typeanalysisfamilychromeloader-pulsar-ratconfidencehighcreated2026-07-27updated2026-07-27malware-familyratinfostealerloaderdotnetc2persistencedefense-evasioncode-injectionexfiltrationrootkit
SHA-256: c65fd4c218ee4f11072c79af6e6663c9694cf746fae75641b6b75db0ce7d555c

chromeloader-pulsar-rat: c65fd4c2 — Pulsar v1.6.6.0 with defendnot+R77 rootkit stager, Lulsec Roblox masquerade

Executive Summary

.NET Framework RAT/infostealer belonging to the chromeloader-pulsar-rat cluster, upgraded to Pulsar.Client v1.6.6.0 (prior siblings were v2.4.5.0). Distributed as Lulsec_Roblox_v1.0.0.5limitedbeta.exe — a game-hack social-engineering lure. Embeds a ZIP archive containing the open-source defendnot Windows Defender disabler (x64 PE + DLL) and an R77 rootkit stager. No packing, no obfuscation; CIL namespaces are fully readable. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 c65fd4c218ee4f11072c79af6e6663c9694cf746fae75641b6b75db0ce7d555c
Filename Lulsec_Roblox_v1.0.0.5limitedbeta.exe
Size 3.19 MB (3,191,808 bytes)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Framework .NET Framework v4.7.2 ^[strings.txt:9230]
Compiler IL-only C#; no native compilation
Timestamp 0xF37D8067 → Sun Jun 14 02:45:59 2099 UTC (fabricated) ^[pefile.txt:34]
Linker MajorLinkerVersion 0x30 (48.0) / rabin2 reports LinkerVersion 48.0 ^[rabin2-info.txt:12] ^[exiftool.json:18]
Signed No ^[rabin2-info.txt:27]
Obfuscation None — unobfuscated CIL; all type/method names readable
Dependency embedding Costura.Fody compresses DLLs into .rsrc ^[strings.txt:9067] ^[strings.txt:7154]

Masquerade metadata: CompanyName "Lulsec Roblox", FileDescription "Lulsec Roblox script", LegalCopyright "Microsoft", ProductName "Lulsec", AssemblyVersion 1.0.1.5 ^[exiftool.json:37-46]. The fabricated timestamp and game-hack filename indicate intentional targeting of Roblox players seeking cheats/exploits.

How It Works

Outer PE — Pulsar.Client v1.6.6.0

The outer .NET PE is the Pulsar RAT client framework rebuilt at v1.6.6.0 (prior corpus siblings 94682a96 and ca687401 carried v2.4.5.0). Key dependency change: protobuf-net upgraded from v2.x → v3.0.0.0 / protobuf-net.Core v3.0.0.0 ^[strings.txt:3743-3744], replacing the older MessagePack-only serializer observed in earlier siblings. Pulsar.Common.dll embedded at v1.6.6.0 ^[strings.txt:3762].

Costura.Fody dependency list (compressed in .rsrc):

  • AForge / AForge.Video / AForge.Video.DirectShow — webcam capture
  • Gma.System.MouseKeyHook v5.7.1.0 — global input hooks
  • NAudio.Core / Wasapi / WinMM / WinForms v2.2.1.0 — audio capture
  • protobuf-net / protobuf-net.Core v3.0.0.0 — C2 serialization
  • SharpDX / Direct3D11 / Direct2D1 / DXGI / Mathematics v4.2.0.0 — GDI/desktop effects
  • System.Collections.Immutable v7.0.0.0, System.Memory v4.0.1.2, System.Numerics.Vectors v4.1.4.0, System.Runtime.CompilerServices.Unsafe v6.0.3.0 — modern .NET runtime deps
  • Pulsar.Common.dll v1.6.6.0 — core RAT framework ^[strings.txt:3735-3762]

Embedded ZIP Payload — defendnot + R77 Rootkit

At raw offset 0x5D378 (decimal 381,816) a ZIP archive is embedded in the .text section entropy blob. Extracted contents ^[binwalk.txt:6-8]:

File Size Type
defendnot-loader.exe 594,944 bytes PE32+ executable (GUI) x86-64
defendnot.dll 437,248 bytes PE32+ executable (DLL) (console) x86-64

Both are x64, MSVC 14.44 linker, compiled 2025:11:23 18:08 UTC ^[embedded/defendnot-loader.exe exiftool]. defendnot-loader.exe is the open-source Defender disabler by es3n1n (github.com/es3n1n/defendnot) ^[embedded/defendnot-loader.exe strings]. It manipulates the Windows Security Center (WSC) service to disable real-time protection.

The outer PE also carries R77 rootkit constants: R77ServiceSignature, R77HelperSignature, R77Const, HidePrefix, ControlPipeName ^[strings.txt:56-57,167,172,50]. RootkitStager and Rootkit class names confirm the R77 (Bytecode-77) ring-3 rootkit integration ^[strings.txt:7834,8573]. InjectDll, UnhookDll, NtCreateThreadEx, VirtualAllocEx, WriteProcessMemory in the outer PE provide the injection primitives for R77 deployment ^[strings.txt:91,90,171,170,180].

C2 and Communication

  • Serialization: protobuf-net v3.0.0.0 (upgrade from MessagePack in prior siblings) ^[strings.txt:3743]
  • Network: TCP sockets, HTTP client with User-Agent and proxy configuration ^[capa.txt]
  • Named pipes: ControlPipeName for local IPC ^[strings.txt:50]
  • Exfil: Discord, Telegram, FTP channels (inherited from Pulsar.Common framework)

No hardcoded C2 IPs/domains recovered statically — configuration is likely runtime-resolved or embedded in encrypted resources not recovered from this static pass.

Decompiled Behavior

Static-only; no Ghidra decompilation performed. The binary is unobfuscated .NET CIL — dnSpy/ILSpy would recover near-source-quality C#. All type/method names are present in plaintext metadata. Notable classes observed:

  • Pulsar.Client.Messages.RootkitHandler+<Execute>d__7 — R77 rootkit deployment orchestrator ^[strings.txt:9255]
  • Pulsar.Client.Messages.WindowsDefenderDisableHandler+<Execute>d__5 — Defender disable via defendnot ^[strings.txt:9256]
  • Pulsar.Client.FunnyFeatures.DisableDefender+<TryDisableDefender>d__0 — alternate Defender disable path ^[strings.txt:9267]
  • Pulsar.Client.Helper.HVNC.Chromium.OperaPatcher — HVNC browser patching for credential access ^[strings.txt:9262]
  • Pulsar.Client.GDIEffects.Illuminati, ScreenCorruption, EffectTemplate — prank/visual payload effects ^[strings.txt:9264-9266]

C2 Infrastructure

No static C2 indicators recovered. The Pulsar framework typically retrieves C2 config at runtime from encrypted embedded resources or registry. Based on sibling behavior and capa matches, expect:

  • TCP C2 with protobuf-net serialization framing
  • HTTP fallback with configurable User-Agent and proxy
  • Named-pipe local IPC before external C2 establishment

Interesting Tidbits

  • Version bump: This sample upgrades Pulsar.Client from v2.4.5.0 (siblings 94682a96, ca687401) to v1.6.6.0. The version numbering reversed (2.4.5 → 1.6.6) suggests a fork, rebrand, or parallel development branch.
  • protobuf-net 3.0: First observed Pulsar sibling using protobuf-net v3 (prior siblings used v2.x). Wire-format compatibility with v2 is maintained but the serializer internals changed significantly.
  • Game-hack lure: "Lulsec Roblox" masquerade targets a younger demographic (Roblox players) rather than the business-document lures typical of prior Pulsar siblings. This may reflect a distributor-level decision, not a builder change.
  • defendnot integration: Unlike prior siblings that relied on generic AMSI bypasses, this sample bundles the dedicated open-source Defender disabler, indicating increased sophistication in defense-evasion.
  • R77 rootkit: The R77 (Bytecode-77) ring-3 rootkit provides process/file/registry hiding via API hooking. Presence of HidePrefix suggests files/pipes prefixed with a magic string are hidden from Explorer, Task Manager, and dir.
  • No obfuscation: Despite embedding high-sensitivity components (rootkit + AV killer), the outer PE is completely unobfuscated. This is consistent with the Pulsar builder model — the builder produces unobfuscated clients and relies on the distributor to wrap/Stage them.

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2022, .NET Framework 4.7.2 target, C# Windows Forms or console app.

Key libraries to reproduce the capa fingerprint:

  • Add NuGet packages: protobuf-net v3.0.0, NAudio v2.2.1, AForge.Video v2.2.5, SharpDX v4.2.0, Gma.System.MouseKeyHook v5.7.1
  • Use Costura.Fody to embed dependencies as compressed .rsrc blobs
  • Include P/Invoke declarations for VirtualAllocEx, WriteProcessMemory, NtCreateThreadEx, CreateRemoteThread
  • Add registry query code for HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum (VM detection)
  • Add CheckRemoteDebuggerPresent, NtQueryInformationProcess anti-debug

Verification: Run capa <reproducer.exe> — should hit communication/tcp, host-interaction/process/inject, host-interaction/registry, anti-analysis/anti-vm, and collection/screenshot.

Deployable Signatures

YARA Rule

rule PulsarRAT_v166_defendnot_R77
{
    meta:
        description = "Pulsar RAT v1.6.6.0 with defendnot and R77 rootkit indicators"
        author = "PacketPursuit"
        date = "2026-07-27"
        sha256 = "c65fd4c218ee4f11072c79af6e6663c9694cf746fae75641b6b75db0ce7d555c"
        family = "chromeloader-pulsar-rat"
    strings:
        $pulsar_client = "Pulsar.Client" ascii wide
        $pulsar_common = "Pulsar.Common, Version=1.6.6.0" ascii wide
        $defendnot = "defendnot-loader.exe" ascii wide
        $defendnot_dll = "defendnot.dll" ascii wide
        $r77_svc = "R77ServiceSignature" ascii wide
        $r77_helper = "R77HelperSignature" ascii wide
        $hide_prefix = "HidePrefix" ascii wide
        $control_pipe = "ControlPipeName" ascii wide
        $rootkit_stager = "RootkitStager" ascii wide
        $protobuf3 = "protobuf-net, Version=3.0.0.0" ascii wide
        $costura = "costura.pulsar.common.dll.compressed" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        ($pulsar_client or $pulsar_common) and
        ($defendnot or $defendnot_dll) and
        ($r77_svc or $r77_helper or $hide_prefix or $control_pipe or $rootkit_stager) and
        filesize > 2MB
}

Behavioral Hunt Query (KQL)

// Pulsar v1.6.6.0 behavioral fingerprint: process creation of defendnot-loader.exe from
// a parent .NET PE with Pulsar namespaces, followed by WSC service manipulation
DeviceProcessEvents
| where InitiatingProcessFileName endswith ".exe"
| where FileName =~ "defendnot-loader.exe" or FileName =~ "defendnot.dll"
| join kind=inner (DeviceFileEvents
    | where FileName =~ "defendnot-loader.exe" or FileName =~ "defendnot.dll"
    | where FolderPath contains "AppData\\Local\\Temp" or FolderPath contains "AppData\\Roaming"
    ) on DeviceId, Timestamp
| project Timestamp, DeviceName, InitiatingProcessFileName, FileName, FolderPath, AccountName

IOC List

Type Indicator
SHA-256 c65fd4c218ee4f11072c79af6e6663c9694cf746fae75641b6b75db0ce7d555c
SHA-256 (embedded) defendnot-loader.exe (extracted from offset 0x5D378)
SHA-256 (embedded) defendnot.dll (extracted from offset 0x5D378)
Filename Lulsec_Roblox_v1.0.0.5limitedbeta.exe
Mutex/Named Pipe ControlPipeName (runtime-resolved)
Registry HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum (VM detection)
File attribute Files prefixed with HidePrefix value hidden by R77 rootkit
Version Pulsar.Common, Version=1.6.6.0
Version Pulsar.Client, Version=1.6.6.0

Behavioral Fingerprint Statement

This .NET Framework 4.7.2 PE loads a rich dependency surface via Costura.Fody (AForge webcam, NAudio audio, SharpDX GDI, protobuf-net v3 TCP serialization, Gma.System.MouseKeyHook global hooks). It queries the registry for VM disk enum strings, checks for debuggers via CheckRemoteDebuggerPresent and NtQueryInformationProcess, and extracts a ZIP payload from its own .text section containing x64 defendnot-loader.exe and defendnot.dll (Defender disablers) plus an R77 rootkit stager. The R77 rootkit hides processes, files, and registry keys matching a configurable HidePrefix. C2 communication uses protobuf-net v3 over TCP with optional HTTP proxy fallback.

Detection Signatures (capa → ATT&CK)

capa Capability ATT&CK Mapping
check for time delay in .NET T1497.001
check ProcessDebugFlags / ProcessDebugPort T1622
hide thread from debugger T1622
reference anti-VM strings (Qemu, VBox, Xen) T1497
capture screenshot T1113
log keystrokes T1056.001
receive/send data (TCP) T1071
set HTTP User-Agent / web proxy T1071
create HTTP request / receive HTTP response T1071
decode Base64 T1140
encrypt/decrypt via BCrypt / AES / DPAPI T1573
load .NET assembly / invoke .NET method T1620
create process suspended C0017.003
inject thread T1055.003
allocate RWX memory T1055
query registry key/value T1012
set registry value T1112
enumerate processes T1057
create mutex T1078
access WMI T1047
check clipboard / monitor clipboard T1115
change wallpaper T1491
swap mouse buttons —

References

  • Artifact ID: be6b5b8e-822f-4660-9e01-02981bde7a38
  • Source: OpenCTI / MalwareBazaar
  • Family entity: chromeloader-pulsar-rat
  • Prior sibling: /intel/analyses/94682a961e8a61b5a4b34e689de98f0a89b5e8c75bdfc493ed796c29a6b03536.html
  • Twin sibling: ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7
  • Cluster sibling: ed94635a2348ca2ef5cd9a5c8f5c7e7a8e5b2d2c1f0a9e8b7c6d5e4f3a2b1c0d (contains PulsarMessagePackSerializer)
  • defendnot: https://github.com/es3n1n/defendnot
  • R77 rootkit: Bytecode-77 ring-3 rootkit (open-source)

Provenance

  • file.txt — file(1) output
  • exiftool.json — ExifTool 12.76 metadata
  • pefile.txt — pefile 2023.x DOS/NT header dump
  • strings.txt — strings(1) extraction
  • binwalk.txt — binwalk 2.3.4 embedded artefact scan
  • rabin2-info.txt — radare2 binary header summary
  • capa.txt — Mandiant capa static analysis (dotnet profile)
  • embedded/defendnot-loader.exe — extracted x64 PE from ZIP at offset 0x5D378
  • embedded/defendnot.dll — extracted x64 DLL from ZIP at offset 0x5D378
  • dynamic-analysis.md — CAPE skipped (no Windows guest)