typeanalysisfamilyblackmatterconfidencemediumcreated2026-08-30updated2026-08-30malware-familyloaderpeanti-vmdefense-evasionc2attribution
SHA-256: c9417d4683324c34c7b976395c01f79150a626966e27144244214423aa64ccde

blackmatter: c9417d46 — 29th confirmed sibling in MSVC 14.12 reflective-loader cluster

Executive Summary

Twenty-ninth confirmed sibling in the MSVC 14.12 PE32 GUI reflective-loader cluster tagged blackmatter and dropped-by-phorpiex. Identical stub template to all prior siblings: PEB-walking API resolution, XOR-NOT alphabet cipher, CPUID anti-VM, and LCG-based C2 URL generation. Individualized encrypted .data payload and unique PE checksum 0x2A989 confirm per-sample customization. Static-only; CAPE skipped.

What It Is

  • SHA-256: c9417d4683324c34c7b976395c01f79150a626966e27144244214423aa64ccde ^[metadata.json]
  • File: PE32 executable (GUI) Intel 80386, 6 sections, 149,504 bytes ^[file.txt]
  • Timestamp: Fri Sep 9 01:27:01 2022 UTC (0x631A9665) ^[exiftool.json:15]
  • Linker: MSVC 14.12 ^[exiftool.json:18]
  • PE checksum: 0x2A989 (new to cluster) ^[pefile.txt:66]
  • .text hash: cfbda2c4... — matches majority group (21 prior siblings) ^[pefile.txt:93]
  • .data hash: 1a1ee067... — unique, individualized payload ^[pefile.txt:155]
  • Signing: Unsigned ^[rabin2-info.txt:27]
  • Imports: Facade — GDI32 (6), USER32 (11), KERNEL32 (8) ^[pefile.txt:249-301]
  • Mitigations: ASLR, DEP/NX, stack canary ^[rabin2-info.txt:6,21]

How It Works

Cluster sibling — shared behavior documented on blackmatter. Per-sample delta is the encrypted payload in .data (entropy 7.987, R/W), which the stub decrypts and reflectively loads. No new mechanisms observed versus prior 28 siblings. Delivered via phorpiex spam infrastructure ^[metadata.json:8].

Decompiled Behavior

Ghidra not run. Behavior inferred from cluster profile:

  1. CPUID hypervisor-bit check + RDTSC timing gate
  2. PEB-walking InMemoryOrderModuleList with export-name hashing
  3. .data payload decryption via XOR-NOT alphabet cipher (key 0x10035fff)
  4. Reflective load: VirtualAlloc RWX + memmove
  5. LCG PRNG (0x19660d/0x3c6ef35f) generates C2 URLs at runtime
  6. HTTP POST exfil via WinINet

C2 Infrastructure

No static C2 strings. URLs are runtime-generated via LCG PRNG inside the decrypted payload.

Interesting Tidbits

  • Builder fingerprint: Identical timestamp across 29 siblings confirms builder stamping ^[pefile.txt:34]
  • Payload individuation: Unique .data SHA-256 per sample confirms per-sample encryption ^[pefile.txt:155]
  • Checksum novelty: 0x2A989 not seen in 28 prior siblings ^[pefile.txt:66]

Deployable Signatures

rule blackmatter_reflective_loader_29th {
    meta:
        description = "MSVC 14.12 reflective-loader cluster (blackmatter tag)"
        author = "PacketPursuit"
        date = "2026-08-30"
        hash = "c9417d4683324c34c7b976395c01f79150a626966e27144244214423aa64ccde"
    strings:
        $xkey = { ff 5f 03 10 }
        $peb_walk = { 64 A1 30 00 00 00 }
    condition:
        uint16(0) == 0x5A4D and
        pe.timestamp == 0x631A9665 and
        pe.linker_version.major == 14 and
        pe.sections[0].name == ".text" and
        ($xkey or $peb_walk)
}

Behavioral fingerprint: 32-bit PE GUI, MSVC 14.12, forged Sep 2022 timestamp, facade imports (GDI32/USER32/KERNEL32 only). Resolves threat APIs via PEB export-name hashing, decrypts individualized high-entropy .data payload with XOR-NOT cipher, reflectively loads inner PE into RWX memory. C2 unreachable statically — URLs generated at runtime via LCG PRNG.

References

  • blackmatter — cluster entity page
  • phorpiex — delivery infrastructure
  • OpenCTI artifact: 6e83e448-a9f3-4c69-8825-68aa61a98288 ^[metadata.json:2]

Provenance

file.txt, exiftool.json, pefile.txt, rabin2-info.txt, metadata.json, triage.json, dynamic-analysis.md, entities/blackmatter.md.