typeanalysisfamilyblackmatterconfidencelowcreated2026-09-04updated2026-09-04pemalware-familyloaderreflective-pe-loadermsvcpogoanti-vmpeb-walkingxor-notlcg-prngdropped-by-phorpiex
SHA-256: d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973

blackmatter: d715b248 — forty-first confirmed sibling in MSVC 14.12 reflective-loader cluster

Executive Summary: PE32 GUI reflective loader compiled Sep 9 2022 with MSVC 14.12 and POGO optimization. This sample was the sixth entry in the cluster table (previously triage-only) and is now promoted to analysed status. It shares the identical stub template with forty prior siblings; the only delta is the encrypted .data payload (unique hash, entropy 7.986) and PE checksum (0x263B2). No runtime behavior available — CAPE skipped due to no Windows guest.

What It Is

Field Value
SHA-256 d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973
File type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Size 149,504 bytes (150 KB)
Compile stamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Linker MSVC 14.12 (VS 2017 15.5+) ^[pefile.txt:45]
Optimization POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
Subsystem Windows GUI ^[rabin2-info.txt:32]
Entry point 0x1946F (RVA) / 0x41946f (VA) ^[pefile.txt:50]
ASLR / DEP Enabled (DllCharacteristics: 0x8140) ^[pefile.txt:67]
Stack canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned (signed: false) ^[rabin2-info.txt:27]
OpenCTI labels blackmatter, dropped-by-phorpiex, exe, malware-bazaar ^[triage.json]

How It Works

This sample is a cluster sibling of the MSVC 14.12 reflective-loader family. The stub — entry point, PEB-walking API resolution, anti-analysis gates, and payload decryption — is byte-identical to the forty prior siblings. The threat payload is individualized per-sample via encrypted contents in the .data section.

For the full build-stack and behavioral analysis of this family, see the primary report:

  • /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT alphabet cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
  • blackmatter — entity page with cluster table and capability list
  • unattributed — umbrella entity for siblings lacking the blackmatter OpenCTI label

Per-Sample Deltas

Field This Sample Primary (136b5750)
SHA-256 d715b248... 136b5750...
PE Checksum 0x263B2 0x2BC5A
.text MD5 cfbda2c4... (identical) cfbda2c4...
.data MD5 1835b63b... (different) 3d7c9a8e...
.data SHA-256 36c9cacc... varies
.data entropy 7.986 7.981
.data size 0xADC8 (40,968 bytes) varies

The .text section hash match confirms the stub is shared across all forty-one siblings; the .data hash divergence confirms per-sample payload customization. ^[pefile.txt:93] ^[pefile.txt:153]

Key Artefacts Recovered

  • XOR key: 0x10035fff present in .data — identical across all siblings in this cluster
  • Alphabet table: Base64-like character sequence ABCD...YZab...0123...89+/ in .text — identical to primary ^[strings.txt:43-68]
  • Import facade: Only 25 imports across three DLLs — GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI/shell functions. No network, crypto, or process APIs in the IAT. All threat APIs are resolved at runtime via PEB walking through InMemoryOrderModuleList. ^[pefile.txt:249-300]

Decompiled Behavior

No new Ghidra decompilation was performed because the stub is byte-identical to 136b5750, which was fully decompiled in the primary analysis. Radare2 analysis completed successfully (519 functions discovered), matching the function count of prior siblings. ^[r2:fcn.0041946f]

The entry-point pattern at 0x41946f is consistent with the cluster template:

  1. Parse PEB → walk InMemoryOrderModuleList
  2. Hash export names via ROR13-variant
  3. Cache resolved API pointers in .data pseudo-import table
  4. CPUID hypervisor-bit check + RDTSC timing gate
  5. Decrypt .data payload (XOR-NOT alphabet cipher)
  6. Reflectively map decrypted PE into memory (VirtualAlloc → memmove → fix IAT → jump)

No new functions or control-flow deviations observed vs 136b5750 template.

C2 Infrastructure

Runtime-resolved / obfuscated. No hardcoded IPs, domains, URLs, mutex names, or registry keys recovered from .text or .data. The cluster uses an LCG-based PRNG (0x19660d/0x3c6ef35f) to generate C2 URL paths at runtime; the seed and alphabet table are embedded in the encrypted .data payload. ^[blackmatter.md]

No mutex names, named pipes, or persistence artefacts recovered statically.

Interesting Tidbits

  • Builder pipeline fingerprint: Forty-one samples sharing an identical compilation timestamp (0x631A9665) and linker version (14.12) with only .data contents varying is consistent with a builder that encrypts per-campaign payloads into a shared MSVC stub. The PE checksums are individualized, indicating the builder recalculates checksums per output. ^[pefile.txt:65]
  • No .NET, no Go, no Rust: Pure native C/C++ with no managed-runtime artefacts. A deliberate lightweight choice for evading EDR signatures that target managed-runtime imports. ^[rabin2-info.txt:18]
  • POGO optimization as anti-analysis side-effect: Profile-guided optimization scatters hot paths unpredictably, making manual trace-through harder without degrading performance. ^[pefile.txt:313]
  • floss.txt and capa.txt both failed during triage (floss.txt argument error, capa.txt missing signatures). Re-running capa with installed signatures would likely hit T1620 (reflective code loading), T1055 (process injection), and T1497 (virtualization/sandbox evasion) — same as 136b5750. ^[floss.txt] ^[capa.txt]
  • Cluster numbering: This was the sixth entry in the original cluster table (after 9d8526b0, 136b5750, 0b525c35, 370415c8, c527ebf0) but remained triage-only until now. It is the forty-first sibling to receive a full analysis report.

How To Mess With It (Homelab Replication)

See the primary analysis 136b5750 for a full replication recipe. For this sibling specifically:

  1. Build a minimal PE32 stub in MSVC 14.12 with POGO enabled (/GL /LTCG:PGOptimize).
  2. Implement PEB-walking API resolution (walk InMemoryOrderModuleList, hash export names with ROR13 variant, cache resolved addresses in .data pseudo-import table).
  3. Encrypt your payload with the XOR-NOT alphabet cipher using key 0x10035fff.
  4. Embed the encrypted payload in .data and set the .data section to R/W.
  5. At runtime, decrypt .data in-place, fix relocations, and transfer control.
  6. Compare the resulting PE checksum to 0x263B2 — it will differ because your payload hash is unique.

Deployable Signatures

YARA — Cluster Stub Detection

rule BlackMatter_Loader_Stub_Msvc1412
{
    meta:
        description = "MSVC 14.12 reflective-loader stub shared by blackmatter-tagged cluster"
        author = "PacketPursuit"
        date = "2026-09-04"
        hash = "d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973"
        hash = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
    strings:
        $xor_key = { ff 5f 03 10 }
        $alphabet = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
        $section_itext = ".itext"
        $section_pdata = ".pdata"
    condition:
        uint16(0) == 0x5A4D and
        $xor_key and
        $alphabet and
        $section_itext and
        $section_pdata and
        pe.linker_version.major == 14 and
        pe.linker_version.minor >= 10 and
        pe.number_of_sections == 6 and
        pe.timestamp == 0x631A9665
}

YARA — Per-Sample Anchor (d715b248)

rule BlackMatter_Loader_d715b248
{
    meta:
        description = "Specific sibling anchor for d715b248"
        author = "PacketPursuit"
        date = "2026-09-04"
        hash = "d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973"
    strings:
        $stub = { 5A 4D }
        $text_hash_anchor = { cfbda2c4 }
    condition:
        uint16(0) == 0x5A4D and
        filesize < 200KB and
        $stub and
        pe.sections[0].name == ".text" and
        pe.sections[1].name == ".itext" and
        pe.sections[2].name == ".rdata" and
        pe.sections[3].name == ".data" and
        pe.sections[4].name == ".pdata" and
        pe.sections[5].name == ".reloc" and
        pe.checksum == 0x263B2
}

Sigma — Behavioral Hunt (Reflective Loader Pattern)

title: MSVC 14.12 Reflective Loader Cluster - BlackMatter Tag
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    - Hashes|contains:
        - 'MD5=cfbda2c44e51b3b0b00bcbbc767c62a2'
        - 'SHA256=d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973'
  condition: selection
falsepositives:
  - Unknown
level: high

IOC List

Type Value Notes
SHA-256 d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973 This sample
SHA-256 36c9cacc61f7e96bf3f3421ade921b3370dc436d7b63d70a9244b008e38a9b82 .data section payload
MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 .text section (cluster stub)
MD5 1835b63b9da3a50f8e3e3fc46e86c7e6 .data section (individualized)
PE Checksum 0x263B2 Unique per sample
Compile stamp 0x631A9665 Shared across all 41 siblings
XOR key 0x10035fff Shared across all 41 siblings

Behavioral Fingerprint

This binary presents a minimal static import surface (25 GUI-only imports across GDI32, USER32, KERNEL32) while resolving ~30+ threat APIs at runtime via PEB-walking through InMemoryOrderModuleList. It performs CPUID hypervisor-bit checks and RDTSC timing gates before decrypting an individualized payload embedded in the high-entropy .data section (entropy ~7.986). The decrypted payload is reflectively mapped into RWX memory and executed in-process. Network C2 URLs are generated at runtime via an LCG PRNG rather than hardcoded. All forty-one confirmed siblings share an identical compilation timestamp (0x631A9665) and .text section hash (cfbda2c4...), with only .data contents and PE checksum varying per sample.

Detection Signatures

ATT&CK ID Technique Evidence
T1620 Reflective Code Loading PEB-walking API resolution, VirtualAlloc, in-memory PE mapping ^[r2:fcn.0041946f]
T1055 Process Injection Reflective loader maps decrypted payload into allocated memory and transfers control ^[r2:fcn.0041946f]
T1497 Virtualization/Sandbox Evasion CPUID hypervisor-bit checks + RDTSC timing gate ^[blackmatter.md]
T1027.002 Obfuscated Files or Information XOR-NOT alphabet cipher for string decryption; encrypted .data payload ^[strings.txt]

References

  • Artifact ID: 80602f13-3b60-4a52-9e0e-ab87efc2a4ec
  • Source: OpenCTI / MalwareBazaar
  • Primary analysis: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
  • Cluster entity: blackmatter
  • Umbrella entity: unattributed
  • Technique: peb-walking-api-resolution

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile.py PE header dump
  • rabin2-info.txt — radare2 rabin2 -I binary summary
  • strings.txt — strings(1) output
  • floss.txt — FireEye flare-floss (failed: argument error)
  • capa.txt — Mandiant flare-capa (failed: missing signatures)
  • triage.json — triage-fast metadata
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • Radare2 analysis: 519 functions, entry at 0x41946f