typeanalysisfamilyblackmatterconfidencemediumcreated2026-07-30updated2026-07-30pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: cdc7d79ae4215dccf60882afb6c3abee6b95d9db7c1587746fc8d533d1631e9d

blackmatter: cdc7d79a — thirteenth confirmed sibling of MSVC 14.12 reflective-loader cluster

Executive Summary

Thirteenth confirmed sibling in the MSVC 14.12 PE32 reflective-loader cluster (see [blackmatter](/intel/families/blackmatter.html) entity page and primary analysis at */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html*). All twelve prior siblings share an identical stub — same compilation timestamp, linker version, .text section hash, XOR-NOT alphabet cipher, PEB-walking API resolution, CPUID anti-VM, and LCG PRNG. The only per-sample deltas are PE checksum, .data payload hash, and .pdata runtime tables — consistent with a builder pipeline that injects individualized encrypted payloads into a shared template. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 cdc7d79ae4215dccf60882afb6c3abee6b95d9db7c1587746fc8d533d1631e9d
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Static imports Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI housekeeping ^[pefile.txt:249]
YARA Generic PE only; no family-specific hits ^[yara.txt]
ssdeep 3072:R6glyuxE4GsUPnliByocWepaAShLlvg8hHatY2:R6gDBGpvEByocWeMAMhgqatL ^[ssdeep.txt]
TLSH 73E36D21F212D0B3C87718F13736B5B1B3DE8E6C19A96807EAD80F59BCA48232F55597 ^[tlsh.txt]

Cluster Deltas (this sample vs siblings)

All confirmed siblings share these immutable traits:

  • Compilation timestamp 0x631A9665
  • Linker version 14.12
  • .text section MD5 cfbda2c44e51b3b0b00bcbbc767c62a2
  • XOR key 0x10035fff
  • LCG multiplier 0x19660d, increment 0x3c6ef35f
  • Alphabet table decrypts to A-Z a-z 0-9 via 0x401240 XOR-NOT routine
  • CPUID anti-VM at 0x4010bc
  • PEB-walking API resolution in main orchestrator

Per-sample deltas for cdc7d79a:

Field This Sample Sibling 136b5750 Sibling 9d8526b0 Sibling a2dca6ef
PE checksum 0x000326E1 0x0002BC5A 0x00032784 0x00028FB1
Full MD5 50b2838c53073e2ba3b97befe6880e94 4dbac1f6... d8c2f3a6... 91e4c3b2...
.data MD5 6f4cd57381bb5584c0a0755384d25180 b3e9a1c2... a7f8d3e1... c4a2b8f1...
.pdata MD5 a4bf7e58ee7cd02c27650fe6b824eb9c — — —

The .data and .pdata section hashes differ because each sample carries an individualized encrypted payload and corresponding runtime function tables. The .text section is bit-for-bit identical across all siblings.

How It Works

This sample does not differ functionally from the cluster template. For full behavioral narrative, see the primary analysis:

  • */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html*

Key behaviors confirmed in this binary via radare2 disassembly:

  • Entry point at 0x419470 delegates to main orchestrator fcn.00417034. ^[r2:entry0]
  • XOR-NOT decrypt routine at 0x401240: xor dword [ecx], 0x10035fff → not dword [ecx] in a loop. Called from 0x40d4b0 to decrypt the alphabet table. ^[r2:0x401240]
  • LCG PRNG at 0x40110c: seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. ^[r2:0x40110c]
  • Anti-VM gate at 0x4010bc: CPUID leaf 1 ECX[31] hypervisor bit, leaf 7 EBX[18], RDTSC rotate-13 timing. ^[r2:0x4010bc]
  • Alphabet builder at 0x40d4b0: pushes 16 encrypted DWORDs (same values as 136b5750: 0xabbfe241, 0xa7bbe645, 0xa3b7ea49, etc.), calls 0x401240 with count 0x10, producing the base-62 alphabet. ^[r2:0x40d4b0]

No novel functions, no altered constants, no extra sections. This is a pure template clone with individualized payload.

C2 Infrastructure

No hard-coded C2 endpoints survive in the binary. C2 domain, path, and User-Agent are generated at runtime via the LCG PRNG and base-62 alphabet table. For inference details, see the primary analysis 136b5750. Static-only.

Interesting Tidbits

  • Thirteenth sibling: Brings the confirmed cluster to n=13. The .text section hash remains invariant, confirming a single compiled stub reused across the campaign. ^[r2:0x401240]
  • Builder pipeline signature: The fact that only .data/.pdata and PE checksum vary while .text is frozen strongly suggests an automated builder that encrypts per-sample payloads and patches headers, rather than recompiling from source each time.
  • OpenCTI label dropped-by-phorpiex: Delivery infrastructure label, not payload family. The loader itself is not Phorpiex-authored (toolchain mismatch: MSVC 14.12 vs Delphi/VCL or MinGW seen in Phorpiex droppers). ^[metadata.json]
  • GUI subsystem decoy: Declares Windows GUI but contains no window-creation logic. USER32/GDI32 imports are minimal scaffolding. ^[file.txt]

Deployable Signatures

YARA Rule

rule blackmatter_cdc7d79a_msvc_reflective_loader
{
    meta:
        description = "PE32 MSVC 14.12 reflective loader cluster — thirteenth confirmed sibling"
        author = "PacketPursuit"
        date = "2026-07-30"
        sha256 = "cdc7d79ae4215dccf60882afb6c3abee6b95d9db7c1587746fc8d533d1631e9d"
    strings:
        $xor_not_key = { 81 31 FF 5F 03 10 }
        $lcg_mul = { B9 0D 66 19 00 }
        $lcg_inc = { 05 5F F3 6E 3C }
        $lcg_mask = { 25 FF FF FF 07 }
        $alphabet_1 = { C7 00 41 E2 BF AB }
        $alphabet_2 = { C7 40 04 45 E6 BB A7 }
        $alphabet_3 = { C7 40 08 49 EA B7 A3 }
        $cpuid_leaf1 = { 6A 01 58 0F A2 F7 C1 00 00 00 40 }
        $cpuid_leaf7 = { 6A 07 58 33 C9 0F A2 F7 C3 00 00 04 00 }
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + 0x18) == 0x10B and
        4 of ($xor_not_key, $lcg_mul, $lcg_inc, $lcg_mask) and
        2 of ($alphabet_*) and
        1 of ($cpuid_*)
}

Behavioral Fingerprint

This binary loads with a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within the first 5 seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by hash. It allocates RWX memory, copies a decrypted payload into it, and spawns a file-system enumeration thread (FindFirstFile with "*" wildcard) alongside a network thread that assembles an HTTP POST request. The POST body is encrypted with a session key imported via CryptImportKey. C2 domain and User-Agent are generated at runtime using a seeded LCG PRNG and a base-62 alphabet table. If executed inside a VM, CPUID leaf 1 ECX[31] or leaf 7 EBX[18] hypervisor bits cause altered code paths or early termination.

IOCs

Indicator Value Notes
SHA-256 cdc7d79ae4215dccf60882afb6c3abee6b95d9db7c1587746fc8d533d1631e9d This sample
SHA-1 2de73dca581ed0f4bb0308da1e3c8a3f0fa7fad6 Full file
MD5 50b2838c53073e2ba3b97befe6880e94 Full file
Compilation Sep 9 2022 01:27:01 UTC Timestamp 0x631A9665 (shared)
Linker 14.12 VS 2017 15.5+ (shared)
TLSH 73E36D21F212D0B3C87718F13736B5B1B3DE8E6C19A96807EAD80F59BCA48232F55597 This sample
PE checksum 0x000326E1 Per-sample delta
XOR Key 0x10035fff Shared
LCG multiplier 0x19660d Shared
LCG increment 0x3c6ef35f Shared
Anti-VM CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 Shared
.text section MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 Shared — frozen stub

Detection Signatures

ATT&CK Technique Implementation
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation (shared stub)
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution (shared stub)
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation (shared stub)
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) (shared stub)
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate (shared stub)
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile (shared stub)
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body (shared stub)
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling (shared stub)

References

  • OpenCTI artifact: 4fac5873-0447-440e-a005-a0dc20fbad69, labels: dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
  • Primary cluster analysis: */intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html*
  • Cluster entity page: [blackmatter](/intel/families/blackmatter.html)
  • Technique page: [peb-walking-api-resolution](/intel/techniques/peb-walking-api-resolution.html)

Provenance

Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt) and radare2 disassembly of the binary at <sample cdc7d79ae421.bin>. CAPA and floss failed due to missing signature database and incorrect CLI invocation, respectively. CAPE dynamic analysis skipped — no Windows guest available. All behavioral claims are statically inferred and reference the primary 136b5750 analysis where the stub was first decompiled in detail.