typeanalysisfamilyblackmatterconfidencehighcreated2026-09-04updated2026-09-04pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: bc93fb67cf4dba8c35e91b551ca3190db25ffa4a36f821bc5a6b900927470fb9

blackmatter: bc93fb67 — 42nd confirmed sibling, MSVC 14.12 PE32 GUI reflective-loader

Executive Summary

The 42nd confirmed sibling in the MSVC 14.12 PE32 GUI reflective-loader cluster (Sep 2022). Tagged blackmatter and dropped-by-phorpiex by OpenCTI. All build artefacts, anti-analysis patterns, and capability signatures match the majority group template established by sibling 136b5750. The .text section hash is identical to the cluster majority; the .data payload is individualized (SHA-256 8c53c2db...). Static-only analysis — CAPE skipped due to no Windows guest. For full behavioral analysis see the cluster entity pages blackmatter and unattributed.

What It Is

Field Value
SHA-256 bc93fb67cf4dba8c35e91b551ca3190db25ffa4a36f821bc5a6b900927470fb9
Size 149,504 bytes (150 KB) ^[file.txt]
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[exiftool.json:18] ^[pefile.txt:46]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP / Canary All enabled ^[pefile.txt:74] ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Static imports Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt:249]
YARA Generic PE only; no family-specific hits ^[yara.txt]
PE checksum 0x28702 ^[pefile.txt:65]
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 — matches cluster majority group ^[pefile.txt:93]
.data payload SHA-256 8c53c2db6af71913c7710cf6ca463a15a806b5eaeb123e56ba6e34438c779da6 — individualized ^[pefile.txt:155]

How It Works

This sample is a cluster twin — it shares the identical stub template with all prior siblings. The build timestamp, linker version, section layout (.text, .itext, .rdata, .data, .pdata, .reloc), entry-point RVA (0x1946F), and every anti-analysis / API-resolution pattern are byte-for-byte consistent with the majority group. For the full behavioral breakdown (PEB-walking, XOR-NOT alphabet cipher, LCG PRNG, CPUID anti-VM, RDTSC timing gate, reflective loader, HTTP POST C2, file-system enumeration) see the primary cluster analysis on unattributed and the entity page blackmatter.

Deltas from the cluster template

  • PE checksum: 0x28702 — unique per-sample, consistent with individualized .data payload. No other structural divergence observed. ^[pefile.txt:65]
  • .data payload: SHA-256 8c53c2db... differs from every prior sibling, confirming the builder injects a per-sample encrypted payload into the shared stub. ^[pefile.txt:155]
  • OpenCTI labels: Both blackmatter and dropped-by-phorpiex tags present. ^[metadata.json] ^[triage.json]

Decompiled Behavior

Radare2 analysis (level 3) recovered 519 functions. The entry-point orchestrator at fcn.00417034, decrypt stub at fcn.00401240, LCG PRNG at fcn.0040110c, anti-VM gate at fcn.004010bc, and alphabet builder at fcn.0040d4b0 are structurally identical to sibling 136b5750. No new functions or control-flow divergences were detected. ^[r2:fcn.00417034] ^[r2:fcn.00401240] ^[r2:fcn.0040110c] ^[r2:fcn.004010bc] ^[r2:fcn.0040d4b0]

C2 Infrastructure

No hard-coded C2 endpoints survive in the binary. Domain, path, and User-Agent are generated at runtime via the LCG PRNG + base-62 alphabet table, identical to all prior siblings. Static inference only — see unattributed for the full C2 construction analysis.

Interesting Tidbits

  • capa failure: capa failed with a missing signature database error (Using default signature path, but it doesn't exist). This is an environment issue, not a binary issue. ^[capa.txt]
  • floss failure: floss was invoked with an incorrect CLI argument (--no without a valid choice), producing no decoded strings. The XOR-NOT cipher evades standard string extraction anyway. ^[floss.txt]
  • CAPE skipped: No Windows guest available; all behavioral claims are statically inferred. ^[dynamic-analysis.md]
  • POGO optimization: IMAGE_DEBUG_TYPE_POGO present — same as all siblings, suggesting the builder compiles with Profile-Guided Optimization enabled. ^[pefile.txt:313]

How To Mess With It (Homelab Replication)

See the primary cluster analysis on unattributed for the full reproduction guide (PEB-walking stub, XOR-NOT alphabet cipher, LCG PRNG, CPUID anti-VM gate). This sample adds no new techniques to replicate.

Deployable Signatures

YARA Rule

rule blackmatter_cluster_bc93fb67_pe32_xor_not_loader
{
    meta:
        description = "PE32 MSVC 14.12 reflective loader with XOR-NOT string crypto and PEB-walking API resolution — blackmatter cluster sibling"
        author = "PacketPursuit"
        date = "2026-09-04"
        sha256 = "bc93fb67cf4dba8c35e91b551ca3190db25ffa4a36f821bc5a6b900927470fb9"
    strings:
        $xor_not_key = { 3D FF 5F 03 10 }
        $xor_not_op = { 81 31 FF 5F 03 10 }
        $lcg_mul = { 0D 66 19 00 00 }
        $lcg_inc = { 35 3C EF C6 03 }
        $lcg_mask = { 25 FF FF FF 07 }
        $alphabet_1 = { 41 BB BF EA }
        $alphabet_2 = { 45 E6 BB A7 }
        $alphabet_3 = { 49 EA B7 A3 }
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + 0x18) == 0x10B and
        3 of ($xor_not_*) and
        2 of ($lcg_*) and
        2 of ($alphabet_*)
}

Behavioral Fingerprint

This binary loads with a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within the first 5 seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by hash. It allocates RWX memory, copies a decrypted payload into it, and spawns a file-system enumeration thread (FindFirstFile with "*" wildcard) alongside a network thread that assembles an HTTP POST request. The POST body is encrypted with a session key imported via CryptImportKey. C2 domain and User-Agent are generated at runtime using a seeded LCG PRNG and a base-62 alphabet table. If executed inside a VM, CPUID leaf 1 ECX[31] or leaf 7 EBX[18] hypervisor bits cause altered code paths or early termination. This specific sample (SHA-256 bc93fb67...) carries an individualized .data payload (SHA-256 8c53c2db...) and PE checksum 0x28702, but is otherwise structurally identical to the cluster majority template.

IOCs

Indicator Value Notes
SHA-256 bc93fb67cf4dba8c35e91b551ca3190db25ffa4a36f821bc5a6b900927470fb9 Primary
SHA-1 (.text) 5d12d573caddd78d39ef56deaf9afe44636ae19b .text section, matches cluster majority
MD5 (.text) cfbda2c44e51b3b0b00bcbbc767c62a2 Cluster majority hash
MD5 (.data) 0bad3a92ef633037469cdb5e8e7d1bb6 Individualized payload
Compilation Sep 9 2022 01:27:01 UTC Timestamp 0x631A9665
Linker 14.12 VS 2017 15.5+
PE checksum 0x28702 Unique per sample
TLSH 4FE37D21B212D0B3C87718F13736B572F39E8E2C19996847EAD80F5DBCA58236F05997 Sample-specific
XOR Key 0x10035fff Cluster-wide constant
LCG multiplier 0x19660d Cluster-wide constant
LCG increment 0x3c6ef35f Cluster-wide constant
Anti-VM CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 Cluster-wide pattern
Pseudo-import region 0x425000–0x425fff (.data VA) Decrypted at runtime

Detection Signatures

ATT&CK Technique Implementation
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation ^[r2:fcn.00406668]
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution ^[r2:fcn.0040cfcc]
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation ^[r2:fcn.00401240] ^[r2:fcn.0040d4b0]
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) ^[r2:fcn.004010bc]
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate ^[r2:fcn.004010bc]
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile ^[r2:fcn.00407468]
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body ^[r2:fcn.0040782c]
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling ^[r2:fcn.0040782c]

References

  • OpenCTI artifact: b654ad6b-956a-48f2-a7cd-04128e1fb7f4, labels: blackmatter, dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json] ^[triage.json]
  • Related cluster entity pages: blackmatter, unattributed
  • Technique page: peb-walking-api-resolution
  • Delivery infrastructure (not payload family): phorpiex

Provenance

Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt, strings.txt, binwalk.txt, capa.txt, floss.txt) and radare2 decompilation (analysis level 3) of the binary at <sample bc93fb67cf4d.bin>. CAPA and floss failed due to environment / CLI issues, not binary obfuscation. CAPE dynamic analysis skipped — no Windows guest available. All behavioral claims are statically inferred and trace to the cluster template established in sibling 136b5750.