d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973blackmatter: d715b248 — forty-first confirmed sibling in MSVC 14.12 reflective-loader cluster
Executive Summary: PE32 GUI reflective loader compiled Sep 9 2022 with MSVC 14.12 and POGO optimization. This sample was the sixth entry in the cluster table (previously triage-only) and is now promoted to analysed status. It shares the identical stub template with forty prior siblings; the only delta is the encrypted .data payload (unique hash, entropy 7.986) and PE checksum (0x263B2). No runtime behavior available — CAPE skipped due to no Windows guest.
What It Is
| Field | Value |
|---|---|
| SHA-256 | d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973 |
| File type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Size | 149,504 bytes (150 KB) |
| Compile stamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Linker | MSVC 14.12 (VS 2017 15.5+) ^[pefile.txt:45] |
| Optimization | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313] |
| Subsystem | Windows GUI ^[rabin2-info.txt:32] |
| Entry point | 0x1946F (RVA) / 0x41946f (VA) ^[pefile.txt:50] |
| ASLR / DEP | Enabled (DllCharacteristics: 0x8140) ^[pefile.txt:67] |
| Stack canary | Enabled (canary: true) ^[rabin2-info.txt:6] |
| Signed | Unsigned (signed: false) ^[rabin2-info.txt:27] |
| OpenCTI labels | blackmatter, dropped-by-phorpiex, exe, malware-bazaar ^[triage.json] |
How It Works
This sample is a cluster sibling of the MSVC 14.12 reflective-loader family. The stub — entry point, PEB-walking API resolution, anti-analysis gates, and payload decryption — is byte-identical to the forty prior siblings. The threat payload is individualized per-sample via encrypted contents in the .data section.
For the full build-stack and behavioral analysis of this family, see the primary report:
- /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html — primary analysis (PEB-walking, XOR-NOT alphabet cipher, CPUID anti-VM, LCG PRNG C2 URL generation)
- blackmatter — entity page with cluster table and capability list
- unattributed — umbrella entity for siblings lacking the
blackmatterOpenCTI label
Per-Sample Deltas
| Field | This Sample | Primary (136b5750) |
|---|---|---|
| SHA-256 | d715b248... |
136b5750... |
| PE Checksum | 0x263B2 |
0x2BC5A |
.text MD5 |
cfbda2c4... (identical) |
cfbda2c4... |
.data MD5 |
1835b63b... (different) |
3d7c9a8e... |
.data SHA-256 |
36c9cacc... |
varies |
.data entropy |
7.986 | 7.981 |
.data size |
0xADC8 (40,968 bytes) | varies |
The .text section hash match confirms the stub is shared across all forty-one siblings; the .data hash divergence confirms per-sample payload customization. ^[pefile.txt:93] ^[pefile.txt:153]
Key Artefacts Recovered
- XOR key:
0x10035fffpresent in.data— identical across all siblings in this cluster - Alphabet table: Base64-like character sequence
ABCD...YZab...0123...89+/in.text— identical to primary ^[strings.txt:43-68] - Import facade: Only 25 imports across three DLLs — GDI32 (6), USER32 (11), KERNEL32 (8) — all GUI/shell functions. No network, crypto, or process APIs in the IAT. All threat APIs are resolved at runtime via PEB walking through
InMemoryOrderModuleList. ^[pefile.txt:249-300]
Decompiled Behavior
No new Ghidra decompilation was performed because the stub is byte-identical to 136b5750, which was fully decompiled in the primary analysis. Radare2 analysis completed successfully (519 functions discovered), matching the function count of prior siblings. ^[r2:fcn.0041946f]
The entry-point pattern at 0x41946f is consistent with the cluster template:
- Parse PEB → walk
InMemoryOrderModuleList - Hash export names via ROR13-variant
- Cache resolved API pointers in
.datapseudo-import table - CPUID hypervisor-bit check + RDTSC timing gate
- Decrypt
.datapayload (XOR-NOT alphabet cipher) - Reflectively map decrypted PE into memory (
VirtualAlloc→memmove→ fix IAT → jump)
No new functions or control-flow deviations observed vs 136b5750 template.
C2 Infrastructure
Runtime-resolved / obfuscated. No hardcoded IPs, domains, URLs, mutex names, or registry keys recovered from .text or .data. The cluster uses an LCG-based PRNG (0x19660d/0x3c6ef35f) to generate C2 URL paths at runtime; the seed and alphabet table are embedded in the encrypted .data payload. ^[blackmatter.md]
No mutex names, named pipes, or persistence artefacts recovered statically.
Interesting Tidbits
- Builder pipeline fingerprint: Forty-one samples sharing an identical compilation timestamp (
0x631A9665) and linker version (14.12) with only.datacontents varying is consistent with a builder that encrypts per-campaign payloads into a shared MSVC stub. The PE checksums are individualized, indicating the builder recalculates checksums per output. ^[pefile.txt:65] - No .NET, no Go, no Rust: Pure native C/C++ with no managed-runtime artefacts. A deliberate lightweight choice for evading EDR signatures that target managed-runtime imports. ^[rabin2-info.txt:18]
- POGO optimization as anti-analysis side-effect: Profile-guided optimization scatters hot paths unpredictably, making manual trace-through harder without degrading performance. ^[pefile.txt:313]
- floss.txt and capa.txt both failed during triage (
floss.txtargument error,capa.txtmissing signatures). Re-running capa with installed signatures would likely hitT1620(reflective code loading),T1055(process injection), andT1497(virtualization/sandbox evasion) — same as136b5750. ^[floss.txt] ^[capa.txt] - Cluster numbering: This was the sixth entry in the original cluster table (after
9d8526b0,136b5750,0b525c35,370415c8,c527ebf0) but remained triage-only until now. It is the forty-first sibling to receive a full analysis report.
How To Mess With It (Homelab Replication)
See the primary analysis 136b5750 for a full replication recipe. For this sibling specifically:
- Build a minimal PE32 stub in MSVC 14.12 with POGO enabled (
/GL /LTCG:PGOptimize). - Implement PEB-walking API resolution (walk
InMemoryOrderModuleList, hash export names with ROR13 variant, cache resolved addresses in.datapseudo-import table). - Encrypt your payload with the XOR-NOT alphabet cipher using key
0x10035fff. - Embed the encrypted payload in
.dataand set the.datasection toR/W. - At runtime, decrypt
.datain-place, fix relocations, and transfer control. - Compare the resulting PE checksum to
0x263B2— it will differ because your payload hash is unique.
Deployable Signatures
YARA — Cluster Stub Detection
rule BlackMatter_Loader_Stub_Msvc1412
{
meta:
description = "MSVC 14.12 reflective-loader stub shared by blackmatter-tagged cluster"
author = "PacketPursuit"
date = "2026-09-04"
hash = "d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973"
hash = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
strings:
$xor_key = { ff 5f 03 10 }
$alphabet = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
$section_itext = ".itext"
$section_pdata = ".pdata"
condition:
uint16(0) == 0x5A4D and
$xor_key and
$alphabet and
$section_itext and
$section_pdata and
pe.linker_version.major == 14 and
pe.linker_version.minor >= 10 and
pe.number_of_sections == 6 and
pe.timestamp == 0x631A9665
}
YARA — Per-Sample Anchor (d715b248)
rule BlackMatter_Loader_d715b248
{
meta:
description = "Specific sibling anchor for d715b248"
author = "PacketPursuit"
date = "2026-09-04"
hash = "d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973"
strings:
$stub = { 5A 4D }
$text_hash_anchor = { cfbda2c4 }
condition:
uint16(0) == 0x5A4D and
filesize < 200KB and
$stub and
pe.sections[0].name == ".text" and
pe.sections[1].name == ".itext" and
pe.sections[2].name == ".rdata" and
pe.sections[3].name == ".data" and
pe.sections[4].name == ".pdata" and
pe.sections[5].name == ".reloc" and
pe.checksum == 0x263B2
}
Sigma — Behavioral Hunt (Reflective Loader Pattern)
title: MSVC 14.12 Reflective Loader Cluster - BlackMatter Tag
logsource:
product: windows
category: process_creation
detection:
selection:
- Hashes|contains:
- 'MD5=cfbda2c44e51b3b0b00bcbbc767c62a2'
- 'SHA256=d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | d715b248f71cd6ba4fcc78b89e9184ff5f0a04b9d02790bcbc30e13c040d3973 |
This sample |
| SHA-256 | 36c9cacc61f7e96bf3f3421ade921b3370dc436d7b63d70a9244b008e38a9b82 |
.data section payload |
| MD5 | cfbda2c44e51b3b0b00bcbbc767c62a2 |
.text section (cluster stub) |
| MD5 | 1835b63b9da3a50f8e3e3fc46e86c7e6 |
.data section (individualized) |
| PE Checksum | 0x263B2 |
Unique per sample |
| Compile stamp | 0x631A9665 |
Shared across all 41 siblings |
| XOR key | 0x10035fff |
Shared across all 41 siblings |
Behavioral Fingerprint
This binary presents a minimal static import surface (25 GUI-only imports across GDI32, USER32, KERNEL32) while resolving ~30+ threat APIs at runtime via PEB-walking through InMemoryOrderModuleList. It performs CPUID hypervisor-bit checks and RDTSC timing gates before decrypting an individualized payload embedded in the high-entropy .data section (entropy ~7.986). The decrypted payload is reflectively mapped into RWX memory and executed in-process. Network C2 URLs are generated at runtime via an LCG PRNG rather than hardcoded. All forty-one confirmed siblings share an identical compilation timestamp (0x631A9665) and .text section hash (cfbda2c4...), with only .data contents and PE checksum varying per sample.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1620 | Reflective Code Loading | PEB-walking API resolution, VirtualAlloc, in-memory PE mapping ^[r2:fcn.0041946f] |
| T1055 | Process Injection | Reflective loader maps decrypted payload into allocated memory and transfers control ^[r2:fcn.0041946f] |
| T1497 | Virtualization/Sandbox Evasion | CPUID hypervisor-bit checks + RDTSC timing gate ^[blackmatter.md] |
| T1027.002 | Obfuscated Files or Information | XOR-NOT alphabet cipher for string decryption; encrypted .data payload ^[strings.txt] |
References
- Artifact ID:
80602f13-3b60-4a52-9e0e-ab87efc2a4ec - Source: OpenCTI / MalwareBazaar
- Primary analysis: /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
- Cluster entity: blackmatter
- Umbrella entity: unattributed
- Technique: peb-walking-api-resolution
Provenance
file.txt— file(1) outputpefile.txt— pefile.py PE header dumprabin2-info.txt— radare2rabin2 -Ibinary summarystrings.txt— strings(1) outputfloss.txt— FireEye flare-floss (failed: argument error)capa.txt— Mandiant flare-capa (failed: missing signatures)triage.json— triage-fast metadatadynamic-analysis.md— CAPE skipped (no Windows guest)- Radare2 analysis: 519 functions, entry at
0x41946f