typeanalysisfamilyblackmatterconfidencelowcreated2026-08-29updated2026-08-29pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: a397bea4c70bf3264348c88fca652fcbb2d421832672fa58a790af67bf419469

blackmatter: a397bea4 — twenty-fifth confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster

Executive Summary

A 150 KB PE32 GUI binary compiled with MSVC 14.12 (VS 2017 15.5+) on 9 Sep 2022. Tagged blackmatter and dropped-by-phorpiex by OpenCTI. Static analysis confirms it is a binary twin of the unattributed MSVC reflective-loader cluster (136b5750, 9d8526b0, etc.) — same stub, same compilation timestamp, same .text hash (cfbda2c4...), same XOR key 0x10035fff, same anti-analysis gates, same LCG PRNG. The only delta is an individualized encrypted .data payload and a unique PE checksum (0x31603). This is the twenty-fifth confirmed sibling in the cluster. Static-only (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 a397bea4c70bf3264348c88fca652fcbb2d421832672fa58a790af67bf419469
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 — Visual Studio 2017 15.5+ ^[exiftool.json]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt]
Canary Enabled ^[rabin2-info.txt]
Signed Unsigned ^[rabin2-info.txt]
Overlay None ^[rabin2-info.txt]
Static imports Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt]
YARA Generic PE only ^[yara.txt]

Section Hashes

Section Size MD5 SHA-256 Entropy
.text 97,792 cfbda2c44e51b3b0b00bcbbc767c62a2 000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 6.6341
.itext 1,536 6f4cd57381bb5584c0a0755384d25180 38f20ce7e2c9381f3a07f666269d4f509565f5aa40d19aa383a8afd583bf60c2 2.9337
.rdata 1,536 bd829aa493ecd52fe5bec776d207f206 ce47d70dffec241b1a8e768bc48eb91352a2275202b52ec299995bdee67a426a 3.5366
.data 40,960 03e37fcc3635b880aa8101230a121919 5271c3df93d4a765cb4e050926b9f43160726830591f30b93e530440b5368397 7.9871
.pdata 2,560 32de82163d745e7f178c14678059ec79 6b10256f75f6ce5e5b955c3cfde07bf0e08987ded998434ecdf119f1828e6316 7.3215
.reloc 4,096 3f87e4c23650dfad0bee7da98889ba94 7b8a35469d264f92e4d13f7537e5ee98d40b2776426c0ad90298326533ad9e5e 6.7390

The .text MD5 cfbda2c4... matches the majority of the cluster (siblings 136b5750, 9d8526b0, 0b525c35, 370415c8, c527ebf0, d715b248, f8850a32, 73841818, 0017ecc5, 34ca794e, a2dca6ef, cdc7d79a, ae02bd22, 7e9bbc5c, e67dbabcd, 2ac8295381, 89dc341bbd, 8655b3b9b2, 91e39f6bb60a, 65844473d39b, 044539a2eacf, f016df16d0f3). The .data SHA-256 is unique per sibling, confirming individualized payload injection.

How It Works

Identical to sibling 136b5750 and all confirmed twins. See the primary report for full decompiled details:

/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html

Behavioral summary:

  1. Entry Point (0x41946F RVA) → delegates to runtime orchestrator at 0x417034.
  2. PEB-Walking API Resolution — walks InMemoryOrderModuleList via fs:[0x30], resolves ~30+ threat APIs by export hash, caches in .data pseudo-import table at 0x425xxx. ^[techniques/peb-walking-api-resolution.md]
  3. String Encryption — XOR 0x10035fff then NOT; builds a base-62 alphabet table (A-Z a-z 0-9). C2 URLs and User-Agent are generated at runtime via LCG PRNG + alphabet lookup. ^[r2:fcn.00401240]
  4. Anti-VM / Anti-Debug — CPUID leaf 1 ECX[31] (hypervisor bit) and leaf 7 EBX[18]; RDTSC differential timing with rotate-13. ^[r2:fcn.004010bc]
  5. LCG PRNG — seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. ^[r2:fcn.0040110c]
  6. Network / C2 — HTTP POST body assembly with encrypted payload; WinInet handle allocation. No hard-coded domains. ^[r2:fcn.00406668]
  7. File-System Enumeration — recursive "*" wildcard enumeration via resolved FindFirstFile/FindNextFile.
  8. Reflective Loader — VirtualAlloc → write decrypted payload → VirtualProtect → thread creation.

Decompiled Behavior

Address Role Evidence
0x4010bc Anti-debug/VM gate CPUID leaf 1 ECX[31] + leaf 7 EBX[18]; RDTSC rotate-13 timing ^[r2:fcn.004010bc]
0x40110c LCG PRNG stub Multiplier 0x19660d, increment 0x3c6ef35f ^[r2:fcn.0040110c]
0x401240 Decrypt stub XOR 0x10035fff then NOT; 147 call sites across the binary ^[r2:fcn.00401240]
0x406668 Reflective mapper / network init Allocates memory, resolves handles, builds HTTP POST body ^[r2:fcn.00406668]
0x417034 Main orchestrator PEB-walk, thread creation, flag-gated execution

C2 Infrastructure

No hard-coded C2 endpoints. Runtime-generated via LCG + alphabet table. See 136b5750 report for detailed inference.

Interesting Tidbits

  • Twenty-fifth sibling: The .text hash cfbda2c4... confirms this sample belongs to the majority stub group within the cluster. The PE checksum (0x31603) and unique .data payload confirm per-sample customization.
  • BlackMatter mislabel persists: OpenCTI continues tagging these as blackmatter, but no ransomware behavior is present. The label is a false-positive attribution from upstream clustering. ^[triage.json]
  • Phorpiex delivery chain: The dropped-by-phorpiex tag is accurate for delivery — these loaders are distributed by Phorpiex spam infrastructure — but the payload itself is a distinct MSVC reflective loader, not a Phorpiex downloader. ^[metadata.json]
  • GUI subsystem decoy: Declares Windows GUI with minimal USER32/GDI32 imports, but no window-creation logic in the entry path. The imports are scaffolding. ^[file.txt]

How To Mess With It (Homelab Replication)

See 136b5750 report — identical stub template. Reproduce the PEB-walker, XOR-NOT cipher, LCG PRNG, and CPUID anti-VM gate. Per-sample customization is limited to the encrypted .data payload blob.

Deployable Signatures

YARA Rule

rule blackmatter_a397bea4_msvc_pe32_reflective_loader
{
    meta:
        description = "MSVC 14.12 PE32 reflective loader twin (blackmatter OpenCTI label) with PEB-walking API resolution and XOR-NOT string crypto"
        author = "PacketPursuit"
        date = "2026-08-29"
        sha256 = "a397bea4c70bf3264348c88fca652fcbb2d421832672fa58a790af67bf419469"
    strings:
        $xor_not_key = { 81 31 FF 5F 03 10 }
        $lcg_mul = { 0D 66 19 00 00 }
        $lcg_inc = { 35 3C EF C6 03 }
        $lcg_mask = { 25 FF FF FF 07 }
        $alphabet_1 = { 41 BB BF EA }
        $alphabet_2 = { 45 E6 BB A7 }
        $post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + 0x18) == 0x10B and
        2 of ($xor_not_*) and
        2 of ($lcg_*) and
        2 of ($alphabet_*) and
        $post_wide
}

Behavioral Fingerprint

This binary presents a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by export hash, caching pointers in a .data pseudo-import table. It allocates RWX memory, maps a decrypted payload, and spawns parallel threads for file-system enumeration (FindFirstFile with "*" wildcard) and HTTP POST C2 communication. The POST body is encrypted; C2 domain and User-Agent are generated at runtime via a seeded LCG PRNG indexing a base-62 alphabet table. VM execution triggers altered paths via CPUID hypervisor-bit checks and RDTSC timing gates.

IOCs

Indicator Value Notes
SHA-256 a397bea4c70bf3264348c88fca652fcbb2d421832672fa58a790af67bf419469 This sample (25th sibling)
SHA-256 (primary twin) 136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51 Primary analysis
Compilation Sep 9 2022 01:27:01 UTC Timestamp 0x631A9665 (shared across cluster)
Linker 14.12 VS 2017 15.5+
PE checksum 0x31603 Unique per sibling
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 Majority group stub hash
.data SHA-256 5271c3df93d4a765cb4e050926b9f43160726830591f30b93e530440b5368397 Individualized payload
XOR Key 0x10035fff String + pointer encryption
LCG multiplier 0x19660d PRNG constant
LCG increment 0x3c6ef35f PRNG constant

Detection Signatures

ATT&CK Technique Implementation
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18])
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling

References

  • OpenCTI artifact: 3954b7ef-c9c5-45bc-8a56-a29a8e36584b, labels: blackmatter, dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
  • Primary analysis (confirmed twin): /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Related entity pages: blackmatter, unattributed, phorpiex
  • Technique page: peb-walking-api-resolution

Provenance

Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt, strings.txt, floss.txt, capa.txt, binwalk.txt, dynamic-analysis.md) and radare2 decompilation (analysis level 3) of the binary at <sample a397bea4c70b.bin>. CAPA failed due to missing signature database. floss failed due to CLI invocation error. CAPE dynamic analysis skipped — no Windows guest available. Behavioral claims are statically inferred from the confirmed-twin 136b5750 report and radare2 decompilation of this sample.