bc93fb67cf4dba8c35e91b551ca3190db25ffa4a36f821bc5a6b900927470fb9blackmatter: bc93fb67 — 42nd confirmed sibling, MSVC 14.12 PE32 GUI reflective-loader
Executive Summary
The 42nd confirmed sibling in the MSVC 14.12 PE32 GUI reflective-loader cluster (Sep 2022). Tagged blackmatter and dropped-by-phorpiex by OpenCTI. All build artefacts, anti-analysis patterns, and capability signatures match the majority group template established by sibling 136b5750. The .text section hash is identical to the cluster majority; the .data payload is individualized (SHA-256 8c53c2db...). Static-only analysis — CAPE skipped due to no Windows guest. For full behavioral analysis see the cluster entity pages blackmatter and unattributed.
What It Is
| Field | Value |
|---|---|
| SHA-256 | bc93fb67cf4dba8c35e91b551ca3190db25ffa4a36f821bc5a6b900927470fb9 |
| Size | 149,504 bytes (150 KB) ^[file.txt] |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[exiftool.json:18] ^[pefile.txt:46] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP / Canary | All enabled ^[pefile.txt:74] ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Static imports | Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt:249] |
| YARA | Generic PE only; no family-specific hits ^[yara.txt] |
| PE checksum | 0x28702 ^[pefile.txt:65] |
.text MD5 |
cfbda2c44e51b3b0b00bcbbc767c62a2 — matches cluster majority group ^[pefile.txt:93] |
.data payload SHA-256 |
8c53c2db6af71913c7710cf6ca463a15a806b5eaeb123e56ba6e34438c779da6 — individualized ^[pefile.txt:155] |
How It Works
This sample is a cluster twin — it shares the identical stub template with all prior siblings. The build timestamp, linker version, section layout (.text, .itext, .rdata, .data, .pdata, .reloc), entry-point RVA (0x1946F), and every anti-analysis / API-resolution pattern are byte-for-byte consistent with the majority group. For the full behavioral breakdown (PEB-walking, XOR-NOT alphabet cipher, LCG PRNG, CPUID anti-VM, RDTSC timing gate, reflective loader, HTTP POST C2, file-system enumeration) see the primary cluster analysis on unattributed and the entity page blackmatter.
Deltas from the cluster template
- PE checksum:
0x28702— unique per-sample, consistent with individualized.datapayload. No other structural divergence observed. ^[pefile.txt:65] .datapayload: SHA-2568c53c2db...differs from every prior sibling, confirming the builder injects a per-sample encrypted payload into the shared stub. ^[pefile.txt:155]- OpenCTI labels: Both
blackmatteranddropped-by-phorpiextags present. ^[metadata.json] ^[triage.json]
Decompiled Behavior
Radare2 analysis (level 3) recovered 519 functions. The entry-point orchestrator at fcn.00417034, decrypt stub at fcn.00401240, LCG PRNG at fcn.0040110c, anti-VM gate at fcn.004010bc, and alphabet builder at fcn.0040d4b0 are structurally identical to sibling 136b5750. No new functions or control-flow divergences were detected. ^[r2:fcn.00417034] ^[r2:fcn.00401240] ^[r2:fcn.0040110c] ^[r2:fcn.004010bc] ^[r2:fcn.0040d4b0]
C2 Infrastructure
No hard-coded C2 endpoints survive in the binary. Domain, path, and User-Agent are generated at runtime via the LCG PRNG + base-62 alphabet table, identical to all prior siblings. Static inference only — see unattributed for the full C2 construction analysis.
Interesting Tidbits
- capa failure:
capafailed with a missing signature database error (Using default signature path, but it doesn't exist). This is an environment issue, not a binary issue. ^[capa.txt] - floss failure:
flosswas invoked with an incorrect CLI argument (--nowithout a valid choice), producing no decoded strings. The XOR-NOT cipher evades standard string extraction anyway. ^[floss.txt] - CAPE skipped: No Windows guest available; all behavioral claims are statically inferred. ^[dynamic-analysis.md]
- POGO optimization:
IMAGE_DEBUG_TYPE_POGOpresent — same as all siblings, suggesting the builder compiles with Profile-Guided Optimization enabled. ^[pefile.txt:313]
How To Mess With It (Homelab Replication)
See the primary cluster analysis on unattributed for the full reproduction guide (PEB-walking stub, XOR-NOT alphabet cipher, LCG PRNG, CPUID anti-VM gate). This sample adds no new techniques to replicate.
Deployable Signatures
YARA Rule
rule blackmatter_cluster_bc93fb67_pe32_xor_not_loader
{
meta:
description = "PE32 MSVC 14.12 reflective loader with XOR-NOT string crypto and PEB-walking API resolution — blackmatter cluster sibling"
author = "PacketPursuit"
date = "2026-09-04"
sha256 = "bc93fb67cf4dba8c35e91b551ca3190db25ffa4a36f821bc5a6b900927470fb9"
strings:
$xor_not_key = { 3D FF 5F 03 10 }
$xor_not_op = { 81 31 FF 5F 03 10 }
$lcg_mul = { 0D 66 19 00 00 }
$lcg_inc = { 35 3C EF C6 03 }
$lcg_mask = { 25 FF FF FF 07 }
$alphabet_1 = { 41 BB BF EA }
$alphabet_2 = { 45 E6 BB A7 }
$alphabet_3 = { 49 EA B7 A3 }
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C) + 0x18) == 0x10B and
3 of ($xor_not_*) and
2 of ($lcg_*) and
2 of ($alphabet_*)
}
Behavioral Fingerprint
This binary loads with a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within the first 5 seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve
VirtualAlloc,CreateThread,InternetOpen, and cryptographic APIs by hash. It allocates RWX memory, copies a decrypted payload into it, and spawns a file-system enumeration thread (FindFirstFilewith"*"wildcard) alongside a network thread that assembles an HTTP POST request. The POST body is encrypted with a session key imported viaCryptImportKey. C2 domain and User-Agent are generated at runtime using a seeded LCG PRNG and a base-62 alphabet table. If executed inside a VM, CPUID leaf 1 ECX[31] or leaf 7 EBX[18] hypervisor bits cause altered code paths or early termination. This specific sample (SHA-256bc93fb67...) carries an individualized.datapayload (SHA-2568c53c2db...) and PE checksum0x28702, but is otherwise structurally identical to the cluster majority template.
IOCs
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | bc93fb67cf4dba8c35e91b551ca3190db25ffa4a36f821bc5a6b900927470fb9 |
Primary |
SHA-1 (.text) |
5d12d573caddd78d39ef56deaf9afe44636ae19b |
.text section, matches cluster majority |
MD5 (.text) |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
Cluster majority hash |
MD5 (.data) |
0bad3a92ef633037469cdb5e8e7d1bb6 |
Individualized payload |
| Compilation | Sep 9 2022 01:27:01 UTC | Timestamp 0x631A9665 |
| Linker | 14.12 | VS 2017 15.5+ |
| PE checksum | 0x28702 |
Unique per sample |
| TLSH | 4FE37D21B212D0B3C87718F13736B572F39E8E2C19996847EAD80F5DBCA58236F05997 |
Sample-specific |
| XOR Key | 0x10035fff |
Cluster-wide constant |
| LCG multiplier | 0x19660d |
Cluster-wide constant |
| LCG increment | 0x3c6ef35f |
Cluster-wide constant |
| Anti-VM | CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 | Cluster-wide pattern |
| Pseudo-import region | 0x425000–0x425fff (.data VA) |
Decrypted at runtime |
Detection Signatures
| ATT&CK Technique | Implementation |
|---|---|
| T1055 — Process Injection | Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation ^[r2:fcn.00406668] |
| T1071.001 — Application Layer Protocol: Web Protocols | HTTP POST C2 with encrypted body; WinInet API resolution ^[r2:fcn.0040cfcc] |
| T1027 — Obfuscated Files or Information | XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation ^[r2:fcn.00401240] ^[r2:fcn.0040d4b0] |
| T1497.001 — Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) ^[r2:fcn.004010bc] |
| T1497.002 — Virtualization/Sandbox Evasion: User Activity Based | RDTSC differential timing gate ^[r2:fcn.004010bc] |
| T1083 — File and Directory Discovery | Recursive "*" enumeration via FindFirstFile / FindNextFile ^[r2:fcn.00407468] |
| T1573.001 — Encrypted Channel: Symmetric Cryptography | CryptEncrypt / CryptDecrypt for C2 payload body ^[r2:fcn.0040782c] |
| T1105 — Ingress Tool Transfer | Downloader / payload retrieval via HTTP POST response handling ^[r2:fcn.0040782c] |
References
- OpenCTI artifact:
b654ad6b-956a-48f2-a7cd-04128e1fb7f4, labels:blackmatter,dropped-by-phorpiex,exe,malware-bazaar^[metadata.json] ^[triage.json] - Related cluster entity pages: blackmatter, unattributed
- Technique page: peb-walking-api-resolution
- Delivery infrastructure (not payload family): phorpiex
Provenance
Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt, strings.txt, binwalk.txt, capa.txt, floss.txt) and radare2 decompilation (analysis level 3) of the binary at <sample bc93fb67cf4d.bin>. CAPA and floss failed due to environment / CLI issues, not binary obfuscation. CAPE dynamic analysis skipped — no Windows guest available. All behavioral claims are statically inferred and trace to the cluster template established in sibling 136b5750.