typeanalysisfamilychromeloader-pulsar-ratconfidencehighcreated2026-08-04updated2026-08-04dotnetmalware-familyratinfostealerloaderpersistencec2mitre-attckdefense-evasioncode-injectionexfiltration
SHA-256: ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7

chromeloader-pulsar-rat: ca687401 — "Windows Media Player" masquerade twin of 94682a96

Executive Summary A .NET Framework PE32 binary (~1.41 MB) tagged masslogger by upstream triage. Static evidence confirms it is a near-identical twin of sample 94682a96 within the ChromeLoader / Pulsar RAT cluster — same Pulsar.Common.dll v2.4.5.0, same MessagePack C2 serialization, same surveillance and stealer capabilities. The only meaningful deltas are the masquerade identity (wmplayer.exe / Microsoft Corporation vs Acrobat.exe / Adobe Systems) and a handful of encrypted/obfuscated config blobs. The masslogger label is an OpenCTI false positive.


What It Is

Field Value
SHA-256 ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7
Size 1,412,608 bytes (1.35 MB) ^[file.txt]
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Compiler .NET Framework (IL only, metadata version 2.0) ^[pefile.txt]
Obfuscation None on outer binary; inner payload uses AES-XOR layered encryption (AesxorModule) ^[strings.txt:4297]
Packing Costura.Fody dependency embedding (compressed DLLs in .rsrc) ^[strings.txt:1294-1302]
Signed No ^[pefile.txt]

Family ascription: High-confidence chromeloader-pulsar-rat. Dominant class names match the primary sample exactly: ChromeLoader.AesxorModule, PulsarMessagePackSerializer, Pulsar.Common.Messages.*, StealthInjector, ReflectiveLoader, TokensGrabber, FilesGrabber, GetChromeWallets, GetGeckoWallets. ^[strings.txt:6546-6570,6716,6752,6857] ssdeep differs from 94682a96 by only the first character (8fedx... vs 0fedx...), confirming a near-identical build. ^[ssdeep.txt]

Masquerade delta: VS_VERSIONINFO and manifest resources identify this build as wmplayer.exe, Windows Media Player, Microsoft Corporation, version 12.0.19.4. ^[exiftool.json] The primary 94682a96 masquerades as Acrobat.exe, Adobe Acrobat, Adobe Systems Incorporated, version 26.1.21431.0. Both share the same PE timestamp (2045-05-10 12:32:43 UTC) ^[exiftool.json] and identical .text section hash, indicating compilation from the same source tree in a single build session with only the resource manifest changed between outputs.


How It Works

Build / RE Lens

Toolchain: Pure C# / .NET Framework 4.x, compiled with csc.exe or Visual Studio. Entirely IL; no native compiler fingerprints. Debug-build attributes present (capa false-positive risk for T1620, T1059). ^[capa.txt]

Packing / embedding: Costura.Fody compresses the same nine dependency DLLs into .rsrc as the primary: MessagePack.dll (v3.1.4.0), MessagePack.Annotations.dll, System.Buffers, System.Collections.Immutable, System.Memory, System.Numerics.Vectors, System.Runtime.CompilerServices.Unsafe, System.Threading.Tasks.Extensions, and Pulsar.Common.dll (v2.4.5.0). ^[strings.txt:1294-1302,3624]

Embedded resources: .rsrc contains two PNG icons (256×256 and 512×512, 8-bit RGBA) ^[binwalk.txt] and a standard RT_MANIFEST XML document. The larger icon set accounts for the +57 KB size delta over 94682a96. ^[pefile.txt]

Anti-analysis: Identical surface to primary:

  • Debugger detection: CheckRemoteDebuggerPresent, NtQueryInformationProcess (ProcessDebugPort/ProcessDebugFlags), GetTickCount timing, WudfIsAnyDebuggerPresent. ^[capa.txt]
  • VM detection: Strings referencing Parallels, QEMU, VMware, VirtualBox. ^[capa.txt]
  • Parent PID spoofing (PROC_THREAD_ATTRIBUTE_PARENT_PROCESS). ^[capa.txt]
  • Self-deletion via COMSPEC. ^[capa.txt]

Decompiled behavior: Ghidra not run for this sample; static analysis relies on strings + capa, identical to the primary 94682a96 deep-dive. For function-level detail, see /intel/analyses/94682a961e8a61b5a4b34e689de98f0a89b5e8c75bdfc493ed796c29a6b03536.html.

Deploy / ATT&CK Lens

All TTPs are identical to the primary sample. The full mapping is maintained on the chromeloader-pulsar-rat entity page. Key static evidence:

TTP Technique Evidence
Persistence T1547.001 — Registry Run DoStartupItemAdd, StartupInformation ^[strings.txt:3533,5995]
Persistence T1053.005 — Scheduled Task schtasks creation capability (capa). ^[capa.txt]
Persistence T1546.001 — Default File Association Capa match. ^[capa.txt]
Credential Access T1555.005 — Password Managers KeePass theft via KeeFarce. ^[capa.txt]
Credential Access T1555.003 — Browser Credentials GetChromeWallets, GetGeckoWallets, chrome_decrypt.dll, chrome_decrypt_lite.dll. ^[strings.txt:1426,1570,5552,374]
Collection T1115 — Clipboard Data Pulsar.Common.Messages.Monitoring.Clipboard. ^[strings.txt:3909]
Collection T1056.001 — Keylogging Application hook + polling (capa). ^[capa.txt]
Collection T1113 — Screen Capture capture screenshot, GetHVNCDesktopResponse. ^[capa.txt, strings.txt:4639]
Collection T1123 — Audio Capture Pulsar.Common.Messages.Audio. ^[strings.txt:6351]
Defense Evasion T1620 — Reflective Code Loading ReflectiveLoader, FindReflectiveLoader. ^[strings.txt:375,6570]
Defense Evasion T1055.001 — DLL Injection StealthInjector, InjectDll. ^[capa.txt, strings.txt:6857]
Defense Evasion T1055.003 — Thread Hijacking Capa match. ^[capa.txt]
Defense Evasion T1134.004 — Parent PID Spoofing Capa match. ^[capa.txt]
Defense Evasion T1622 — Debugger Evasion Multiple debugger checks. ^[capa.txt]
Defense Evasion T1497 — VM/Sandbox Evasion Anti-VM strings + system checks. ^[capa.txt]
C2 T1071 — Named Pipe IPC NamedPipeServerStream, GenerateUniquePipeName. ^[strings.txt:4360,5389]
C2 T1095 — Non-Standard Protocol MessagePack-serialized objects over TCP socket. ^[capa.txt, strings.txt:6752]
Exfiltration T1041 — Exfil Over C2 Discord, Telegram, FTP client names. ^[strings.txt:1549,1668,1798,1860]

Crypto / traffic encryption: AesxorModule (AES + XOR), ChaCha20Poly1305 referenced in HandleXoriumSteal. ^[strings.txt:1365,1540,5474] Base64 encoding/decoding (26 capa matches). ^[capa.txt]


C2 Infrastructure

No hardcoded URLs, IPs, or webhook endpoints recovered in static strings. The C2 configuration is runtime-decrypted by AesxorModule or passed via the named-pipe bootstrap. The primary twin ed94635a was observed beaconing to 194.87.242.28:4133 (MessagePack over TCP, AES-256-GCM transport) — see raw/analyses/ed94635a.../report.md. This sample is expected to use the same infrastructure or a rotation within the same panel.

Static C2 artifacts:

  • PulsarMessagePackSerializer — MessagePack-framed commands. ^[strings.txt:6752]
  • NamedPipeServerStream + PipeStream — IPC transport. ^[strings.txt:4360,5389]
  • System.Net.Sockets.TcpClient implied by capa TCP socket matches. ^[capa.txt]
  • HTTP client surface: set HTTP User-Agent, set web proxy, create HTTP request. ^[capa.txt]

Interesting Tidbits

  • "masslogger" is a ghost: The only sample in the corpus tagged masslogger. The OpenCTI label masslogger is a false-positive family ascription; the static fingerprint is pure ChromeLoader/Pulsar. ^[metadata.json, triage.json]
  • Twin confirmation: ssdeep near-match (differs by first character only), identical PE timestamp, identical .text hash, identical class/method names — same source tree, different resource manifest. ^[ssdeep.txt, pefile.txt]
  • Masquerade variance: wmplayer.exe (Media Player) vs Acrobat.exe (Adobe PDF). Both use plausible, widely-trusted vendor identities. The builder likely randomizes or campaign-selects the masquerade at compile time.
  • Icon resources: Two high-resolution PNGs in .rsrc (256×256 and 512×512) ^[binwalk.txt] — unusual for a stealer/RAT and likely chosen to reinforce the Media Player masquerade in Explorer thumbnails and taskbar previews.
  • No CAPE detonation: No Windows guest available at time of triage; all TTPs inferred from static strings + capa. ^[dynamic-analysis.md]

Deployable Signatures

YARA Rule

The primary sample's YARA rule (from 94682a96) matches this twin verbatim. A streamlined version follows:

rule ChromeloaderPulsar_RAT
{
    meta:
        description = "ChromeLoader / Pulsar .NET RAT with Pulsar.Common v2.4.5.0"
        author      = "PacketPursuit"
        date        = "2026-08-04"
        hash        = "ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7"
        family      = "chromeloader-pulsar-rat"

    strings:
        $pulsar_common = "Pulsar.Common" ascii wide
        $pulsar_msgpack = "PulsarMessagePackSerializer" ascii wide
        $chrome_loader  = "ChromeLoader" ascii wide
        $aesxor_module  = "AesxorModule" ascii wide
        $start_pipe     = "StartPipeServerAsync" ascii wide
        $stealth_inject = "StealthInjector" ascii wide
        $reflective     = "ReflectiveLoader" ascii wide
        $msgpack_v      = "costura.messagepack.dll.compressed" ascii wide
        $pulsar_dll     = "costura.pulsar.common.dll.compressed" ascii wide
        $tokens_grab    = "TokensGrabber" ascii wide
        $files_grab     = "FilesGrabber" ascii wide
        $chrome_wallet  = "GetChromeWallets" ascii wide
        $gecko_wallet   = "GetGeckoWallets" ascii wide
        $chrome_decrypt = "chrome_decrypt.dll" ascii wide

    condition:
        uint16(0) == 0x5a4d and
        ( $pulsar_common or $chrome_loader ) and
        ( $reflective or $stealth_inject or $start_pipe ) and
        ( $tokens_grab or $files_grab or $chrome_wallet )
}

Behavioral Hunt Query (Sigma-like)

title: ChromeLoader Pulsar Named Pipe C2 and Injection
logsource:
  product: windows
detection:
  selection_pipe:
    - Image|endswith:
      - '\\wmplayer.exe'
      - '\\Acrobat.exe'
    - CommandLine|contains:
      - 'NamedPipeServerStream'
      - 'GenerateUniquePipeName'
  selection_inject:
    - CallTrace|contains:
      - 'VirtualAllocEx'
      - 'WriteProcessMemory'
      - 'CreateRemoteThread'
    - TargetImage|endswith:
      - '\\svchost.exe'
      - '\\explorer.exe'
      - '\\RuntimeBroker.exe'
  selection_registry:
    - EventType: SetValue
    - TargetObject|contains:
      - '\\Software\\Microsoft\\Windows\\CurrentVersion\\Run'
    - Details|contains:
      - 'ChromeLoader'
      - 'Pulsar'
      - 'wmplayer'
      - 'Acrobat'
  condition: 1 of selection*
falsepositives:
  - Unknown
level: high

IOC List

Type Value Notes
SHA-256 ca687401049c4fae9fc3d278008361f470f79dcdc20fda5e9e4c482d2a9c7df7 This twin
SHA-256 94682a961e8a61b5a4b34e689de98f0a89b5e8c75bdfc493ed796c29a6b03536 Primary twin
SHA-256 ed94635a2348ca2e8c9c53a46336b14be509ce0a19c2521d50f9976470096ab1 Cluster member with observed C2
ssdeep 24576:8fedx38vxbIRxJzck+uGW/yFoBkkAxg2jFjHmGOpy+X9zAE5Fw:8fex33RTYjqqanRaXOQ+ Twin
Mutex MutexControl Observed in strings ^[strings.txt]
Pipe name GenerateUniquePipeName Dynamic pipe generation ^[strings.txt]
Registry HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run Startup persistence
File chrome_decrypt.dll Embedded browser decryption module ^[strings.txt]
File chrome_decrypt_lite.dll Lite variant ^[strings.txt]
Module Pulsar.Common.dll v2.4.5.0 Core framework DLL ^[strings.txt]
Module MessagePack.dll v3.1.4.0 Serialization layer ^[strings.txt]
C2 (observed in cluster) 194.87.242.28:4133 From ed94635a dynamic analysis

Behavioral Fingerprint

This binary is a .NET Framework PE32 with a minimal native import table (mscoree._CorExeMain only) and a high-entropy .rsrc section containing Costura.Fody-compressed DLLs. At runtime it decompresses Pulsar.Common.dll and MessagePack.dll, initializes a NamedPipeServerStream, and decrypts C2 config via AesxorModule. It enumerates browser SQLite stores (Chrome, Firefox, Yandex, CryptoTab), extracts credentials with chrome_decrypt.dll, harvests Discord/Telegram tokens, captures screenshots and audio via WasapiCapture, and exfiltrates over MessagePack-serialized TCP or HTTP. Process injection is performed through StealthInjector using VirtualAllocEx / WriteProcessMemory / CreateRemoteThread. Persistence is achieved via Registry Run keys and scheduled tasks.


Detection Signatures (capa → ATT&CK)

See capa.txt for 330+ capability matches. The mapping is identical to the primary 94682a96 sample. Notable dense clusters:

  • Communication: 6× receive data, 6× send data, TCP socket, named-pipe creation, HTTP request/response. ^[capa.txt]
  • Process injection: DLL injection, thread hijacking, reflective loading, VirtualAllocEx + WriteProcessMemory + CreateRemoteThread. ^[capa.txt]
  • Collection: Screenshot (2), keylog (3), clipboard (4), password manager (KeeFarce), audio/video capture. ^[capa.txt]
  • Anti-analysis: Debugger checks (5), VM checks (4), parent-PID spoofing, self-deletion. ^[capa.txt]

References

  • Sample source: OpenCTI / MalwareBazaar (artifact 2e5f5458-29bc-4745-910f-522b1c5d52c2)
  • Twin sample: 94682a961e8a61b5a4b34e689de98f0a89b5e8c75bdfc493ed796c29a6b03536
  • Cluster member: ed94635a2348ca2e8c9c53a46336b14be509ce0a19c2521d50f9976470096ab1
  • Entity page: chromeloader-pulsar-rat
  • Distribution label: gcleaner

Provenance

  • file.txt — file type and header
  • pefile.txt — PE structure, imports, sections, resource directory
  • strings.txt — .NET metadata strings, class names, method names
  • floss.txt — decoded stacked strings (minimal additional findings; tool argument error)
  • capa.txt — Mandiant capa v7 static capability detection
  • binwalk.txt — embedded file signatures (PNG icons, SQLite, AES S-Box)
  • rabin2-info.txt — radare2 binary header (CIL, PE32, compiled 2045-05-10)
  • exiftool.json — VS_VERSIONINFO masquerade metadata
  • metadata.json — OpenCTI labels (masslogger, dropped-by-gcleaner, us.file)
  • triage.json — original (incorrect) masslogger family label
  • dynamic-analysis.md — CAPE skipped (no Windows guest)

Report generated 2026-08-04. Static-only analysis; no dynamic execution data available.