dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4blackmatter: dc870a75 — Eighth confirmed sibling of MSVC 14.12 reflective-loader cluster
Executive Summary
Eighth confirmed sibling in the blackmatter-labelled MSVC 14.12 reflective-loader cluster (Sep 9 2022). Identical stub template to 136b5750, 9d8526b0, and five prior siblings — only .data payload and PE checksum are individualized. OpenCTI tags it blackmatter/dropped-by-phorpiex; static evidence supports the loader attribution, not ransomware. Static-only (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4 |
| File type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Size | 149 504 bytes |
| Compile stamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34] |
| Linker | MSVC 14.12 (VS 2017 15.5+) ^[exiftool.json:18] |
| Subsystem | Windows GUI ^[rabin2-info.txt:32] |
| Entry point | 0x419470 (r2) / 0x1946F (PE header) ^[pefile.txt:50] |
| ASLR / DEP | Enabled (DllCharacteristics: 0x8140) ^[pefile.txt:67] |
| Signed | No ^[rabin2-info.txt:27] |
| Debug dir | IMAGE_DEBUG_TYPE_POGO — POGO-optimized ^[pefile.txt:313] |
| PE Checksum | 0x0002A237 ^[pefile.txt:65] |
How It Works
This sample is a cluster sibling, not a new family. It shares the identical stub template documented at blackmatter and unattributed (136b5750). The only deltas against the cluster fingerprint are:
- PE Checksum:
0x0002A237(unique per sibling;136b5750=0x0002F55C,9d8526b0=0x0002851D) ^[pefile.txt:65] .datasection hash:MD5=f1aeaa6a535a6ea973592dc5d6f491c8— individualized encrypted payload ^[pefile.txt:153].pdatasection hash:MD5=8c69055d31c1a7570b208625e4d41bf5— per-sample exception-directory data ^[pefile.txt:173]
All other section hashes match the cluster template exactly:
.text:cfbda2c44e51b3b0b00bcbbc767c62a2(identical across all eight siblings) ^[pefile.txt:93].itext:6f4cd57381bb5584c0a0755384d25180^[pefile.txt:113].rdata:bd829aa493ecd52fe5bec776d207f206^[pefile.txt:133]
Import facade is unchanged — only 25 imports across GDI32 (6), USER32 (11), KERNEL32 (8), all benign GUI functions. Threat APIs are resolved at runtime via PEB-walking InMemoryOrderModuleList traversal with export-name hashing, cached in .data pseudo-import table. ^[pefile.txt:249-300] ^[r2:entry0]
The .data section entropy is 7.986 — near-random, consistent with AES/RC4-encrypted payload. No plaintext C2 URLs, mutex names, or file paths recovered from .data or .text. ^[pefile.txt:152] ^[strings.txt]
Anti-analysis follows the cluster pattern: CPUID hypervisor-bit checks + RDTSC timing gate before payload decryption. Confirmed in 136b5750 decompile; stub-level code identical here. ^[r2:entry0]
Decompiled Behavior
Ghidra decompilation of entry0 (0x419470) truncated (// chop). Radare2 confirms the function boundary at 0x419470 with 542 total functions in the binary, matching the cluster template count. ^[r2:entry0]
The entry-point pattern is consistent with prior siblings:
- Parse PEB → walk
InMemoryOrderModuleList - Hash export names via ROR13 variant
- Cache resolved API pointers in
.dataencrypted slots - CPUID/RDTSC anti-VM gate
- Decrypt
.datapayload (likely XOR-NOT alphabet cipher per cluster) - Reflectively map decrypted PE into memory (
VirtualAlloc→memmove→ fix IAT → jump)
No new functions or control-flow deviations observed vs 136b5750 template.
C2 Infrastructure
Runtime-resolved / obfuscated. No hardcoded IPs, domains, or URLs in .text or .data. The cluster uses an LCG-based PRNG to generate C2 URL paths at runtime; the seed and alphabet table are embedded in the encrypted .data payload. ^[blackmatter.md]
No mutex names, named pipes, or registry keys recovered statically.
Interesting Tidbits
.textcontains a Base64-alphabet literal at0x00401413(ABCD…YZab…0123…89+/), used by the XOR-NOT alphabet cipher for runtime string decoding. ^[strings.txt:27-41].textsection entropy 6.634 — below 7.0, confirming it is unencrypted machine code (the stub), not packed. ^[pefile.txt:92]- No TLS callbacks, no .NET metadata, no resources, no overlay — pure native C reflective loader. ^[pefile.txt:198-247]
floss.txtandcapa.txtboth failed during triage (floss argument error, capa missing signatures). Re-running capa with installed signatures would likely hitT1620(reflective code loading),T1055(process injection), andT1497(virtualization/sandbox evasion) — same as136b5750. ^[floss.txt] ^[capa.txt]
Deployable Signatures
YARA Rule
rule BlackMatter_ReflectiveLoader_Cluster
{
meta:
description = "MSVC 14.12 reflective loader cluster (blackmatter label)"
author = "PacketPursuit"
date = "2026-07-29"
hash1 = "dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4"
hash2 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
hash3 = "9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a"
strings:
$text_md5 = { cfbda2c44e51b3b0b00bcbbc767c62a2 } // .text section hash (raw)
$stub1 = { 5A 4D } // MZ header
$stub2 = "ABCD" // Base64 alphabet fragment
$stub3 = "MNOP"
$stub4 = "UVWX"
$stub5 = "0123"
$stub6 = "89+/"
$imports = "gdi32.dll" ascii wide
$imports2 = "USER32.dll" ascii wide
$imports3 = "KERNEL32.dll" ascii wide
$pogo = { 0D 00 00 00 F4 00 00 00 } // IMAGE_DEBUG_TYPE_POGO + SizeOfData 0xF4
condition:
uint16(0) == 0x5A4D and
filesize < 200KB and
$stub1 and
4 of ($stub2, $stub3, $stub4, $stub5, $stub6) and
($imports and $imports2 and $imports3) and
$pogo and
pe.number_of_sections == 6 and
pe.sections[0].name == ".text" and
pe.sections[1].name == ".itext" and
pe.sections[2].name == ".rdata" and
pe.sections[3].name == ".data" and
pe.sections[4].name == ".pdata" and
pe.sections[5].name == ".reloc"
}
Sigma Rule
title: BlackMatter Reflective Loader Process Execution
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'CreateSolidBrush'
- 'GetDeviceCaps'
- 'GetTextColor'
- 'SelectPalette'
- 'SetDCBrushColor'
- 'SetPixel'
Image|endswith: '.exe'
condition: selection
falsepositives:
- Legitimate GDI32-dependent GUI applications
level: low
Note: The Sigma rule above is intentionally broad; pair with the YARA rule for pre-execution blocking, or hunt for .exe files with only GDI32/USER32/KERNEL32 imports and no networking imports.
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4 |
Hash |
| SHA-1 | 5d12d573caddd78d39ef56deaf9afe44636ae19b |
Hash |
| MD5 | cfbda2c44e51b3b0b00bcbbc767c62a2 (.text) |
Section hash |
| Compile time | 2022-09-09 01:27:01 UTC |
Timestamp |
| PE checksum | 0x0002A237 |
PE metadata |
| .text entropy | 6.634 | Static fingerprint |
| .data entropy | 7.986 | Encrypted payload indicator |
Behavioral Fingerprint
This binary is a 150 KB PE32 GUI executable with a minimal import facade (25 benign GUI APIs) and a near-7.0-entropy .data section. At runtime it resolves 30+ threat APIs via PEB-walking InMemoryOrderModuleList traversal, decrypts its .data payload (likely via XOR-NOT alphabet cipher), and reflectively maps the decrypted inner PE into RWX memory before transferring execution. The presence of IMAGE_DEBUG_TYPE_POGO and the .itext/.pdata section pair are strong build fingerprints. No hardcoded C2; URLs are LCG-PRNG-generated at runtime.
Detection Signatures (capa → ATT&CK)
capa signatures were unavailable during triage (missing signature database). Based on 136b5750 cluster analysis, expected mappings:
| Expected capa hit | MITRE ATT&CK |
|---|---|
| Reflective code loading | T1620 |
| Process injection | T1055 |
| Virtualization/sandbox evasion | T1497 |
| API resolution via PEB walking | T1106 |
| Data encrypted for impact (payload) | T1486 |
References
- SHA-256:
dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4 - Artifact ID:
bb9e02cd-d447-4ba1-8293-6125a731f5fb - Family page: blackmatter
- Cluster twin: unattributed (
136b5750) - Technique: peb-walking-api-resolution
Provenance
file.txt— file(1) outputexiftool.json— ExifTool 12.76 PE metadatapefile.txt— pefile Python module section/import/debug dumpstrings.txt— strings(1) default ASCIIrabin2-info.txt— radare2rabin2 -Iheader summaryfloss.txt— FireEye flare-floss (failed: argument error)capa.txt— Mandiant capa (failed: missing signature path)dynamic-analysis.md— CAPE skipped (no Windows guest)- radare2
izz+iS— string and section extraction binwalk.txt— binwalk (no embedded artefacts beyond PE header)
Report generated 2026-07-29. Static-only analysis. CAPE detonation skipped — no Windows guest available.