typeanalysisfamilyghostpulseconfidencehighcreated2026-08-17updated2026-08-17malware-familyloaderpeevasionc2signing
SHA-256: c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8

ghostpulse: c88a5bba — DigiCert-signed YHClient x86 morph, cloud55filecc false-positive label

Executive Summary

A 6.6 MB 7-Zip SFX archive that silently extracts an x86 MSVC C++ payload (FrameworSwitch32.exe) to %TEMP% and executes it. The inner PE is DigiCert code-signed (CN=Hangzhou Shunwang Technology Co.,Ltd) and masquerades as a "YHClient" product with PDB paths referencing D:\slave\workspace\YHClient\Release\startbc.pdb. It is bundled with a custom Log.dll helper, legitimate MSVC redistributables, a 6.1 MB high-entropy encrypted sidecar (monitor.sym), and a 34 KB config file (sampler.xml). The OpenCTI cloud55filecc label is a false positive — static evidence resolves this sample to the ghostpulse family, specifically the x86 YHClient morph cluster first documented at 94db5892. No CAPE detonation available (no Windows guest); all behaviour inferred from static extraction and decompilation.

What It Is

  • Outer container: 7-Zip SFX stub (7ZSfxMod_x86.exe, Oleg Scherbakov, 2010), MSVC linker v8.0, compiled 2010-06-27 ^[file.txt] ^[exiftool.json]
  • Archive: LZMA-compressed 7z solid archive at offset 0x2df4f; 6 files extracted to %TEMP% ^[binwalk.txt]
  • Inner payload: FrameworSwitch32.exe — PE32 x86, MSVC 14.x (VS 2019+), timestamp 0x6790d7cb (2025-01-22), 6 sections ^[rabin2-info.txt]
  • PDB path: D:\slave\workspace\YHClient\Release\startbc.pdb — masquerades as a "YHClient" product build ^[rabin2-info.txt] ^[strings.txt]
  • Authenticode: Valid DigiCert code-signing certificate chain: leaf CN=Hangzhou Shunwang Technology Co.,Ltd (CN), issued by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, valid 2023-03-24 through 2026-06-19, countersigned by DigiCert Timestamp 2024 ^[r2:iC]
  • Helper DLL: Log.dll — PE32 x86, same toolchain/timestamp as inner payload, exports GenericLogImpl, LogSetOption, LogSetOutputLevel ^[strings Log.dll]
  • Sidecar files: monitor.sym (6.1 MB, entropy 7.93, near-random — encrypted payload) and sampler.xml (34 KB, entropy 5.35 — likely config/key) ^[terminal:entropy-check]
  • Legitimate libraries: msvcp_win.dll and ucrtbase.dll — standard MSVC 2019+ redistributables
  • Family resolution: OpenCTI label cloud55filecc is contested. The sample shares no Go build fingerprint, no ACR certificate chain, and no Lumma/ACR randomized-function-name pattern. All static indicators (SFX packaging, YHClient masquerade, Log.dll, monitor.sym/sampler.xml sidecars, cmd.exe pipe execution) align with the ghostpulse x86 YHClient morph cluster. ^[entities/cloud55filecc.md] ^[entities/ghostpulse.md]

How It Works

Stage 1 — SFX Extraction

The outer binary is a legitimate 7-Zip SFX mod configured to silently extract (Progress=no, GUIFlags=8) to %TEMP% and immediately run "%%T\\FrameworSwitch32.exe". ^[strings.txt:381] The 7z archive contains the inner payload, the Log.dll helper, MSVC runtime libraries, and two attacker-controlled sidecar files.

Stage 2 — Payload Execution (main at 0x004058b0)

main() performs the following control flow: ^[r2:main]

  1. Clean-Edashi gate: Tests bit 0x4000 at 0x43394c. If set, logs "Execute Clean Edashi finished!" via log.dll_GenericLogImpl and exits. This is a conditional abort path, possibly environment-gated or an uninstall/cleanup routine. ^[r2:main:0x4058de]
  2. Single-instance mutex: Opens mutex {FA531CC1-0497-11d3-A180-00105A276C3E} with SYNCHRONIZE rights. If the mutex exists, the process finds a window via FindWindowW and sends WM_USER+0x4a (0x4a = 74) with lParam pointing to a 1,307-byte payload — inter-process communication to an already-running instance. ^[r2:main:0x40591e]
  3. Path construction: Builds a wide-char path to BarClientView.exe in the same directory. ^[r2:main:0x405986]
  4. File-existence check: Calls PathFileExistsW on the constructed path. ^[r2:main:0x4059dd]
  5. Launch: If the file exists, calls ShellExecuteW("open", ...) to launch it. If not, logs "path not exists.%s". ^[r2:main:0x405a0f]

Stage 3 — Encrypted Sidecar Loading

monitor.sym (6.1 MB, entropy 7.93) is strongly consistent with encrypted payload data. sampler.xml (34 KB, entropy 5.35) is lower-entropy, consistent with a configuration or decryption-key file. Neither filename appears as a plaintext string in FrameworSwitch32.exe, suggesting the sidecar names may be hardcoded in .data or resolved dynamically. The Log.dll helper provides structured logging, indicating the authors care about operational telemetry.

Stage 4 — cmd.exe Pipe Execution (fcn.004026c0)

A distinct function at 0x004026c0 (2,492 bytes) creates anonymous pipes via CreatePipe, builds a STARTUPINFO with redirected std handles, and spawns cmd.exe. ^[r2:fcn.004026c0] This pattern is consistent with a reverse-shell or command-execution backdoor capability. It is not invoked from the visible main() flow, suggesting it may be triggered by:

  • A command received from the decrypted monitor.sym payload
  • An IPC message sent by a companion process (e.g., BarClientView.exe)
  • A callback from Log.dll under specific conditions

Decompiled Behavior

Notable Functions

Address Size Description
main (0x004058b0) 528 Entry logic: Clean-Edashi gate → mutex check → BarClientView.exe launch
fcn.004026c0 2,492 Pipe creation + cmd.exe spawn with redirected I/O
fcn.004063a0 3,619 Window message handler; sends WM_USER+0x4a with 1,307-byte payload to existing window
fcn.00405340 1,386 Path/string construction helper
fcn.00405ac0 897 Early initialization called before gate check

Key Imports and Their Roles

  • KERNEL32.dll: CreatePipe, PeekNamedPipe, CreateProcessW — pipe-based command execution ^[r2:fcn.004026c0]
  • USER32.dll: FindWindowW, SendMessageW, PostMessageW — IPC to existing instance ^[r2:main]
  • SHELL32.dll: ShellExecuteW — launch BarClientView.exe ^[r2:main]
  • SHLWAPI.dll: PathFileExistsW — file-existence gate ^[r2:main]
  • log.dll: GenericLogImpl — structured logging telemetry ^[r2:main:0x4058fb]

Resource Section

The .rsrc section (586 KB, entropy 3.79) contains 17 RT_ICON groups, RT_GROUP_ICON, RT_VERSIONINFO, and RT_MANIFEST resources. The VS_VERSIONINFO reports:

  • ProductName: startbc
  • FileVersion: 1.0
  • InternalName: startbc
  • OriginalFilename: startbc.exe This masquerades as a benign "startbc" application.

C2 Infrastructure

No static C2 indicators recovered. No hardcoded URLs, IPs, domains, or mutex names (beyond the single-instance GUID) appear in plaintext. Network connectivity, if any, is expected to be:

  1. Encrypted inside monitor.sym and decrypted at runtime
  2. Communicated via a companion process (BarClientView.exe)
  3. Or relayed through the Log.dll telemetry channel

The BarClientLocatePassport export name in the strings hints at a "locate passport" function — possibly a geo-location or system-fingerprinting module that would beacon to a C2 server.

Interesting Tidbits

  1. DigiCert code-signing delta: Unlike the 94db5892 sibling (reported as unsigned), this sample carries a valid DigiCert code-signing certificate for Hangzhou Shunwang Technology Co.,Ltd (Hangzhou, China), with a 2024 timestamp counter-signature. The signer is a legitimate Chinese technology company — the certificate may be stolen, re-issued under false pretenses, or the company may be a front. This is a notable family-level evolution.

  2. OpenCTI false-positive label: The triage pipeline tagged this sample cloud55filecc based on OpenCTI labels. Static analysis proves it belongs to the ghostpulse x86 YHClient morph cluster, not the ACR/Lumma Go infostealer cluster. The cloud55filecc label should be treated as contested and resolved to ghostpulse. ^[entities/cloud55filecc.md]

  3. "YHClient" attribution clue: PDB paths reference D:\slave\workspace\YHClient\.... "YH" is a common Chinese abbreviation (银河 Yínhé, 银汉 Yínhàn). The "slave" directory name suggests a CI/CD build server or Jenkins-like environment.

  4. "Clean Edashi" gate: The conditional abort string "Execute Clean Edashi finished!" uses a Japanese given name (江戸橋 Edashi / 枝 Edashi). This may be a developer artefact, a code-name for an uninstall/cleanup routine, or an anti-analysis breadcrumb.

  5. Virtual disk bus driver reference: Source path ControlvDiskBus.cpp in the strings suggests the payload or a companion module includes virtual-disk or storage-filter-driver functionality — potentially used for hiding files or maintaining persistence.

  6. Multilingual UI support: 31 locale strings (zh-CHS, ar-SA, de-DE, en-US, fr-FR, ja-JP, ko-KR, ru-RU, etc.) in the .rsrc section indicate international deployment or a product built for global distribution.

  7. Log.dll operational telemetry: The helper DLL exports LogSetOutputLevel and LogSetOption, suggesting configurable log verbosity and output redirection — unusual for commodity malware and more consistent with a managed tool or RAT.

How To Mess With It (Homelab Replication)

Reproducing the dropper pattern:

  1. Build a small MSVC C++ Win32 GUI app (VS 2019+, x86) that checks a mutex, then launches a hardcoded companion EXE via ShellExecuteW
  2. Add an IPC path: FindWindowW + SendMessageW(WM_USER+0x4a, ...) for single-instance coordination
  3. Include a conditional abort gate that logs and exits (mimic "Clean Edashi")
  4. Build a helper DLL with GenericLogImpl export and structured logging
  5. Package with 7-Zip SFX (7zSfxMod) with RunProgram="%%T\\YourApp.exe" and Progress=no
  6. Bundle a large encrypted sidecar file with >7.5 entropy alongside a smaller config file

Detection target for your own VMs: The resulting binary will have:

  • A 7-Zip SFX outer stub with RunProgram config
  • An inner x86 PE importing a custom log.dll
  • A .rsrc section with 17+ icons and multilingual locale tables
  • Companion files with >7.5 entropy and non-standard extensions (.sym, .xml)

Deployable Signatures

YARA Rule — GhostPulse SFX Loader (x86 YHClient Morph, Signed Variant)

rule GhostPulse_SFX_YHClient_x86_Signed {
    meta:
        description = "Detects GhostPulse family 7-Zip SFX dropper with x86 YHClient inner payload (signed variant)"
        author = "PacketPursuit"
        date = "2026-08-17"
        sha256 = "c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8"
    strings:
        $sfx1 = "7ZSfxMod" ascii
        $sfx2 = "7-Zip SFX" wide
        $runprog = /RunProgram="\\%%T\\\\[A-Za-z]{5,30}\.exe"/ wide
        $yhclient = "YHClient" ascii
        $startbc = "startbc.pdb" ascii
        $logdll = "log.dll" ascii
        $monitor = ".monitor.sym" ascii
        $barclient = "BarClientView.exe" ascii
        $passport = "BarClientLocatePassport" ascii
        $mutex = "{FA531CC1-0497-11d3-A180-00105A276C3E}" ascii
        $shunwang = "Hangzhou Shunwang Technology Co.,Ltd" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize > 3MB and filesize < 15MB and
        ($sfx1 or $sfx2) and
        $runprog and
        (any of ($yhclient, $startbc, $logdll, $monitor, $barclient, $passport, $mutex, $shunwang))
}

YARA Rule — FrameworSwitch32 Inner Payload

rule GhostPulse_YHClient_Inner {
    meta:
        description = "Detects GhostPulse x86 inner payload with YHClient masquerade"
        author = "PacketPursuit"
        date = "2026-08-17"
        sha256 = "c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8"
    strings:
        $pdb = "D:\\slave\\workspace\\YHClient\\Release\\startbc.pdb" ascii
        $src1 = "D:\\slave\\workspace\\YHClient\\startbc\\startbc.cpp" ascii
        $src2 = "D:\\slave\\workspace\\YHClient\\startbc\\SecPolicy.cpp" ascii
        $src3 = "D:\\slave\\workspace\\YHClient\\CommFile\\driver\\ControlvDiskBus.cpp" ascii
        $passport = "BarClientLocatePassport" ascii
        $device = "\\\\.\\ControlDevice" ascii
        $clean = "Execute Clean Edashi finished!" ascii
        $log = "GenericLogImpl" ascii
        $shunwang = "Hangzhou Shunwang Technology Co.,Ltd" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.machine == pe.MACHINE_I386 and
        3 of them
}

Behavioral Hunt Query (Sigma)

title: GhostPulse YHClient x86 Payload Execution
description: Detects the execution of GhostPulse inner payload FrameworSwitch32.exe or its BarClientView.exe companion
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - 'FrameworSwitch32.exe'
      - 'BarClientView.exe'
  selection_mutex:
    - MutexName|contains: '{FA531CC1-0497-11d3-A180-00105A276C3E}'
  selection_pipe:
    ParentImage|endswith:
      - 'FrameworSwitch32.exe'
    Image|endswith:
      - 'cmd.exe'
    CommandLine|contains: 'cmd.exe'
  condition: selection or selection_mutex or selection_pipe
falsepositives:
  - Unknown
level: high

IOC List

Type Value Note
SHA-256 (outer) c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8 7-Zip SFX archive
SHA-256 (inner) 15363d9cd84c09e9b14abec25072b7c9f8bb4e5a0fd46aa36908691e6488775b FrameworSwitch32.exe
SHA-256 (Log.dll) c5bd69d4964c01e119f27bbb4a7f265e634270e9a91d40084b420c3afdd6e7b0 Helper DLL
SHA-256 (monitor.sym) 5ed281c8322905e3eb373d822f5056f629d20379727131a150199e6b0993386f Encrypted sidecar
SHA-256 (sampler.xml) a2ae04f8a85a5be22fbcd1f03801679ad9466feb5577d44cb27f93520ca238b7 Config/key sidecar
Mutex {FA531CC1-0497-11d3-A180-00105A276C3E} Single-instance IPC
Code-signing CN Hangzhou Shunwang Technology Co.,Ltd DigiCert G4, valid 2023-03-24 → 2026-06-19
File paths %TEMP%\FrameworSwitch32.exe SFX extraction target
File paths %TEMP%\BarClientView.exe Companion process (expected)
File paths %TEMP%\monitor.sym Encrypted payload sidecar
File paths %TEMP%\sampler.xml Config/key sidecar

Behavioral Fingerprint Statement

This binary is a 7-Zip SFX self-extractor that silently drops an x86 MSVC C++ payload (FrameworSwitch32.exe) to %TEMP% and executes it. The inner payload imports a custom Log.dll for structured telemetry, checks a single-instance mutex ({FA531CC1-0497-11d3-A180-00105A276C3E}), and if already running, sends a WM_USER+0x4a window message with a 1,307-byte payload to the existing instance. It then constructs a path to BarClientView.exe in the same directory and launches it via ShellExecuteW if present. A separate function creates anonymous pipes and spawns cmd.exe with redirected I/O, consistent with a reverse-shell or command-execution backdoor. Two high-entropy sidecar files (monitor.sym and sampler.xml) are bundled alongside the payload and expected to contain encrypted C2 configuration or secondary payload data. The inner payload may be DigiCert code-signed under the name Hangzhou Shunwang Technology Co.,Ltd.

Detection Signatures

ATT&CK ID Name Evidence
T1204.002 User Execution: Malicious File SFX social-engineering delivery ^[strings.txt:371]
T1059.003 Windows Command Shell Pipe-based cmd.exe spawn in fcn.004026c0 ^[r2:fcn.004026c0]
T1574.002 DLL Side-Loading Custom Log.dll loaded by inner payload ^[r2:main:0x4058fb]
T1027.002 Software Packing 7z SFX outer layer with LZMA compression ^[binwalk.txt]
T1071 Application Layer Protocol No static C2; expected runtime-decoded from sidecars
T1497.001 System Checks "Clean Edashi" conditional abort gate ^[r2:main]
T1106 Native API CreatePipe + CreateProcessW for stealthy command execution ^[r2:fcn.004026c0]
T1055 Process Injection Potential via pipe-based cmd.exe execution (inferred)

References

Provenance

  • File type: file v5.44
  • ExifTool: v12.76
  • pefile: Python pefile module
  • radare2: rabin2 + r2 decompiler (pdc)
  • 7-Zip: v23.01
  • Strings: GNU strings v2.38
  • Entropy: Python math.log2 custom script
  • OpenCTI labels: cloud55file-cc, hijackloader, snappyclient, vidar (all contested)
  • CAPE: Skipped — no Windows guest available