: Fri Sep 9 01:27:01 2022 UTC (
0x631A9665) ^[pefile.txt] - Linker: MSVC 14.12 (VS 2017 15.5+) ^[pefile.txt]
- Optimization: POGO (
IMAGE_DEBUG_TYPE_POGO) ^[pefile.txt] - Subsystem: Windows GUI ^[rabin2-info.txt]
- Mitigations: ASLR (
pic: true), DEP/NX (nx: true), stack canary (canary: true) ^[rabin2-info.txt] - Signing: Unsigned ^[rabin2-info.txt]
- OpenCTI labels:
dropped-by-phorpiex,exe,malware-bazaar^[triage.json]
How It Works
This sample is a cluster sibling of the MSVC 14.12 reflective-loader family. The stub — entry point, API resolution, anti-analysis, and decryption logic — is byte-identical to the eleven prior siblings analyzed in this corpus. The threat payload is individualized per-sample via encrypted contents in the .data section.
For the full build-stack and behavioral analysis of this family, see the primary report:
- /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
- blackmatter — entity page with cluster table and capability list
Per-Sample Deltas
| Field | This Sample | Primary (136b5750) |
|---|---|---|
| SHA-256 | a2dca6ef... |
136b5750... |
| PE Checksum | 0x28FB1 |
0x2BC5A |
.text MD5 |
cfbda2c4... (identical) |
cfbda2c4... |
.data MD5 |
ce19fe01... |
3d7c9a8e... (different) |
.data entropy |
7.986 | 7.981 |
.data size |
0xADC8 (40,968 bytes) | varies |
The .text section hash match confirms the stub is shared; the .data hash divergence confirms per-sample payload customization. ^[pefile.txt]
Key Artefacts Recovered
- XOR key:
0x10035fffpresent at offset0x0A80in.data— identical across all twelve siblings ^[r2:hexdump at 0x0A80] - Alphabet table: Base64-like character sequence
ABCD...89+/at offset0x0810in.text— identical to primary ^[r2:strings "ABCD"] - Import facade: Only 25 imports across three DLLs — GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI/shell functions. No network, crypto, or process APIs in the IAT. All threat APIs are resolved at runtime via PEB walking. ^[pefile.txt]
Decompiled Behavior
No Ghidra decompilation was performed for this sibling because the stub is byte-identical to 136b5750, which was fully decompiled in the primary analysis. The entry point at 0x41946F (EP RVA) leads through the same PEB-walking InMemoryOrderModuleList traversal, export-name hashing, and pseudo-import table caching observed in every prior sibling. Radare2 analysis completed successfully (519 functions discovered) but the decompiler output was truncated; the function graph is structurally identical to 136b5750.
C2 Infrastructure
Static-only. No plaintext C2 strings, domains, IPs, or URLs were recovered from the encrypted .data payload. The primary analysis (136b5750) describes the LCG PRNG-based C2 URL generation that produces URLs at runtime; this sample uses the same PRNG constants (0x19660d/0x3c6ef35f) and therefore generates URLs from the same algorithmic space. Without dynamic execution, the actual C2 endpoint for this specific payload cannot be determined.
Interesting Tidbits
- Builder pipeline fingerprint: Twelve samples sharing an identical compilation timestamp (
0x631A9665) and linker version (14.12) with only.datacontents varying is consistent with a builder that encrypts per-campaign payloads into a shared MSVC stub. The PE checksums are individualized, indicating the builder recalculates checksums per output. ^[pefile.txt] - No .NET, no Go, no Rust: Pure native C/C++ with no managed-runtime artefacts. This is a deliberate lightweight choice for evading EDR signatures that target .NET/Go runtime imports.
- POGO optimization as anti-analysis side-effect: Profile-guided optimization scatters hot paths unpredictably, making manual trace-through harder without degrading the binary's performance.
How To Mess With It (Homelab Replication)
See the primary analysis 136b5750 for a full replication recipe. For this sibling specifically:
- Build a minimal PE32 stub in MSVC 14.12 with POGO enabled (
/GL /LTCG:PGOptimize). - Implement PEB-walking API resolution (walk
InMemoryOrderModuleList, hash export names with a custom algorithm, cache resolved addresses in a.datapseudo-import table). - Encrypt your payload with the XOR-NOT cipher using key
0x10035fff. - Embed the encrypted payload in
.dataand set the.datasection toR/W. - At runtime, decrypt
.datain-place, fix relocations, and transfer control. - Compare the resulting PE checksum to
0x28FB1— it will differ because your payload hash is unique.
Deployable Signatures
YARA — Cluster Stub Detection
rule BlackMatter_Loader_Stub_Msvc1412
{
meta:
description = "MSVC 14.12 reflective-loader stub shared by blackmatter-tagged cluster"
author = "PacketPursuit"
date = "2026-07-30"
hash = "a2dca6efacc34720cbfeb2e75b15ee587bd2263f1720f63f373bc1632c603553"
hash = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
strings:
$xor_key = { 35 ff 5f 03 10 }
$alphabet = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
$section_itext = ".itext"
$section_pdata = ".pdata"
condition:
uint16(0) == 0x5A4D and
$xor_key and
$alphabet and
$section_itext and
$section_pdata and
pe.linker_version.major == 14 and
pe.linker_version.minor >= 10 and
pe.number_of_sections == 6 and
pe.timestamp == 0x631A9665
}
YARA — Per-Sample Anchor (a2dca6ef)
rule BlackMatter_Loader_a2dca6ef
{
meta:
description = "Specific sibling anchor for a2dca6ef"
author = "PacketPursuit"
date = "2026-07-30"
hash = "a2dca6efacc34720cbfeb2e75b15ee587bd2263f1720f63f373bc1632c603553"
strings:
$stub = { 35 ff 5f 03 10 }
condition:
uint16(0) == 0x5A4D and
$stub at 0x0A80 and
pe.checksum == 0x28FB1 and
pe.timestamp == 0x631A9665
}
IOC List
| Type | Value | Source |
|---|---|---|
| SHA-256 | a2dca6efacc34720cbfeb2e75b15ee587bd2263f1720f63f373bc1632c603553 |
triage.json |
| SHA-1 | 5d12d573caddd78d39ef56deaf9afe44636ae19b (.text section) |
pefile.txt |
MD5 (.text) |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
pefile.txt |
MD5 (.data) |
ce19fe01f5a844906637e20cee745574 |
pefile.txt |
| PE Checksum | 0x28FB1 |
pefile.txt |
| Compilation | 0x631A9665 (2022-09-09 01:27:01 UTC) |
pefile.txt |
| XOR Key | 0x10035fff |
r2 hex dump |
| Delivery tag | dropped-by-phorpiex |
triage.json |
Behavioral Fingerprint
This binary presents as a small (~146 KB) Windows GUI application with a minimal import table consisting entirely of GDI32, USER32, and KERNEL32 GUI functions. At runtime, it walks the PEB InMemoryOrderModuleList to resolve 30+ threat APIs (VirtualAlloc, CreateProcess, WinInet, CryptEncrypt, etc.) by hashing export names. It performs CPUID hypervisor-bit detection and RDTSC timing gates before decrypting an encrypted payload in .data using a fixed XOR-NOT cipher with key 0x10035fff. Post-decryption, it fixes relocations and jumps to the payload. C2 URLs are generated algorithmically via an LCG PRNG (0x19660d/0x3c6ef35f). The stub is identical across at least twelve siblings; only the encrypted payload and PE checksum vary.
Detection Signatures
No capa output was produced for this sample (signature path missing at analysis time). Based on the primary analysis (136b5750), the expected ATT&CK mappings are:
| Technique | ID | Evidence |
|---|---|---|
| Reflective PE Loading | T1620 | Decrypt .data → fix relocations → execute in-memory ^[primary:136b5750] |
| PEB Walking API Resolution | T1106 | InMemoryOrderModuleList traversal with export-name hashing ^[primary:136b5750] |
| VirtualAlloc RWX Staging | T1055.012 | RWX memory allocation for decrypted payload ^[primary:136b5750] |
| CPUID Hypervisor Bit Check | T1497.001 | Anti-VM gate before payload decryption ^[primary:136b5750] |
| RDTSC Timing Gate | T1497.001 | Anti-emulation delay via timestamp counter ^[primary:136b5750] |
| LCG PRNG C2 URL Generation | T1071.001 | Algorithmic C2 endpoint generation ^[primary:136b5750] |
| Data Encrypted for Impact | T1486 | XOR-NOT payload encryption ^[primary:136b5750] |
References
- Primary analysis: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
- Family entity: blackmatter
- Delivery infrastructure: phorpiex
- Technique: peb-walking-api-resolution
Provenance
This report synthesizes static artefacts from:
file.txt(file type)pefile.txt(PE headers, sections, imports, debug info, checksums)rabin2-info.txt(radare2 binary summary)strings.txt(static strings — no plaintext C2 recovered)triage.json(OpenCTI labels, ssdeep, yara)binwalk.txt(no embedded archives — standard PE only)- Radare2 hex dump at offset
0x0A80(XOR key confirmation) - Dynamic analysis: skipped — no CAPE Windows guest available ^[dynamic-analysis.md]
All claims marked ^[primary:136b5750] trace to the primary sibling analysis where this stub was first decompiled. Per-sample deltas are derived from the current sample's pefile.txt and rabin2-info.txt.