cdc7d79ae4215dccf60882afb6c3abee6b95d9db7c1587746fc8d533d1631e9dblackmatter: cdc7d79a — thirteenth confirmed sibling of MSVC 14.12 reflective-loader cluster
Executive Summary
Thirteenth confirmed sibling in the MSVC 14.12 PE32 reflective-loader cluster (see [blackmatter](/intel/families/blackmatter.html) entity page and primary analysis at */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html*). All twelve prior siblings share an identical stub — same compilation timestamp, linker version, .text section hash, XOR-NOT alphabet cipher, PEB-walking API resolution, CPUID anti-VM, and LCG PRNG. The only per-sample deltas are PE checksum, .data payload hash, and .pdata runtime tables — consistent with a builder pipeline that injects individualized encrypted payloads into a shared template. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | cdc7d79ae4215dccf60882afb6c3abee6b95d9db7c1587746fc8d533d1631e9d |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68] |
| Canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Static imports | Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI housekeeping ^[pefile.txt:249] |
| YARA | Generic PE only; no family-specific hits ^[yara.txt] |
| ssdeep | 3072:R6glyuxE4GsUPnliByocWepaAShLlvg8hHatY2:R6gDBGpvEByocWeMAMhgqatL ^[ssdeep.txt] |
| TLSH | 73E36D21F212D0B3C87718F13736B5B1B3DE8E6C19A96807EAD80F59BCA48232F55597 ^[tlsh.txt] |
Cluster Deltas (this sample vs siblings)
All confirmed siblings share these immutable traits:
- Compilation timestamp
0x631A9665 - Linker version 14.12
.textsection MD5cfbda2c44e51b3b0b00bcbbc767c62a2- XOR key
0x10035fff - LCG multiplier
0x19660d, increment0x3c6ef35f - Alphabet table decrypts to
A-Z a-z 0-9via0x401240XOR-NOT routine - CPUID anti-VM at
0x4010bc - PEB-walking API resolution in main orchestrator
Per-sample deltas for cdc7d79a:
| Field | This Sample | Sibling 136b5750 |
Sibling 9d8526b0 |
Sibling a2dca6ef |
|---|---|---|---|---|
| PE checksum | 0x000326E1 |
0x0002BC5A |
0x00032784 |
0x00028FB1 |
| Full MD5 | 50b2838c53073e2ba3b97befe6880e94 |
4dbac1f6... |
d8c2f3a6... |
91e4c3b2... |
.data MD5 |
6f4cd57381bb5584c0a0755384d25180 |
b3e9a1c2... |
a7f8d3e1... |
c4a2b8f1... |
.pdata MD5 |
a4bf7e58ee7cd02c27650fe6b824eb9c |
— | — | — |
The .data and .pdata section hashes differ because each sample carries an individualized encrypted payload and corresponding runtime function tables. The .text section is bit-for-bit identical across all siblings.
How It Works
This sample does not differ functionally from the cluster template. For full behavioral narrative, see the primary analysis:
*/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html*
Key behaviors confirmed in this binary via radare2 disassembly:
- Entry point at
0x419470delegates to main orchestratorfcn.00417034. ^[r2:entry0] - XOR-NOT decrypt routine at
0x401240:xor dword [ecx], 0x10035fff→not dword [ecx]in a loop. Called from0x40d4b0to decrypt the alphabet table. ^[r2:0x401240] - LCG PRNG at
0x40110c:seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. ^[r2:0x40110c] - Anti-VM gate at
0x4010bc: CPUID leaf 1 ECX[31] hypervisor bit, leaf 7 EBX[18], RDTSC rotate-13 timing. ^[r2:0x4010bc] - Alphabet builder at
0x40d4b0: pushes 16 encrypted DWORDs (same values as136b5750:0xabbfe241,0xa7bbe645,0xa3b7ea49, etc.), calls0x401240with count0x10, producing the base-62 alphabet. ^[r2:0x40d4b0]
No novel functions, no altered constants, no extra sections. This is a pure template clone with individualized payload.
C2 Infrastructure
No hard-coded C2 endpoints survive in the binary. C2 domain, path, and User-Agent are generated at runtime via the LCG PRNG and base-62 alphabet table. For inference details, see the primary analysis 136b5750. Static-only.
Interesting Tidbits
- Thirteenth sibling: Brings the confirmed cluster to n=13. The
.textsection hash remains invariant, confirming a single compiled stub reused across the campaign. ^[r2:0x401240] - Builder pipeline signature: The fact that only
.data/.pdataand PE checksum vary while.textis frozen strongly suggests an automated builder that encrypts per-sample payloads and patches headers, rather than recompiling from source each time. - OpenCTI label
dropped-by-phorpiex: Delivery infrastructure label, not payload family. The loader itself is not Phorpiex-authored (toolchain mismatch: MSVC 14.12 vs Delphi/VCL or MinGW seen in Phorpiex droppers). ^[metadata.json] - GUI subsystem decoy: Declares
Windows GUIbut contains no window-creation logic. USER32/GDI32 imports are minimal scaffolding. ^[file.txt]
Deployable Signatures
YARA Rule
rule blackmatter_cdc7d79a_msvc_reflective_loader
{
meta:
description = "PE32 MSVC 14.12 reflective loader cluster — thirteenth confirmed sibling"
author = "PacketPursuit"
date = "2026-07-30"
sha256 = "cdc7d79ae4215dccf60882afb6c3abee6b95d9db7c1587746fc8d533d1631e9d"
strings:
$xor_not_key = { 81 31 FF 5F 03 10 }
$lcg_mul = { B9 0D 66 19 00 }
$lcg_inc = { 05 5F F3 6E 3C }
$lcg_mask = { 25 FF FF FF 07 }
$alphabet_1 = { C7 00 41 E2 BF AB }
$alphabet_2 = { C7 40 04 45 E6 BB A7 }
$alphabet_3 = { C7 40 08 49 EA B7 A3 }
$cpuid_leaf1 = { 6A 01 58 0F A2 F7 C1 00 00 00 40 }
$cpuid_leaf7 = { 6A 07 58 33 C9 0F A2 F7 C3 00 00 04 00 }
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C) + 0x18) == 0x10B and
4 of ($xor_not_key, $lcg_mul, $lcg_inc, $lcg_mask) and
2 of ($alphabet_*) and
1 of ($cpuid_*)
}
Behavioral Fingerprint
This binary loads with a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within the first 5 seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by hash. It allocates RWX memory, copies a decrypted payload into it, and spawns a file-system enumeration thread (FindFirstFile with "*" wildcard) alongside a network thread that assembles an HTTP POST request. The POST body is encrypted with a session key imported via CryptImportKey. C2 domain and User-Agent are generated at runtime using a seeded LCG PRNG and a base-62 alphabet table. If executed inside a VM, CPUID leaf 1 ECX[31] or leaf 7 EBX[18] hypervisor bits cause altered code paths or early termination.
IOCs
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | cdc7d79ae4215dccf60882afb6c3abee6b95d9db7c1587746fc8d533d1631e9d |
This sample |
| SHA-1 | 2de73dca581ed0f4bb0308da1e3c8a3f0fa7fad6 |
Full file |
| MD5 | 50b2838c53073e2ba3b97befe6880e94 |
Full file |
| Compilation | Sep 9 2022 01:27:01 UTC | Timestamp 0x631A9665 (shared) |
| Linker | 14.12 | VS 2017 15.5+ (shared) |
| TLSH | 73E36D21F212D0B3C87718F13736B5B1B3DE8E6C19A96807EAD80F59BCA48232F55597 |
This sample |
| PE checksum | 0x000326E1 |
Per-sample delta |
| XOR Key | 0x10035fff |
Shared |
| LCG multiplier | 0x19660d |
Shared |
| LCG increment | 0x3c6ef35f |
Shared |
| Anti-VM | CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 | Shared |
.text section MD5 |
cfbda2c44e51b3b0b00bcbbc767c62a2 |
Shared — frozen stub |
Detection Signatures
| ATT&CK Technique | Implementation |
|---|---|
| T1055 — Process Injection | Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation (shared stub) |
| T1071.001 — Application Layer Protocol: Web Protocols | HTTP POST C2 with encrypted body; WinInet API resolution (shared stub) |
| T1027 — Obfuscated Files or Information | XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation (shared stub) |
| T1497.001 — Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) (shared stub) |
| T1497.002 — Virtualization/Sandbox Evasion: User Activity Based | RDTSC differential timing gate (shared stub) |
| T1083 — File and Directory Discovery | Recursive "*" enumeration via FindFirstFile / FindNextFile (shared stub) |
| T1573.001 — Encrypted Channel: Symmetric Cryptography | CryptEncrypt / CryptDecrypt for C2 payload body (shared stub) |
| T1105 — Ingress Tool Transfer | Downloader / payload retrieval via HTTP POST response handling (shared stub) |
References
- OpenCTI artifact:
4fac5873-0447-440e-a005-a0dc20fbad69, labels:dropped-by-phorpiex,exe,malware-bazaar^[metadata.json] - Primary cluster analysis:
*/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html* - Cluster entity page:
[blackmatter](/intel/families/blackmatter.html) - Technique page:
[peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html)
Provenance
Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt) and radare2 disassembly of the binary at <sample cdc7d79ae421.bin>. CAPA and floss failed due to missing signature database and incorrect CLI invocation, respectively. CAPE dynamic analysis skipped — no Windows guest available. All behavioral claims are statically inferred and reference the primary 136b5750 analysis where the stub was first decompiled in detail.