ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7chromeloader-pulsar-rat: ca687401 — "Windows Media Player" masquerade twin of 94682a96
Executive Summary
A .NET Framework PE32 binary (~1.41 MB) tagged masslogger by upstream triage. Static evidence confirms it is a near-identical twin of sample 94682a96 within the ChromeLoader / Pulsar RAT cluster — same Pulsar.Common.dll v2.4.5.0, same MessagePack C2 serialization, same surveillance and stealer capabilities. The only meaningful deltas are the masquerade identity (wmplayer.exe / Microsoft Corporation vs Acrobat.exe / Adobe Systems) and a handful of encrypted/obfuscated config blobs. The masslogger label is an OpenCTI false positive.
What It Is
| Field | Value |
|---|---|
| SHA-256 | ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7 |
| Size | 1,412,608 bytes (1.35 MB) ^[file.txt] |
| Type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Compiler | .NET Framework (IL only, metadata version 2.0) ^[pefile.txt] |
| Obfuscation | None on outer binary; inner payload uses AES-XOR layered encryption (AesxorModule) ^[strings.txt:4297] |
| Packing | Costura.Fody dependency embedding (compressed DLLs in .rsrc) ^[strings.txt:1294-1302] |
| Signed | No ^[pefile.txt] |
Family ascription: High-confidence chromeloader-pulsar-rat. Dominant class names match the primary sample exactly: ChromeLoader.AesxorModule, PulsarMessagePackSerializer, Pulsar.Common.Messages.*, StealthInjector, ReflectiveLoader, TokensGrabber, FilesGrabber, GetChromeWallets, GetGeckoWallets. ^[strings.txt:6546-6570,6716,6752,6857] ssdeep differs from 94682a96 by only the first character (8fedx... vs 0fedx...), confirming a near-identical build. ^[ssdeep.txt]
Masquerade delta: VS_VERSIONINFO and manifest resources identify this build as wmplayer.exe, Windows Media Player, Microsoft Corporation, version 12.0.19.4. ^[exiftool.json] The primary 94682a96 masquerades as Acrobat.exe, Adobe Acrobat, Adobe Systems Incorporated, version 26.1.21431.0. Both share the same PE timestamp (2045-05-10 12:32:43 UTC) ^[exiftool.json] and identical .text section hash, indicating compilation from the same source tree in a single build session with only the resource manifest changed between outputs.
How It Works
Build / RE Lens
Toolchain: Pure C# / .NET Framework 4.x, compiled with csc.exe or Visual Studio. Entirely IL; no native compiler fingerprints. Debug-build attributes present (capa false-positive risk for T1620, T1059). ^[capa.txt]
Packing / embedding: Costura.Fody compresses the same nine dependency DLLs into .rsrc as the primary: MessagePack.dll (v3.1.4.0), MessagePack.Annotations.dll, System.Buffers, System.Collections.Immutable, System.Memory, System.Numerics.Vectors, System.Runtime.CompilerServices.Unsafe, System.Threading.Tasks.Extensions, and Pulsar.Common.dll (v2.4.5.0). ^[strings.txt:1294-1302,3624]
Embedded resources: .rsrc contains two PNG icons (256×256 and 512×512, 8-bit RGBA) ^[binwalk.txt] and a standard RT_MANIFEST XML document. The larger icon set accounts for the +57 KB size delta over 94682a96. ^[pefile.txt]
Anti-analysis: Identical surface to primary:
- Debugger detection:
CheckRemoteDebuggerPresent,NtQueryInformationProcess(ProcessDebugPort/ProcessDebugFlags),GetTickCounttiming,WudfIsAnyDebuggerPresent. ^[capa.txt] - VM detection: Strings referencing Parallels, QEMU, VMware, VirtualBox. ^[capa.txt]
- Parent PID spoofing (
PROC_THREAD_ATTRIBUTE_PARENT_PROCESS). ^[capa.txt] - Self-deletion via COMSPEC. ^[capa.txt]
Decompiled behavior: Ghidra not run for this sample; static analysis relies on strings + capa, identical to the primary 94682a96 deep-dive. For function-level detail, see /intel/analyses/94682a961e8a61b5a4b34e689de98f0a89b5e8c75bdfc493ed796c29a6b03536.html.
Deploy / ATT&CK Lens
All TTPs are identical to the primary sample. The full mapping is maintained on the chromeloader-pulsar-rat entity page. Key static evidence:
| TTP | Technique | Evidence |
|---|---|---|
| Persistence | T1547.001 — Registry Run | DoStartupItemAdd, StartupInformation ^[strings.txt:3533,5995] |
| Persistence | T1053.005 — Scheduled Task | schtasks creation capability (capa). ^[capa.txt] |
| Persistence | T1546.001 — Default File Association | Capa match. ^[capa.txt] |
| Credential Access | T1555.005 — Password Managers | KeePass theft via KeeFarce. ^[capa.txt] |
| Credential Access | T1555.003 — Browser Credentials | GetChromeWallets, GetGeckoWallets, chrome_decrypt.dll, chrome_decrypt_lite.dll. ^[strings.txt:1426,1570,5552,374] |
| Collection | T1115 — Clipboard Data | Pulsar.Common.Messages.Monitoring.Clipboard. ^[strings.txt:3909] |
| Collection | T1056.001 — Keylogging | Application hook + polling (capa). ^[capa.txt] |
| Collection | T1113 — Screen Capture | capture screenshot, GetHVNCDesktopResponse. ^[capa.txt, strings.txt:4639] |
| Collection | T1123 — Audio Capture | Pulsar.Common.Messages.Audio. ^[strings.txt:6351] |
| Defense Evasion | T1620 — Reflective Code Loading | ReflectiveLoader, FindReflectiveLoader. ^[strings.txt:375,6570] |
| Defense Evasion | T1055.001 — DLL Injection | StealthInjector, InjectDll. ^[capa.txt, strings.txt:6857] |
| Defense Evasion | T1055.003 — Thread Hijacking | Capa match. ^[capa.txt] |
| Defense Evasion | T1134.004 — Parent PID Spoofing | Capa match. ^[capa.txt] |
| Defense Evasion | T1622 — Debugger Evasion | Multiple debugger checks. ^[capa.txt] |
| Defense Evasion | T1497 — VM/Sandbox Evasion | Anti-VM strings + system checks. ^[capa.txt] |
| C2 | T1071 — Named Pipe IPC | NamedPipeServerStream, GenerateUniquePipeName. ^[strings.txt:4360,5389] |
| C2 | T1095 — Non-Standard Protocol | MessagePack-serialized objects over TCP socket. ^[capa.txt, strings.txt:6752] |
| Exfiltration | T1041 — Exfil Over C2 | Discord, Telegram, FTP client names. ^[strings.txt:1549,1668,1798,1860] |
Crypto / traffic encryption: AesxorModule (AES + XOR), ChaCha20Poly1305 referenced in HandleXoriumSteal. ^[strings.txt:1365,1540,5474] Base64 encoding/decoding (26 capa matches). ^[capa.txt]
C2 Infrastructure
No hardcoded URLs, IPs, or webhook endpoints recovered in static strings. The C2 configuration is runtime-decrypted by AesxorModule or passed via the named-pipe bootstrap. The primary twin ed94635a was observed beaconing to 194.87.242.28:4133 (MessagePack over TCP, AES-256-GCM transport) — see raw/analyses/ed94635a.../report.md. This sample is expected to use the same infrastructure or a rotation within the same panel.
Static C2 artifacts:
PulsarMessagePackSerializer— MessagePack-framed commands. ^[strings.txt:6752]NamedPipeServerStream+PipeStream— IPC transport. ^[strings.txt:4360,5389]System.Net.Sockets.TcpClientimplied by capa TCP socket matches. ^[capa.txt]- HTTP client surface:
set HTTP User-Agent,set web proxy,create HTTP request. ^[capa.txt]
Interesting Tidbits
- "masslogger" is a ghost: The only sample in the corpus tagged
masslogger. The OpenCTI labelmassloggeris a false-positive family ascription; the static fingerprint is pure ChromeLoader/Pulsar. ^[metadata.json, triage.json] - Twin confirmation: ssdeep near-match (differs by first character only), identical PE timestamp, identical
.texthash, identical class/method names — same source tree, different resource manifest. ^[ssdeep.txt, pefile.txt] - Masquerade variance:
wmplayer.exe(Media Player) vsAcrobat.exe(Adobe PDF). Both use plausible, widely-trusted vendor identities. The builder likely randomizes or campaign-selects the masquerade at compile time. - Icon resources: Two high-resolution PNGs in
.rsrc(256×256 and 512×512) ^[binwalk.txt] — unusual for a stealer/RAT and likely chosen to reinforce the Media Player masquerade in Explorer thumbnails and taskbar previews. - No CAPE detonation: No Windows guest available at time of triage; all TTPs inferred from static strings + capa. ^[dynamic-analysis.md]
Deployable Signatures
YARA Rule
The primary sample's YARA rule (from 94682a96) matches this twin verbatim. A streamlined version follows:
rule ChromeloaderPulsar_RAT
{
meta:
description = "ChromeLoader / Pulsar .NET RAT with Pulsar.Common v2.4.5.0"
author = "PacketPursuit"
date = "2026-08-04"
hash = "ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7"
family = "chromeloader-pulsar-rat"
strings:
$pulsar_common = "Pulsar.Common" ascii wide
$pulsar_msgpack = "PulsarMessagePackSerializer" ascii wide
$chrome_loader = "ChromeLoader" ascii wide
$aesxor_module = "AesxorModule" ascii wide
$start_pipe = "StartPipeServerAsync" ascii wide
$stealth_inject = "StealthInjector" ascii wide
$reflective = "ReflectiveLoader" ascii wide
$msgpack_v = "costura.messagepack.dll.compressed" ascii wide
$pulsar_dll = "costura.pulsar.common.dll.compressed" ascii wide
$tokens_grab = "TokensGrabber" ascii wide
$files_grab = "FilesGrabber" ascii wide
$chrome_wallet = "GetChromeWallets" ascii wide
$gecko_wallet = "GetGeckoWallets" ascii wide
$chrome_decrypt = "chrome_decrypt.dll" ascii wide
condition:
uint16(0) == 0x5a4d and
( $pulsar_common or $chrome_loader ) and
( $reflective or $stealth_inject or $start_pipe ) and
( $tokens_grab or $files_grab or $chrome_wallet )
}
Behavioral Hunt Query (Sigma-like)
title: ChromeLoader Pulsar Named Pipe C2 and Injection
logsource:
product: windows
detection:
selection_pipe:
- Image|endswith:
- '\\wmplayer.exe'
- '\\Acrobat.exe'
- CommandLine|contains:
- 'NamedPipeServerStream'
- 'GenerateUniquePipeName'
selection_inject:
- CallTrace|contains:
- 'VirtualAllocEx'
- 'WriteProcessMemory'
- 'CreateRemoteThread'
- TargetImage|endswith:
- '\\svchost.exe'
- '\\explorer.exe'
- '\\RuntimeBroker.exe'
selection_registry:
- EventType: SetValue
- TargetObject|contains:
- '\\Software\\Microsoft\\Windows\\CurrentVersion\\Run'
- Details|contains:
- 'ChromeLoader'
- 'Pulsar'
- 'wmplayer'
- 'Acrobat'
condition: 1 of selection*
falsepositives:
- Unknown
level: high
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7 |
This twin |
| SHA-256 | 94682a961e8a61b5a4b34e689de98f0a89b5e8c75bdfc493ed796c29a6b03536 |
Primary twin |
| SHA-256 | ed94635a2348ca2e8c9c53a46336b14be509ce0a19c2521d50f9976470096ab1 |
Cluster member with observed C2 |
| ssdeep | 24576:8fedx38vxbIRxJzck+uGW/yFoBkkAxg2jFjHmGOpy+X9zAE5Fw:8fex33RTYjqqanRaXOQ+ |
Twin |
| Mutex | MutexControl |
Observed in strings ^[strings.txt] |
| Pipe name | GenerateUniquePipeName |
Dynamic pipe generation ^[strings.txt] |
| Registry | HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run |
Startup persistence |
| File | chrome_decrypt.dll |
Embedded browser decryption module ^[strings.txt] |
| File | chrome_decrypt_lite.dll |
Lite variant ^[strings.txt] |
| Module | Pulsar.Common.dll v2.4.5.0 |
Core framework DLL ^[strings.txt] |
| Module | MessagePack.dll v3.1.4.0 |
Serialization layer ^[strings.txt] |
| C2 (observed in cluster) | 194.87.242.28:4133 |
From ed94635a dynamic analysis |
Behavioral Fingerprint
This binary is a .NET Framework PE32 with a minimal native import table (mscoree._CorExeMain only) and a high-entropy .rsrc section containing Costura.Fody-compressed DLLs. At runtime it decompresses Pulsar.Common.dll and MessagePack.dll, initializes a NamedPipeServerStream, and decrypts C2 config via AesxorModule. It enumerates browser SQLite stores (Chrome, Firefox, Yandex, CryptoTab), extracts credentials with chrome_decrypt.dll, harvests Discord/Telegram tokens, captures screenshots and audio via WasapiCapture, and exfiltrates over MessagePack-serialized TCP or HTTP. Process injection is performed through StealthInjector using VirtualAllocEx / WriteProcessMemory / CreateRemoteThread. Persistence is achieved via Registry Run keys and scheduled tasks.
Detection Signatures (capa → ATT&CK)
See capa.txt for 330+ capability matches. The mapping is identical to the primary 94682a96 sample. Notable dense clusters:
- Communication: 6×
receive data, 6×send data, TCP socket, named-pipe creation, HTTP request/response. ^[capa.txt] - Process injection: DLL injection, thread hijacking, reflective loading,
VirtualAllocEx+WriteProcessMemory+CreateRemoteThread. ^[capa.txt] - Collection: Screenshot (2), keylog (3), clipboard (4), password manager (KeeFarce), audio/video capture. ^[capa.txt]
- Anti-analysis: Debugger checks (5), VM checks (4), parent-PID spoofing, self-deletion. ^[capa.txt]
References
- Sample source: OpenCTI / MalwareBazaar (artifact
2e5f5458-29bc-4745-910f-522b1c5d52c2) - Twin sample:
94682a961e8a61b5a4b34e689de98f0a89b5e8c75bdfc493ed796c29a6b03536 - Cluster member:
ed94635a2348ca2e8c9c53a46336b14be509ce0a19c2521d50f9976470096ab1 - Entity page: chromeloader-pulsar-rat
- Distribution label: gcleaner
Provenance
file.txt— file type and headerpefile.txt— PE structure, imports, sections, resource directorystrings.txt— .NET metadata strings, class names, method namesfloss.txt— decoded stacked strings (minimal additional findings; tool argument error)capa.txt— Mandiant capa v7 static capability detectionbinwalk.txt— embedded file signatures (PNG icons, SQLite, AES S-Box)rabin2-info.txt— radare2 binary header (CIL, PE32, compiled 2045-05-10)exiftool.json— VS_VERSIONINFO masquerade metadatametadata.json— OpenCTI labels (masslogger,dropped-by-gcleaner,us.file)triage.json— original (incorrect)massloggerfamily labeldynamic-analysis.md— CAPE skipped (no Windows guest)
Report generated 2026-08-04. Static-only analysis; no dynamic execution data available.