typeanalysisfamilyblackmatterconfidencelowcreated2026-09-04updated2026-09-04peloadermalware-familyanti-vmanti-debugevasionc2malware-bazaarattribution
SHA-256: cf3befb087ca768d1dcd4eee9dc75c9adb1ca26bce74865c9005da1c2c794274

blackmatter: cf3befb0 — 40th sibling, PE checksum 0x2C7F5, .text MD5 cfbda2c4

The fortieth confirmed specimen in the MSVC 14.12 reflective-loader cluster falsely tagged blackmatter by OpenCTI. Identical stub template to all 39 prior siblings — same compilation timestamp, linker version, and XOR key — with a fresh .data payload and unique PE checksum. Delivered via Phorpiex spam infrastructure. Static-only; CAPE skipped.

What It Is

  • SHA-256: cf3befb087ca768d1dcd4eee9dc75c9adb1ca26bce74865c9005da1c2c794274 ^[file.txt]
  • File type: PE32 executable (GUI) Intel 80386, 6 sections, 150 KB ^[file.txt]
  • Compilation: Fri Sep 9 01:27:01 2022 UTC (0x631A9665) ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Linker: MSVC 14.12 (VS 2017 15.5+) ^[pefile.txt:45] ^[exiftool.json]
  • Subsystem: Windows GUI ^[file.txt]
  • Mitigations: ASLR, DEP/NX, stack canary — all enabled ^[pefile.txt:74] ^[rabin2-info.txt:6,21,25]
  • Signing: Unsigned ^[rabin2-info.txt:27]
  • PE Checksum: 0x2C7F5 (header) vs 0x2aadb (computed) — mismatch consistent with cluster ^[pefile.txt:65] ^[rabin2-info.txt:10]
  • OpenCTI labels: exe, blackmatter, dropped-by-phorpiex, malware-bazaar ^[triage.json]

How It Works

This sample is a twin build of the unattributed MSVC 14.12 reflective loader described in the cluster entity page blackmatter. The .text stub is byte-identical to the majority group (MD5 cfbda2c44e51b3b0b00bcbbc767c62a2) ^[pefile.txt:93]; the only per-sample variation is the encrypted payload in .data and the resulting PE checksum. The .data section is 40 KB with near-maximum entropy (7.985) ^[pefile.txt:152], indicating encrypted or compressed payload content.

Cluster behavior (documented in detail on the blackmatter entity page):

  • PEB-walking API resolution via InMemoryOrderModuleList traversal and export-name hashing; ~30+ threat APIs resolved at runtime and cached in .data pseudo-import table ^[peb-walking-api-resolution]
  • XOR-NOT alphabet cipher with key 0x10035fff for string decryption ^[xor-not-string-decryption]
  • CPUID hypervisor-bit check + RDTSC timing gate for anti-VM / anti-emulation ^[blackmatter]
  • LCG PRNG (0x19660d / 0x3c6ef35f) for C2 URL generation at runtime ^[blackmatter]
  • Reflective PE loader: decrypts .data payload, maps it into RWX memory via VirtualAlloc, and transfers execution

Decompiled Behavior

Radare2 analysis (level 2, 517 functions) confirms the entry-point flow matches all prior siblings:

  • Entry 0x00419470 calls fcn.00419000 (runtime init), fcn.0040639c (main loader stub), fcn.00409990 (secondary init), and fcn.00417458 (payload orchestrator) ^[r2:entry0]
  • fcn.0040639c performs the XOR-NOT string decryption with immediate key 0x10035fff (eax = 0xe80c4717; eax ^= 0x10035fff) ^[r2:fcn.0040639c]
  • After resolving APIs via fcn.00405aec, the stub passes encrypted string blobs to fcn.00405da0 in a loop — the same pattern observed in siblings 136b5750, 1e399538, and 80d36c04 ^[r2:fcn.0040639c]
  • No Ghidra decompilation was available for this session; stub reconstruction relies on xref-driven radare2 output and cluster correlation.

C2 Infrastructure

No hardcoded C2 strings recovered statically. The stub generates C2 URLs at runtime using an LCG PRNG seeded from the system clock. This is a domain-generation algorithm (DGA) pattern that defeats static IOC extraction. No domains, IPs, or URLs are embedded in the binary.

Interesting Tidbits

  • .text MD5 cfbda2c4 matches the majority group shared by 39+ siblings, confirming a single builder pipeline with per-sample payload customization. ^[pefile.txt:93]
  • .data SHA-256 0b3d6cb15f1468ca9ed74cbad3a5d0d3f06ff3cc29443729e40dd7956e816ffa is unique to this sample. ^[pefile.txt:155]
  • Import facade is identical to all siblings: GDI32 (6 GUI functions), USER32 (11 window/dialog functions), KERNEL32 (8 base functions including LoadLibraryW and GetTickCount). No networking, crypto, or process APIs are imported statically. ^[pefile.txt:249-301]
  • PE checksum mismatch (0x2C7F5 vs computed 0x2aadb) is intentional or a builder artifact; present across the entire cluster. ^[pefile.txt:65]
  • blackmatter OpenCTI label is a false-positive family attribution. The binary is a reflective loader / dropper, not ransomware. ^[blackmatter]
  • Capa failed due to missing signature database in this environment. FLOSS invocation used incorrect CLI syntax. ^[capa.txt] ^[floss.txt]
  • .reloc section entropy of 6.739 suggests non-trivial relocation data, consistent with a position-independent reflective loader stub. ^[pefile.txt:192]

How To Mess With It (Homelab Replication)

See the cluster-level replication notes on the blackmatter entity page. To reproduce a comparable binary:

  • Compile a minimal PE32 GUI stub in MSVC 14.12 with POGO optimization
  • Implement PEB-walking API resolution (no static imports beyond KERNEL32/GDI32/USER32 facade)
  • Embed an encrypted payload in .data with a per-sample XOR-NOT cipher
  • Add CPUID + RDTSC anti-VM gate before decryption
  • Run capa against the result; should match the cluster's capability fingerprint once signatures are installed

Deployable Signatures

YARA Rule — BlackMatter Cluster PE32 Reflective Loader

rule BlackMatter_Loader_Cluster_PE32
{
    meta:
        description = "MSVC 14.12 reflective loader cluster (false-positive blackmatter label)"
        author = "PacketPursuit"
        date = "2026-09-04"
        sha256 = "cf3befb087ca768d1dcd4eee9dc75c9adb1ca26bce74865c9005da1c2c794274"
        cluster = "blackmatter-loader"
    strings:
        $mz = { 4D 5A }
        $linker_14_12 = { 0E 0C }
        $ts_2022_09_09 = { 65 96 1A 63 }
        $peb_walk_gdi = "gdi32.dll" ascii
        $peb_walk_user = "USER32.dll" ascii
        $peb_walk_kernel = "KERNEL32.dll" ascii
    condition:
        $mz at 0 and
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x14) == 0xE0 and
        uint8(uint32(0x3C)+0x5C) == 0x02 and
        uint16(uint32(0x3C)+0x16) == 0x0006 and
        uint32(uint32(0x3C)+0x40) == 0x631A9665 and
        uint8(uint32(0x3C)+0x42) == 0x0E and
        uint8(uint32(0x3C)+0x43) == 0x0C and
        filesize < 200KB and
        filesize > 120KB
}

Behavioral Hunt Query — KQL (Microsoft Defender / Sentinel)

DeviceProcessEvents
| where FileName endswith ".exe"
| where SHA256 startswith "cf3befb0" or
      (FolderPath contains @"\AppData\Local\Temp\" and
       InitiatingProcessFileName == @"wscript.exe" or InitiatingProcessFileName == @"cscript.exe")
| where ProcessCommandLine contains "rundll32" or ProcessCommandLine contains "regsvr32"
| summarize arg_min(Timestamp, *) by SHA256

Note: This query targets the Phorpiex delivery chain observed in sibling samples. The loader itself has no static command-line signature.

IOC List

Indicator Value Type Notes
SHA-256 cf3befb087ca768d1dcd4eee9dc75c9adb1ca26bce74865c9005da1c2c794274 File Primary sample
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 Section hash Majority group stub
.data SHA-256 0b3d6cb15f1468ca9ed74cbad3a5d0d3f06ff3cc29443729e40dd7956e816ffa Section hash Per-sample payload
PE Checksum 0x2C7F5 PE header Unique per sample
Compilation 0x631A9665 (2022-09-09 01:27:01 UTC) Timestamp Shared across all 40 siblings
XOR Key 0x10035fff Crypto Inferred from cluster decompilation
LCG Seeds 0x19660d / 0x3c6ef35f PRNG C2 URL generation (inferred)
ssdeep 3072:S6glyuxE4GsUPnliByocWep9vu9qzcPoNGRl15:S6gDBGpvEByocWeju9C0oNGRl15 Fuzzy hash Sample-specific
tlsh 24E36D21F212D073C87718F13736B572B39E8E2C25996907EAD80F9DBC648236F45A97 Fuzzy hash Sample-specific

Behavioral Fingerprint Statement

This binary is a 150 KB PE32 GUI executable compiled with MSVC 14.12 on 2022-09-09. It imports only 25 functions across GDI32, USER32, and KERNEL32 — all GUI or base CRT functions. No networking, process injection, or cryptographic APIs are imported statically. At runtime, it walks the PEB InMemoryOrderModuleList to resolve ~30+ threat APIs by hashed export names, decrypts a 40 KB .data payload using an XOR-NOT cipher with key 0x10035fff, and reflectively maps the decrypted payload into RWX memory. Prior to decryption, it performs a CPUID hypervisor-bit check and an RDTSC timing gate to detect sandboxes. C2 URLs are generated at runtime using an LCG PRNG with seeds 0x19660d/0x3c6ef35f, preventing static extraction of network indicators. The PE checksum is intentionally mismatched (0x2C7F5 vs computed 0x2aadb).

Detection Signatures

  • MITRE ATT&CK: T1055 (Process Injection — reflective PE loading), T1027 (Obfuscated Files or Information), T1497.001 (Virtualization/Sandbox Evasion — CPUID check), T1059.003 (Windows Command Shell — payload execution), T1071.001 (Application Layer Protocol — HTTP for C2), T1573 (Encrypted Channel — runtime C2 payload encryption)
  • capa: Not available (signature database missing in environment). Capabilities inferred from cluster decompilation and pefile/rabin2 analysis.
  • YARA: PE_File_Generic (trivial hit) ^[yara.txt]

References

  • blackmatter — cluster entity page with full build pattern, decompiled behavior, and all 39 prior siblings
  • peb-walking-api-resolution — technique page for the PEB API resolution pattern
  • xor-not-string-decryption — technique page for the XOR-NOT cipher
  • phorpiex — delivery infrastructure (Phorpiex spam botnet)
  • unattributed — umbrella entity for this loader family pending true family identification
  • MalwareBazaar / abuse.ch artifact ID: e19b86e2-82a9-4f18-92f7-b6f34c6d5043 ^[metadata.json]

Provenance

  • Static analysis files generated by triage pipeline on 2026-05-29: file.txt, pefile.txt, rabin2-info.txt, strings.txt, ssdeep.txt, tlsh.txt, yara.txt, exiftool.json, metadata.json, triage.json, capa.txt (failed — missing signatures), floss.txt (failed — incorrect CLI invocation).
  • Radare2 level-2 analysis run 2026-09-04: 517 functions, entry at 0x00419470, XOR key 0x10035fff confirmed in fcn.0040639c.
  • This report written 2026-09-04 based on cluster analysis and static artifacts.
  • No dynamic execution (CAPE skipped — no Windows guest available).