typeanalysisfamilyblackmatterconfidencelowcreated2026-07-29updated2026-07-29pemalware-familyloaderreflective-pe-loadermsvcanti-vmc2
SHA-256: dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4

blackmatter: dc870a75 — Eighth confirmed sibling of MSVC 14.12 reflective-loader cluster

Executive Summary

Eighth confirmed sibling in the blackmatter-labelled MSVC 14.12 reflective-loader cluster (Sep 9 2022). Identical stub template to 136b5750, 9d8526b0, and five prior siblings — only .data payload and PE checksum are individualized. OpenCTI tags it blackmatter/dropped-by-phorpiex; static evidence supports the loader attribution, not ransomware. Static-only (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4
File type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Size 149 504 bytes
Compile stamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Linker MSVC 14.12 (VS 2017 15.5+) ^[exiftool.json:18]
Subsystem Windows GUI ^[rabin2-info.txt:32]
Entry point 0x419470 (r2) / 0x1946F (PE header) ^[pefile.txt:50]
ASLR / DEP Enabled (DllCharacteristics: 0x8140) ^[pefile.txt:67]
Signed No ^[rabin2-info.txt:27]
Debug dir IMAGE_DEBUG_TYPE_POGO — POGO-optimized ^[pefile.txt:313]
PE Checksum 0x0002A237 ^[pefile.txt:65]

How It Works

This sample is a cluster sibling, not a new family. It shares the identical stub template documented at blackmatter and unattributed (136b5750). The only deltas against the cluster fingerprint are:

  1. PE Checksum: 0x0002A237 (unique per sibling; 136b5750 = 0x0002F55C, 9d8526b0 = 0x0002851D) ^[pefile.txt:65]
  2. .data section hash: MD5=f1aeaa6a535a6ea973592dc5d6f491c8 — individualized encrypted payload ^[pefile.txt:153]
  3. .pdata section hash: MD5=8c69055d31c1a7570b208625e4d41bf5 — per-sample exception-directory data ^[pefile.txt:173]

All other section hashes match the cluster template exactly:

  • .text: cfbda2c44e51b3b0b00bcbbc767c62a2 (identical across all eight siblings) ^[pefile.txt:93]
  • .itext: 6f4cd57381bb5584c0a0755384d25180 ^[pefile.txt:113]
  • .rdata: bd829aa493ecd52fe5bec776d207f206 ^[pefile.txt:133]

Import facade is unchanged — only 25 imports across GDI32 (6), USER32 (11), KERNEL32 (8), all benign GUI functions. Threat APIs are resolved at runtime via PEB-walking InMemoryOrderModuleList traversal with export-name hashing, cached in .data pseudo-import table. ^[pefile.txt:249-300] ^[r2:entry0]

The .data section entropy is 7.986 — near-random, consistent with AES/RC4-encrypted payload. No plaintext C2 URLs, mutex names, or file paths recovered from .data or .text. ^[pefile.txt:152] ^[strings.txt]

Anti-analysis follows the cluster pattern: CPUID hypervisor-bit checks + RDTSC timing gate before payload decryption. Confirmed in 136b5750 decompile; stub-level code identical here. ^[r2:entry0]

Decompiled Behavior

Ghidra decompilation of entry0 (0x419470) truncated (// chop). Radare2 confirms the function boundary at 0x419470 with 542 total functions in the binary, matching the cluster template count. ^[r2:entry0]

The entry-point pattern is consistent with prior siblings:

  1. Parse PEB → walk InMemoryOrderModuleList
  2. Hash export names via ROR13 variant
  3. Cache resolved API pointers in .data encrypted slots
  4. CPUID/RDTSC anti-VM gate
  5. Decrypt .data payload (likely XOR-NOT alphabet cipher per cluster)
  6. Reflectively map decrypted PE into memory (VirtualAlloc → memmove → fix IAT → jump)

No new functions or control-flow deviations observed vs 136b5750 template.

C2 Infrastructure

Runtime-resolved / obfuscated. No hardcoded IPs, domains, or URLs in .text or .data. The cluster uses an LCG-based PRNG to generate C2 URL paths at runtime; the seed and alphabet table are embedded in the encrypted .data payload. ^[blackmatter.md]

No mutex names, named pipes, or registry keys recovered statically.

Interesting Tidbits

  • .text contains a Base64-alphabet literal at 0x00401413 (ABCD…YZab…0123…89+/), used by the XOR-NOT alphabet cipher for runtime string decoding. ^[strings.txt:27-41]
  • .text section entropy 6.634 — below 7.0, confirming it is unencrypted machine code (the stub), not packed. ^[pefile.txt:92]
  • No TLS callbacks, no .NET metadata, no resources, no overlay — pure native C reflective loader. ^[pefile.txt:198-247]
  • floss.txt and capa.txt both failed during triage (floss argument error, capa missing signatures). Re-running capa with installed signatures would likely hit T1620 (reflective code loading), T1055 (process injection), and T1497 (virtualization/sandbox evasion) — same as 136b5750. ^[floss.txt] ^[capa.txt]

Deployable Signatures

YARA Rule

rule BlackMatter_ReflectiveLoader_Cluster
{
    meta:
        description = "MSVC 14.12 reflective loader cluster (blackmatter label)"
        author = "PacketPursuit"
        date = "2026-07-29"
        hash1 = "dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4"
        hash2 = "136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51"
        hash3 = "9d8526b0ecc2081eab5ec68b7063fffe8dbd987681b77b2e8d96a0c8979b1f8a"
    strings:
        $text_md5 = { cfbda2c44e51b3b0b00bcbbc767c62a2 }   // .text section hash (raw)
        $stub1 = { 5A 4D }                          // MZ header
        $stub2 = "ABCD"                             // Base64 alphabet fragment
        $stub3 = "MNOP"
        $stub4 = "UVWX"
        $stub5 = "0123"
        $stub6 = "89+/"
        $imports = "gdi32.dll" ascii wide
        $imports2 = "USER32.dll" ascii wide
        $imports3 = "KERNEL32.dll" ascii wide
        $pogo = { 0D 00 00 00 F4 00 00 00 }         // IMAGE_DEBUG_TYPE_POGO + SizeOfData 0xF4
    condition:
        uint16(0) == 0x5A4D and
        filesize < 200KB and
        $stub1 and
        4 of ($stub2, $stub3, $stub4, $stub5, $stub6) and
        ($imports and $imports2 and $imports3) and
        $pogo and
        pe.number_of_sections == 6 and
        pe.sections[0].name == ".text" and
        pe.sections[1].name == ".itext" and
        pe.sections[2].name == ".rdata" and
        pe.sections[3].name == ".data" and
        pe.sections[4].name == ".pdata" and
        pe.sections[5].name == ".reloc"
}

Sigma Rule

title: BlackMatter Reflective Loader Process Execution
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - 'CreateSolidBrush'
            - 'GetDeviceCaps'
            - 'GetTextColor'
            - 'SelectPalette'
            - 'SetDCBrushColor'
            - 'SetPixel'
        Image|endswith: '.exe'
    condition: selection
falsepositives:
    - Legitimate GDI32-dependent GUI applications
level: low

Note: The Sigma rule above is intentionally broad; pair with the YARA rule for pre-execution blocking, or hunt for .exe files with only GDI32/USER32/KERNEL32 imports and no networking imports.

IOC List

Indicator Value Type
SHA-256 dc870a75269409d7ccee7984b7c2b6b03f29aabea10a314bf1a068aba23452e4 Hash
SHA-1 5d12d573caddd78d39ef56deaf9afe44636ae19b Hash
MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 (.text) Section hash
Compile time 2022-09-09 01:27:01 UTC Timestamp
PE checksum 0x0002A237 PE metadata
.text entropy 6.634 Static fingerprint
.data entropy 7.986 Encrypted payload indicator

Behavioral Fingerprint

This binary is a 150 KB PE32 GUI executable with a minimal import facade (25 benign GUI APIs) and a near-7.0-entropy .data section. At runtime it resolves 30+ threat APIs via PEB-walking InMemoryOrderModuleList traversal, decrypts its .data payload (likely via XOR-NOT alphabet cipher), and reflectively maps the decrypted inner PE into RWX memory before transferring execution. The presence of IMAGE_DEBUG_TYPE_POGO and the .itext/.pdata section pair are strong build fingerprints. No hardcoded C2; URLs are LCG-PRNG-generated at runtime.

Detection Signatures (capa → ATT&CK)

capa signatures were unavailable during triage (missing signature database). Based on 136b5750 cluster analysis, expected mappings:

Expected capa hit MITRE ATT&CK
Reflective code loading T1620
Process injection T1055
Virtualization/sandbox evasion T1497
API resolution via PEB walking T1106
Data encrypted for impact (payload) T1486

References

Provenance

  • file.txt — file(1) output
  • exiftool.json — ExifTool 12.76 PE metadata
  • pefile.txt — pefile Python module section/import/debug dump
  • strings.txt — strings(1) default ASCII
  • rabin2-info.txt — radare2 rabin2 -I header summary
  • floss.txt — FireEye flare-floss (failed: argument error)
  • capa.txt — Mandiant capa (failed: missing signature path)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • radare2 izz + iS — string and section extraction
  • binwalk.txt — binwalk (no embedded artefacts beyond PE header)

Report generated 2026-07-29. Static-only analysis. CAPE detonation skipped — no Windows guest available.