c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8ghostpulse: c88a5bba — DigiCert-signed YHClient x86 morph, cloud55filecc false-positive label
Executive Summary
A 6.6 MB 7-Zip SFX archive that silently extracts an x86 MSVC C++ payload (FrameworSwitch32.exe) to %TEMP% and executes it. The inner PE is DigiCert code-signed (CN=Hangzhou Shunwang Technology Co.,Ltd) and masquerades as a "YHClient" product with PDB paths referencing D:\slave\workspace\YHClient\Release\startbc.pdb. It is bundled with a custom Log.dll helper, legitimate MSVC redistributables, a 6.1 MB high-entropy encrypted sidecar (monitor.sym), and a 34 KB config file (sampler.xml). The OpenCTI cloud55filecc label is a false positive — static evidence resolves this sample to the ghostpulse family, specifically the x86 YHClient morph cluster first documented at 94db5892. No CAPE detonation available (no Windows guest); all behaviour inferred from static extraction and decompilation.
What It Is
- Outer container: 7-Zip SFX stub (
7ZSfxMod_x86.exe, Oleg Scherbakov, 2010), MSVC linker v8.0, compiled 2010-06-27 ^[file.txt] ^[exiftool.json] - Archive: LZMA-compressed 7z solid archive at offset
0x2df4f; 6 files extracted to%TEMP%^[binwalk.txt] - Inner payload:
FrameworSwitch32.exe— PE32 x86, MSVC 14.x (VS 2019+), timestamp0x6790d7cb(2025-01-22), 6 sections ^[rabin2-info.txt] - PDB path:
D:\slave\workspace\YHClient\Release\startbc.pdb— masquerades as a "YHClient" product build ^[rabin2-info.txt] ^[strings.txt] - Authenticode: Valid DigiCert code-signing certificate chain: leaf CN=
Hangzhou Shunwang Technology Co.,Ltd(CN), issued byDigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, valid 2023-03-24 through 2026-06-19, countersigned byDigiCert Timestamp 2024^[r2:iC] - Helper DLL:
Log.dll— PE32 x86, same toolchain/timestamp as inner payload, exportsGenericLogImpl,LogSetOption,LogSetOutputLevel^[strings Log.dll] - Sidecar files:
monitor.sym(6.1 MB, entropy 7.93, near-random — encrypted payload) andsampler.xml(34 KB, entropy 5.35 — likely config/key) ^[terminal:entropy-check] - Legitimate libraries:
msvcp_win.dllanducrtbase.dll— standard MSVC 2019+ redistributables - Family resolution: OpenCTI label
cloud55fileccis contested. The sample shares no Go build fingerprint, no ACR certificate chain, and no Lumma/ACR randomized-function-name pattern. All static indicators (SFX packaging, YHClient masquerade,Log.dll,monitor.sym/sampler.xmlsidecars, cmd.exe pipe execution) align with the ghostpulse x86 YHClient morph cluster. ^[entities/cloud55filecc.md] ^[entities/ghostpulse.md]
How It Works
Stage 1 — SFX Extraction
The outer binary is a legitimate 7-Zip SFX mod configured to silently extract (Progress=no, GUIFlags=8) to %TEMP% and immediately run "%%T\\FrameworSwitch32.exe". ^[strings.txt:381] The 7z archive contains the inner payload, the Log.dll helper, MSVC runtime libraries, and two attacker-controlled sidecar files.
Stage 2 — Payload Execution (main at 0x004058b0)
main() performs the following control flow: ^[r2:main]
- Clean-Edashi gate: Tests bit
0x4000at0x43394c. If set, logs"Execute Clean Edashi finished!"vialog.dll_GenericLogImpland exits. This is a conditional abort path, possibly environment-gated or an uninstall/cleanup routine. ^[r2:main:0x4058de] - Single-instance mutex: Opens mutex
{FA531CC1-0497-11d3-A180-00105A276C3E}withSYNCHRONIZErights. If the mutex exists, the process finds a window viaFindWindowWand sendsWM_USER+0x4a(0x4a = 74) withlParampointing to a 1,307-byte payload — inter-process communication to an already-running instance. ^[r2:main:0x40591e] - Path construction: Builds a wide-char path to
BarClientView.exein the same directory. ^[r2:main:0x405986] - File-existence check: Calls
PathFileExistsWon the constructed path. ^[r2:main:0x4059dd] - Launch: If the file exists, calls
ShellExecuteW("open", ...)to launch it. If not, logs"path not exists.%s". ^[r2:main:0x405a0f]
Stage 3 — Encrypted Sidecar Loading
monitor.sym (6.1 MB, entropy 7.93) is strongly consistent with encrypted payload data. sampler.xml (34 KB, entropy 5.35) is lower-entropy, consistent with a configuration or decryption-key file. Neither filename appears as a plaintext string in FrameworSwitch32.exe, suggesting the sidecar names may be hardcoded in .data or resolved dynamically. The Log.dll helper provides structured logging, indicating the authors care about operational telemetry.
Stage 4 — cmd.exe Pipe Execution (fcn.004026c0)
A distinct function at 0x004026c0 (2,492 bytes) creates anonymous pipes via CreatePipe, builds a STARTUPINFO with redirected std handles, and spawns cmd.exe. ^[r2:fcn.004026c0] This pattern is consistent with a reverse-shell or command-execution backdoor capability. It is not invoked from the visible main() flow, suggesting it may be triggered by:
- A command received from the decrypted
monitor.sympayload - An IPC message sent by a companion process (e.g.,
BarClientView.exe) - A callback from
Log.dllunder specific conditions
Decompiled Behavior
Notable Functions
| Address | Size | Description |
|---|---|---|
main (0x004058b0) |
528 | Entry logic: Clean-Edashi gate → mutex check → BarClientView.exe launch |
fcn.004026c0 |
2,492 | Pipe creation + cmd.exe spawn with redirected I/O |
fcn.004063a0 |
3,619 | Window message handler; sends WM_USER+0x4a with 1,307-byte payload to existing window |
fcn.00405340 |
1,386 | Path/string construction helper |
fcn.00405ac0 |
897 | Early initialization called before gate check |
Key Imports and Their Roles
KERNEL32.dll:CreatePipe,PeekNamedPipe,CreateProcessW— pipe-based command execution ^[r2:fcn.004026c0]USER32.dll:FindWindowW,SendMessageW,PostMessageW— IPC to existing instance ^[r2:main]SHELL32.dll:ShellExecuteW— launchBarClientView.exe^[r2:main]SHLWAPI.dll:PathFileExistsW— file-existence gate ^[r2:main]log.dll:GenericLogImpl— structured logging telemetry ^[r2:main:0x4058fb]
Resource Section
The .rsrc section (586 KB, entropy 3.79) contains 17 RT_ICON groups, RT_GROUP_ICON, RT_VERSIONINFO, and RT_MANIFEST resources. The VS_VERSIONINFO reports:
- ProductName:
startbc - FileVersion:
1.0 - InternalName:
startbc - OriginalFilename:
startbc.exeThis masquerades as a benign "startbc" application.
C2 Infrastructure
No static C2 indicators recovered. No hardcoded URLs, IPs, domains, or mutex names (beyond the single-instance GUID) appear in plaintext. Network connectivity, if any, is expected to be:
- Encrypted inside
monitor.symand decrypted at runtime - Communicated via a companion process (
BarClientView.exe) - Or relayed through the
Log.dlltelemetry channel
The BarClientLocatePassport export name in the strings hints at a "locate passport" function — possibly a geo-location or system-fingerprinting module that would beacon to a C2 server.
Interesting Tidbits
-
DigiCert code-signing delta: Unlike the
94db5892sibling (reported as unsigned), this sample carries a valid DigiCert code-signing certificate forHangzhou Shunwang Technology Co.,Ltd(Hangzhou, China), with a 2024 timestamp counter-signature. The signer is a legitimate Chinese technology company — the certificate may be stolen, re-issued under false pretenses, or the company may be a front. This is a notable family-level evolution. -
OpenCTI false-positive label: The triage pipeline tagged this sample
cloud55fileccbased on OpenCTI labels. Static analysis proves it belongs to the ghostpulse x86 YHClient morph cluster, not the ACR/Lumma Go infostealer cluster. Thecloud55filecclabel should be treated as contested and resolved to ghostpulse. ^[entities/cloud55filecc.md] -
"YHClient" attribution clue: PDB paths reference
D:\slave\workspace\YHClient\.... "YH" is a common Chinese abbreviation (银河 Yínhé, 银汉 Yínhàn). The "slave" directory name suggests a CI/CD build server or Jenkins-like environment. -
"Clean Edashi" gate: The conditional abort string "Execute Clean Edashi finished!" uses a Japanese given name (江戸橋 Edashi / 枝 Edashi). This may be a developer artefact, a code-name for an uninstall/cleanup routine, or an anti-analysis breadcrumb.
-
Virtual disk bus driver reference: Source path
ControlvDiskBus.cppin the strings suggests the payload or a companion module includes virtual-disk or storage-filter-driver functionality — potentially used for hiding files or maintaining persistence. -
Multilingual UI support: 31 locale strings (zh-CHS, ar-SA, de-DE, en-US, fr-FR, ja-JP, ko-KR, ru-RU, etc.) in the
.rsrcsection indicate international deployment or a product built for global distribution. -
Log.dll operational telemetry: The helper DLL exports
LogSetOutputLevelandLogSetOption, suggesting configurable log verbosity and output redirection — unusual for commodity malware and more consistent with a managed tool or RAT.
How To Mess With It (Homelab Replication)
Reproducing the dropper pattern:
- Build a small MSVC C++ Win32 GUI app (VS 2019+, x86) that checks a mutex, then launches a hardcoded companion EXE via
ShellExecuteW - Add an IPC path:
FindWindowW+SendMessageW(WM_USER+0x4a, ...)for single-instance coordination - Include a conditional abort gate that logs and exits (mimic "Clean Edashi")
- Build a helper DLL with
GenericLogImplexport and structured logging - Package with 7-Zip SFX (
7zSfxMod) withRunProgram="%%T\\YourApp.exe"andProgress=no - Bundle a large encrypted sidecar file with >7.5 entropy alongside a smaller config file
Detection target for your own VMs: The resulting binary will have:
- A 7-Zip SFX outer stub with
RunProgramconfig - An inner x86 PE importing a custom
log.dll - A
.rsrcsection with 17+ icons and multilingual locale tables - Companion files with >7.5 entropy and non-standard extensions (.sym, .xml)
Deployable Signatures
YARA Rule — GhostPulse SFX Loader (x86 YHClient Morph, Signed Variant)
rule GhostPulse_SFX_YHClient_x86_Signed {
meta:
description = "Detects GhostPulse family 7-Zip SFX dropper with x86 YHClient inner payload (signed variant)"
author = "PacketPursuit"
date = "2026-08-17"
sha256 = "c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8"
strings:
$sfx1 = "7ZSfxMod" ascii
$sfx2 = "7-Zip SFX" wide
$runprog = /RunProgram="\\%%T\\\\[A-Za-z]{5,30}\.exe"/ wide
$yhclient = "YHClient" ascii
$startbc = "startbc.pdb" ascii
$logdll = "log.dll" ascii
$monitor = ".monitor.sym" ascii
$barclient = "BarClientView.exe" ascii
$passport = "BarClientLocatePassport" ascii
$mutex = "{FA531CC1-0497-11d3-A180-00105A276C3E}" ascii
$shunwang = "Hangzhou Shunwang Technology Co.,Ltd" ascii
condition:
uint16(0) == 0x5A4D and
filesize > 3MB and filesize < 15MB and
($sfx1 or $sfx2) and
$runprog and
(any of ($yhclient, $startbc, $logdll, $monitor, $barclient, $passport, $mutex, $shunwang))
}
YARA Rule — FrameworSwitch32 Inner Payload
rule GhostPulse_YHClient_Inner {
meta:
description = "Detects GhostPulse x86 inner payload with YHClient masquerade"
author = "PacketPursuit"
date = "2026-08-17"
sha256 = "c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8"
strings:
$pdb = "D:\\slave\\workspace\\YHClient\\Release\\startbc.pdb" ascii
$src1 = "D:\\slave\\workspace\\YHClient\\startbc\\startbc.cpp" ascii
$src2 = "D:\\slave\\workspace\\YHClient\\startbc\\SecPolicy.cpp" ascii
$src3 = "D:\\slave\\workspace\\YHClient\\CommFile\\driver\\ControlvDiskBus.cpp" ascii
$passport = "BarClientLocatePassport" ascii
$device = "\\\\.\\ControlDevice" ascii
$clean = "Execute Clean Edashi finished!" ascii
$log = "GenericLogImpl" ascii
$shunwang = "Hangzhou Shunwang Technology Co.,Ltd" ascii
condition:
uint16(0) == 0x5A4D and
pe.machine == pe.MACHINE_I386 and
3 of them
}
Behavioral Hunt Query (Sigma)
title: GhostPulse YHClient x86 Payload Execution
description: Detects the execution of GhostPulse inner payload FrameworSwitch32.exe or its BarClientView.exe companion
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'FrameworSwitch32.exe'
- 'BarClientView.exe'
selection_mutex:
- MutexName|contains: '{FA531CC1-0497-11d3-A180-00105A276C3E}'
selection_pipe:
ParentImage|endswith:
- 'FrameworSwitch32.exe'
Image|endswith:
- 'cmd.exe'
CommandLine|contains: 'cmd.exe'
condition: selection or selection_mutex or selection_pipe
falsepositives:
- Unknown
level: high
IOC List
| Type | Value | Note |
|---|---|---|
| SHA-256 (outer) | c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8 |
7-Zip SFX archive |
| SHA-256 (inner) | 15363d9cd84c09e9b14abec25072b7c9f8bb4e5a0fd46aa36908691e6488775b |
FrameworSwitch32.exe |
| SHA-256 (Log.dll) | c5bd69d4964c01e119f27bbb4a7f265e634270e9a91d40084b420c3afdd6e7b0 |
Helper DLL |
| SHA-256 (monitor.sym) | 5ed281c8322905e3eb373d822f5056f629d20379727131a150199e6b0993386f |
Encrypted sidecar |
| SHA-256 (sampler.xml) | a2ae04f8a85a5be22fbcd1f03801679ad9466feb5577d44cb27f93520ca238b7 |
Config/key sidecar |
| Mutex | {FA531CC1-0497-11d3-A180-00105A276C3E} |
Single-instance IPC |
| Code-signing CN | Hangzhou Shunwang Technology Co.,Ltd |
DigiCert G4, valid 2023-03-24 → 2026-06-19 |
| File paths | %TEMP%\FrameworSwitch32.exe |
SFX extraction target |
| File paths | %TEMP%\BarClientView.exe |
Companion process (expected) |
| File paths | %TEMP%\monitor.sym |
Encrypted payload sidecar |
| File paths | %TEMP%\sampler.xml |
Config/key sidecar |
Behavioral Fingerprint Statement
This binary is a 7-Zip SFX self-extractor that silently drops an x86 MSVC C++ payload (FrameworSwitch32.exe) to %TEMP% and executes it. The inner payload imports a custom Log.dll for structured telemetry, checks a single-instance mutex ({FA531CC1-0497-11d3-A180-00105A276C3E}), and if already running, sends a WM_USER+0x4a window message with a 1,307-byte payload to the existing instance. It then constructs a path to BarClientView.exe in the same directory and launches it via ShellExecuteW if present. A separate function creates anonymous pipes and spawns cmd.exe with redirected I/O, consistent with a reverse-shell or command-execution backdoor. Two high-entropy sidecar files (monitor.sym and sampler.xml) are bundled alongside the payload and expected to contain encrypted C2 configuration or secondary payload data. The inner payload may be DigiCert code-signed under the name Hangzhou Shunwang Technology Co.,Ltd.
Detection Signatures
| ATT&CK ID | Name | Evidence |
|---|---|---|
| T1204.002 | User Execution: Malicious File | SFX social-engineering delivery ^[strings.txt:371] |
| T1059.003 | Windows Command Shell | Pipe-based cmd.exe spawn in fcn.004026c0 ^[r2:fcn.004026c0] |
| T1574.002 | DLL Side-Loading | Custom Log.dll loaded by inner payload ^[r2:main:0x4058fb] |
| T1027.002 | Software Packing | 7z SFX outer layer with LZMA compression ^[binwalk.txt] |
| T1071 | Application Layer Protocol | No static C2; expected runtime-decoded from sidecars |
| T1497.001 | System Checks | "Clean Edashi" conditional abort gate ^[r2:main] |
| T1106 | Native API | CreatePipe + CreateProcessW for stealthy command execution ^[r2:fcn.004026c0] |
| T1055 | Process Injection | Potential via pipe-based cmd.exe execution (inferred) |
References
c88a5bba3b32...— This analysis94db5892...— Prior GhostPulse x86 YHClient morph analysis (unsigned sibling) ^[/intel/analyses/94db5892d51fa7f24c6f406591d5cc143f48f3f9f576c66d36a8682e3950102b.html]- ghostpulse — Family entity page
- cloud55filecc — Contested label disambiguation
- 7z-sfx-dropper — Technique page
- companion-file-encrypted-payload — Technique page
- legitimate-library-masquerade — Concept page
Provenance
- File type:
filev5.44 - ExifTool: v12.76
- pefile: Python pefile module
- radare2: rabin2 + r2 decompiler (
pdc) - 7-Zip: v23.01
- Strings: GNU strings v2.38
- Entropy: Python
math.log2custom script - OpenCTI labels:
cloud55file-cc,hijackloader,snappyclient,vidar(all contested) - CAPE: Skipped — no Windows guest available