c65fd4c218ee4f11072c79af6e6663c9694cf746fae75641b6b75db0ce7d555cchromeloader-pulsar-rat: c65fd4c2 — Pulsar v1.6.6.0 with defendnot+R77 rootkit stager, Lulsec Roblox masquerade
Executive Summary
.NET Framework RAT/infostealer belonging to the chromeloader-pulsar-rat cluster, upgraded to Pulsar.Client v1.6.6.0 (prior siblings were v2.4.5.0). Distributed as Lulsec_Roblox_v1.0.0.5limitedbeta.exe — a game-hack social-engineering lure. Embeds a ZIP archive containing the open-source defendnot Windows Defender disabler (x64 PE + DLL) and an R77 rootkit stager. No packing, no obfuscation; CIL namespaces are fully readable. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | c65fd4c218ee4f11072c79af6e6663c9694cf746fae75641b6b75db0ce7d555c |
| Filename | Lulsec_Roblox_v1.0.0.5limitedbeta.exe |
| Size | 3.19 MB (3,191,808 bytes) |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Framework | .NET Framework v4.7.2 ^[strings.txt:9230] |
| Compiler | IL-only C#; no native compilation |
| Timestamp | 0xF37D8067 → Sun Jun 14 02:45:59 2099 UTC (fabricated) ^[pefile.txt:34] |
| Linker | MajorLinkerVersion 0x30 (48.0) / rabin2 reports LinkerVersion 48.0 ^[rabin2-info.txt:12] ^[exiftool.json:18] |
| Signed | No ^[rabin2-info.txt:27] |
| Obfuscation | None — unobfuscated CIL; all type/method names readable |
| Dependency embedding | Costura.Fody compresses DLLs into .rsrc ^[strings.txt:9067] ^[strings.txt:7154] |
Masquerade metadata: CompanyName "Lulsec Roblox", FileDescription "Lulsec Roblox script", LegalCopyright "Microsoft", ProductName "Lulsec", AssemblyVersion 1.0.1.5 ^[exiftool.json:37-46]. The fabricated timestamp and game-hack filename indicate intentional targeting of Roblox players seeking cheats/exploits.
How It Works
Outer PE — Pulsar.Client v1.6.6.0
The outer .NET PE is the Pulsar RAT client framework rebuilt at v1.6.6.0 (prior corpus siblings 94682a96 and ca687401 carried v2.4.5.0). Key dependency change: protobuf-net upgraded from v2.x → v3.0.0.0 / protobuf-net.Core v3.0.0.0 ^[strings.txt:3743-3744], replacing the older MessagePack-only serializer observed in earlier siblings. Pulsar.Common.dll embedded at v1.6.6.0 ^[strings.txt:3762].
Costura.Fody dependency list (compressed in .rsrc):
AForge/AForge.Video/AForge.Video.DirectShow— webcam captureGma.System.MouseKeyHookv5.7.1.0 — global input hooksNAudio.Core/Wasapi/WinMM/WinFormsv2.2.1.0 — audio captureprotobuf-net/protobuf-net.Corev3.0.0.0 — C2 serializationSharpDX/Direct3D11/Direct2D1/DXGI/Mathematicsv4.2.0.0 — GDI/desktop effectsSystem.Collections.Immutablev7.0.0.0,System.Memoryv4.0.1.2,System.Numerics.Vectorsv4.1.4.0,System.Runtime.CompilerServices.Unsafev6.0.3.0 — modern .NET runtime depsPulsar.Common.dllv1.6.6.0 — core RAT framework ^[strings.txt:3735-3762]
Embedded ZIP Payload — defendnot + R77 Rootkit
At raw offset 0x5D378 (decimal 381,816) a ZIP archive is embedded in the .text section entropy blob. Extracted contents ^[binwalk.txt:6-8]:
| File | Size | Type |
|---|---|---|
defendnot-loader.exe |
594,944 bytes | PE32+ executable (GUI) x86-64 |
defendnot.dll |
437,248 bytes | PE32+ executable (DLL) (console) x86-64 |
Both are x64, MSVC 14.44 linker, compiled 2025:11:23 18:08 UTC ^[embedded/defendnot-loader.exe exiftool]. defendnot-loader.exe is the open-source Defender disabler by es3n1n (github.com/es3n1n/defendnot) ^[embedded/defendnot-loader.exe strings]. It manipulates the Windows Security Center (WSC) service to disable real-time protection.
The outer PE also carries R77 rootkit constants: R77ServiceSignature, R77HelperSignature, R77Const, HidePrefix, ControlPipeName ^[strings.txt:56-57,167,172,50]. RootkitStager and Rootkit class names confirm the R77 (Bytecode-77) ring-3 rootkit integration ^[strings.txt:7834,8573]. InjectDll, UnhookDll, NtCreateThreadEx, VirtualAllocEx, WriteProcessMemory in the outer PE provide the injection primitives for R77 deployment ^[strings.txt:91,90,171,170,180].
C2 and Communication
- Serialization: protobuf-net v3.0.0.0 (upgrade from MessagePack in prior siblings) ^[strings.txt:3743]
- Network: TCP sockets, HTTP client with User-Agent and proxy configuration ^[capa.txt]
- Named pipes:
ControlPipeNamefor local IPC ^[strings.txt:50] - Exfil: Discord, Telegram, FTP channels (inherited from Pulsar.Common framework)
No hardcoded C2 IPs/domains recovered statically — configuration is likely runtime-resolved or embedded in encrypted resources not recovered from this static pass.
Decompiled Behavior
Static-only; no Ghidra decompilation performed. The binary is unobfuscated .NET CIL — dnSpy/ILSpy would recover near-source-quality C#. All type/method names are present in plaintext metadata. Notable classes observed:
Pulsar.Client.Messages.RootkitHandler+<Execute>d__7— R77 rootkit deployment orchestrator ^[strings.txt:9255]Pulsar.Client.Messages.WindowsDefenderDisableHandler+<Execute>d__5— Defender disable via defendnot ^[strings.txt:9256]Pulsar.Client.FunnyFeatures.DisableDefender+<TryDisableDefender>d__0— alternate Defender disable path ^[strings.txt:9267]Pulsar.Client.Helper.HVNC.Chromium.OperaPatcher— HVNC browser patching for credential access ^[strings.txt:9262]Pulsar.Client.GDIEffects.Illuminati,ScreenCorruption,EffectTemplate— prank/visual payload effects ^[strings.txt:9264-9266]
C2 Infrastructure
No static C2 indicators recovered. The Pulsar framework typically retrieves C2 config at runtime from encrypted embedded resources or registry. Based on sibling behavior and capa matches, expect:
- TCP C2 with protobuf-net serialization framing
- HTTP fallback with configurable User-Agent and proxy
- Named-pipe local IPC before external C2 establishment
Interesting Tidbits
- Version bump: This sample upgrades Pulsar.Client from v2.4.5.0 (siblings
94682a96,ca687401) to v1.6.6.0. The version numbering reversed (2.4.5 → 1.6.6) suggests a fork, rebrand, or parallel development branch. - protobuf-net 3.0: First observed Pulsar sibling using protobuf-net v3 (prior siblings used v2.x). Wire-format compatibility with v2 is maintained but the serializer internals changed significantly.
- Game-hack lure: "Lulsec Roblox" masquerade targets a younger demographic (Roblox players) rather than the business-document lures typical of prior Pulsar siblings. This may reflect a distributor-level decision, not a builder change.
- defendnot integration: Unlike prior siblings that relied on generic AMSI bypasses, this sample bundles the dedicated open-source Defender disabler, indicating increased sophistication in defense-evasion.
- R77 rootkit: The R77 (Bytecode-77) ring-3 rootkit provides process/file/registry hiding via API hooking. Presence of
HidePrefixsuggests files/pipes prefixed with a magic string are hidden from Explorer, Task Manager, anddir. - No obfuscation: Despite embedding high-sensitivity components (rootkit + AV killer), the outer PE is completely unobfuscated. This is consistent with the Pulsar builder model — the builder produces unobfuscated clients and relies on the distributor to wrap/Stage them.
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2022, .NET Framework 4.7.2 target, C# Windows Forms or console app.
Key libraries to reproduce the capa fingerprint:
- Add NuGet packages:
protobuf-netv3.0.0,NAudiov2.2.1,AForge.Videov2.2.5,SharpDXv4.2.0,Gma.System.MouseKeyHookv5.7.1 - Use Costura.Fody to embed dependencies as compressed
.rsrcblobs - Include P/Invoke declarations for
VirtualAllocEx,WriteProcessMemory,NtCreateThreadEx,CreateRemoteThread - Add registry query code for
HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum(VM detection) - Add
CheckRemoteDebuggerPresent,NtQueryInformationProcessanti-debug
Verification: Run capa <reproducer.exe> — should hit communication/tcp, host-interaction/process/inject, host-interaction/registry, anti-analysis/anti-vm, and collection/screenshot.
Deployable Signatures
YARA Rule
rule PulsarRAT_v166_defendnot_R77
{
meta:
description = "Pulsar RAT v1.6.6.0 with defendnot and R77 rootkit indicators"
author = "PacketPursuit"
date = "2026-07-27"
sha256 = "c65fd4c218ee4f11072c79af6e6663c9694cf746fae75641b6b75db0ce7d555c"
family = "chromeloader-pulsar-rat"
strings:
$pulsar_client = "Pulsar.Client" ascii wide
$pulsar_common = "Pulsar.Common, Version=1.6.6.0" ascii wide
$defendnot = "defendnot-loader.exe" ascii wide
$defendnot_dll = "defendnot.dll" ascii wide
$r77_svc = "R77ServiceSignature" ascii wide
$r77_helper = "R77HelperSignature" ascii wide
$hide_prefix = "HidePrefix" ascii wide
$control_pipe = "ControlPipeName" ascii wide
$rootkit_stager = "RootkitStager" ascii wide
$protobuf3 = "protobuf-net, Version=3.0.0.0" ascii wide
$costura = "costura.pulsar.common.dll.compressed" ascii wide
condition:
uint16(0) == 0x5A4D and
($pulsar_client or $pulsar_common) and
($defendnot or $defendnot_dll) and
($r77_svc or $r77_helper or $hide_prefix or $control_pipe or $rootkit_stager) and
filesize > 2MB
}
Behavioral Hunt Query (KQL)
// Pulsar v1.6.6.0 behavioral fingerprint: process creation of defendnot-loader.exe from
// a parent .NET PE with Pulsar namespaces, followed by WSC service manipulation
DeviceProcessEvents
| where InitiatingProcessFileName endswith ".exe"
| where FileName =~ "defendnot-loader.exe" or FileName =~ "defendnot.dll"
| join kind=inner (DeviceFileEvents
| where FileName =~ "defendnot-loader.exe" or FileName =~ "defendnot.dll"
| where FolderPath contains "AppData\\Local\\Temp" or FolderPath contains "AppData\\Roaming"
) on DeviceId, Timestamp
| project Timestamp, DeviceName, InitiatingProcessFileName, FileName, FolderPath, AccountName
IOC List
| Type | Indicator |
|---|---|
| SHA-256 | c65fd4c218ee4f11072c79af6e6663c9694cf746fae75641b6b75db0ce7d555c |
| SHA-256 (embedded) | defendnot-loader.exe (extracted from offset 0x5D378) |
| SHA-256 (embedded) | defendnot.dll (extracted from offset 0x5D378) |
| Filename | Lulsec_Roblox_v1.0.0.5limitedbeta.exe |
| Mutex/Named Pipe | ControlPipeName (runtime-resolved) |
| Registry | HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum (VM detection) |
| File attribute | Files prefixed with HidePrefix value hidden by R77 rootkit |
| Version | Pulsar.Common, Version=1.6.6.0 |
| Version | Pulsar.Client, Version=1.6.6.0 |
Behavioral Fingerprint Statement
This .NET Framework 4.7.2 PE loads a rich dependency surface via Costura.Fody (AForge webcam, NAudio audio, SharpDX GDI, protobuf-net v3 TCP serialization, Gma.System.MouseKeyHook global hooks). It queries the registry for VM disk enum strings, checks for debuggers via CheckRemoteDebuggerPresent and NtQueryInformationProcess, and extracts a ZIP payload from its own .text section containing x64 defendnot-loader.exe and defendnot.dll (Defender disablers) plus an R77 rootkit stager. The R77 rootkit hides processes, files, and registry keys matching a configurable HidePrefix. C2 communication uses protobuf-net v3 over TCP with optional HTTP proxy fallback.
Detection Signatures (capa → ATT&CK)
| capa Capability | ATT&CK Mapping |
|---|---|
| check for time delay in .NET | T1497.001 |
| check ProcessDebugFlags / ProcessDebugPort | T1622 |
| hide thread from debugger | T1622 |
| reference anti-VM strings (Qemu, VBox, Xen) | T1497 |
| capture screenshot | T1113 |
| log keystrokes | T1056.001 |
| receive/send data (TCP) | T1071 |
| set HTTP User-Agent / web proxy | T1071 |
| create HTTP request / receive HTTP response | T1071 |
| decode Base64 | T1140 |
| encrypt/decrypt via BCrypt / AES / DPAPI | T1573 |
| load .NET assembly / invoke .NET method | T1620 |
| create process suspended | C0017.003 |
| inject thread | T1055.003 |
| allocate RWX memory | T1055 |
| query registry key/value | T1012 |
| set registry value | T1112 |
| enumerate processes | T1057 |
| create mutex | T1078 |
| access WMI | T1047 |
| check clipboard / monitor clipboard | T1115 |
| change wallpaper | T1491 |
| swap mouse buttons | — |
References
- Artifact ID:
be6b5b8e-822f-4660-9e01-02981bde7a38 - Source: OpenCTI / MalwareBazaar
- Family entity: chromeloader-pulsar-rat
- Prior sibling:
/intel/analyses/94682a961e8a61b5a4b34e689de98f0a89b5e8c75bdfc493ed796c29a6b03536.html - Twin sibling:
ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7 - Cluster sibling:
ed94635a2348ca2ef5cd9a5c8f5c7e7a8e5b2d2c1f0a9e8b7c6d5e4f3a2b1c0d(containsPulsarMessagePackSerializer) - defendnot: https://github.com/es3n1n/defendnot
- R77 rootkit: Bytecode-77 ring-3 rootkit (open-source)
Provenance
file.txt— file(1) outputexiftool.json— ExifTool 12.76 metadatapefile.txt— pefile 2023.x DOS/NT header dumpstrings.txt— strings(1) extractionbinwalk.txt— binwalk 2.3.4 embedded artefact scanrabin2-info.txt— radare2 binary header summarycapa.txt— Mandiant capa static analysis (dotnet profile)embedded/defendnot-loader.exe— extracted x64 PE from ZIP at offset 0x5D378embedded/defendnot.dll— extracted x64 DLL from ZIP at offset 0x5D378dynamic-analysis.md— CAPE skipped (no Windows guest)