typeanalysisfamilyunattributedconfidencemediumcreated2026-08-28updated2026-08-28pemalware-familyloaderanti-vmanti-debugevasioncode-injectionc2obfuscation
SHA-256: e67dbabcd48b1294883b07d7724f416a77963c79aaf9d81bed9d7e2d0dcd9731

unattributed: e67dbabcd — 17th confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster

Executive Summary

A 150 KB PE32 GUI binary, seventeenth confirmed sibling in the MSVC 14.12 reflective-loader cluster first documented at 136b5750. Shares an identical .text stub with the majority group (21b12514, ae02bd22, 7e9bbc5c) but carries a unique .data payload (SHA-256 07817a1f...) and PE checksum 0x32ac3. OpenCTI tag dropped-by-phorpiex; no blackmatter label. Static-only analysis (CAPE skipped — no Windows guest). All behavior inferred from decompilation aligns with the established cluster fingerprint; no new capabilities observed.

What It Is

Field Value
SHA-256 e67dbabcd48b1294883b07d7724f416a77963c79aaf9d81bed9d7e2d0dcd9731
Size 149,504 bytes (150 KB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler MSVC 14.12 (LinkerVersion 14.12) — Visual Studio 2017 15.5+ ^[pefile.txt:18] ^[exiftool.json:18]
Timestamp 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt:34]
Debug POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt:313]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:68]
Canary Enabled (canary: true) ^[rabin2-info.txt:6]
Signed Unsigned ^[rabin2-info.txt:27]
Imports Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt:249]
Overlay None ^[rabin2-info.txt:23]
YARA Generic PE only; no family-specific hits ^[yara.txt]

Cluster Membership

Section SHA-256 Cluster Status
.text 000a9a8b1440e44c... Matches majority group — identical to 136b5750, 21b12514, ae02bd22, 7e9bbc5c ^[pefile.txt:95]
.itext 38f20ce7e2c9381f... Identical across all 17 siblings
.rdata ce47d70dffec241b... Identical across all 17 siblings
.data 07817a1fab2142ed... Individualized — unique to this sample
.pdata 61e871411d6ff20c... Unique per sample (function pointers into .data)
.reloc 7b8a35469d264f92... Identical across all 17 siblings
PE checksum 0x32ac3 Unique per sample ^[pefile.txt:65]

How It Works

This sample is a cluster sibling — refer to the primary analysis of 136b5750 for full decompilation and behavioral narrative. Below are the per-sample deltas and confirming observations.

Entry Point (entry0 → fcn.00419479)

  • Delegates immediately to fcn.0040639c, the PEB-walking initializer. ^[r2:entry0]
  • Loads module "C" (kernel32) by pushing 0x43 to slot 0x4256c4 and invoking the walker, identical to sibling 136b5750. ^[r2:fcn.0040639c]
  • Resolves ~25 threat APIs via fcn.00405aec (PEB-walking InMemoryOrderModuleList with export-name iteration). ^[r2:fcn.00405aec]
  • All resolved pointers cached in .data pseudo-import table at 0x425xxx, encrypted with XOR key 0x10035fff. ^[r2:fcn.00405da0]

String Encryption — XOR-NOT Alphabet Cipher

Identical to cluster: buf[i] ^= 0x10035fff; buf[i] = ~buf[i]; at fcn.00401240. ^[r2:fcn.00401240]

Anti-Analysis & Anti-VM (fcn.004010bc)

  • CPUID leaf 1 ECX[31] (hypervisor present bit) ^[r2:fcn.004010bc]
  • CPUID leaf 7 EBX[18] ^[r2:fcn.004010bc]
  • RDTSC differential timing with rotate-13 ^[r2:fcn.004010bc]

LCG PRNG (fcn.0040110c)

Same constants: multiplier 0x19660d, increment 0x3c6ef35f, mask 0x7ffffff. ^[r2:fcn.0040110c]

Network / C2

  • HTTP POST verb decrypted at fcn.0040cfcc ("POST" wide). ^[r2:fcn.0040cfcc]
  • C2 domain and User-Agent generated at runtime via alphabet table + PRNG; no hard-coded endpoints in binary. ^[r2:fcn.0040d4b0]
  • WinInet-style handle operations via resolved slot 0x425470. ^[r2:fcn.00406ae8]

File-System Enumeration

  • fcn.00407468 enumerates with "*" wildcard via resolved FindFirstFile/FindNextFile. ^[r2:fcn.00407468]

Decompiled Behavior ( confirming functions )

Address Role Cluster Match
0x4010bc Anti-debug/VM gate Identical to 136b5750 ^[r2:fcn.004010bc]
0x4011c4 String helper (case conversion) Identical ^[r2:fcn.004011c4]
0x40110c LCG PRNG Identical ^[r2:fcn.0040110c]
0x401240 XOR-NOT decrypt stub Identical ^[r2:fcn.00401240]
0x40639c PEB-walk initializer Identical ^[r2:fcn.0040639c]
0x405aec Export table walker Identical ^[r2:fcn.00405aec]
0x405da0 Pointer encryption / stub builder Identical ^[r2:fcn.00405da0]
0x417738 Payload decoder / memory mapper Identical ^[r2:fcn.00417738]
0x418c34 LZSS-like decompressor (payload stage) Identical ^[r2:fcn.00418c34]
0x407468 File enumerator Identical ^[r2:fcn.00407468]
0x40782c C2 comms Identical ^[r2:fcn.0040782c]
0x40cfcc HTTP POST builder Identical ^[r2:fcn.0040cfcc]
0x40d4b0 Alphabet builder Identical ^[r2:fcn.0040d4b0]

C2 Infrastructure

No hard-coded C2 endpoints survive in the binary. The C2 domain, path, and User-Agent are generated at runtime via:

  1. LCG PRNG (0x40110c) producing indices into the alphabet table.
  2. Character-by-character assembly into a wide-character buffer.
  3. HTTP POST verb decrypted from 0x40cfcc ("POST" wide).
  4. Payload body encrypted before transmission.

Static inference only — no CAPE detonation available. Exact domains are runtime-resolved.

Interesting Tidbits

  • PE checksum 0x32ac3 is new in the cluster; prior siblings range 0x2688E–0x31DEB. This confirms the builder pipeline is still injecting per-sample encrypted payloads into the shared stub. ^[pefile.txt:65]
  • .data entropy 7.986 (near-maximum) confirms the payload region is encrypted / high-entropy, individualized per sample. ^[pefile.txt:152]
  • No .text divergence: Unlike sibling 877f1047 (16th sibling, divergent .text), this sample falls squarely in the majority .text group, suggesting the builder pipeline has two stub variants but this sample used the original template.
  • OpenCTI labels: dropped-by-phorpiex and exe only; no blackmatter tag. This is consistent with the 15th sibling (7e9bbc5c) but differs from the earlier 1st–13th siblings which carried both tags. The upstream connector may have stopped applying the blackmatter label after mid-2026.

How To Mess With It (Homelab Replication)

Refer to the primary cluster analysis at 136b5750 for full reproduction steps. The only delta for this sample is the individualized .data payload; the stub template is unchanged.

Deployable Signatures

YARA Rule

rule unattributed_msvc1412_reflective_loader_cluster
{
    meta:
        description = "PE32 MSVC 14.12 reflective loader with PEB-walking API resolution and XOR-NOT string crypto"
        author = "PacketPursuit"
        date = "2026-08-28"
        sha256 = "e67dbabcd48b1294883b07d7724f416a77963c79aaf9d81bed9d7e2d0dcd9731"
    strings:
        $xor_not_key = { 3D FF 5F 03 10 }
        $xor_not_op = { 81 31 FF 5F 03 10 }
        $lcg_mul = { 0D 66 19 00 00 }
        $lcg_inc = { 35 3C EF C6 03 }
        $lcg_mask = { 25 FF FF FF 07 }
        $alphabet_1 = { 41 BB BF EA }
        $alphabet_2 = { 45 E6 BB A7 }
        $alphabet_3 = { 49 EA B7 A3 }
        $post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + 0x18) == 0x10B and
        3 of ($xor_not_*) and
        2 of ($lcg_*) and
        2 of ($alphabet_*) and
        $post_wide
}

Behavioral Fingerprint

This binary loads with a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within the first 5 seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by hash. It allocates RWX memory, copies a decrypted payload into it, and spawns a file-system enumeration thread (FindFirstFile with "*" wildcard) alongside a network thread that assembles an HTTP POST request. The POST body is encrypted with a session key imported via CryptImportKey. C2 domain and User-Agent are generated at runtime using a seeded LCG PRNG and a base-62 alphabet table. If executed inside a VM, CPUID leaf 1 ECX[31] or leaf 7 EBX[18] hypervisor bits cause altered code paths or early termination.

IOCs

Indicator Value Notes
SHA-256 e67dbabcd48b1294883b07d7724f416a77963c79aaf9d81bed9d7e2d0dcd9731 Primary
Compilation Sep 9 2022 01:27:01 UTC Timestamp 0x631A9665 (cluster-shared)
Linker 14.12 VS 2017 15.5+ (cluster-shared)
PE checksum 0x32ac3 Unique per sample
XOR Key 0x10035fff Used for string + pointer encryption (cluster-shared)
LCG multiplier 0x19660d PRNG constant (cluster-shared)
LCG increment 0x3c6ef35f PRNG constant (cluster-shared)
Anti-VM CPUID leaf 1 ECX[31], leaf 7 EBX[18], RDTSC rotate-13 Static detection targets (cluster-shared)
Pseudo-import region 0x425000–0x425fff (.data VA) Decrypted at runtime

Detection Signatures

ATT&CK Technique Implementation
T1055 — Process Injection Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation ^[r2:fcn.00417738]
T1071.001 — Application Layer Protocol: Web Protocols HTTP POST C2 with encrypted body; WinInet API resolution ^[r2:fcn.0040cfcc]
T1027 — Obfuscated Files or Information XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation ^[r2:fcn.00401240] ^[r2:fcn.0040d4b0]
T1497.001 — Virtualization/Sandbox Evasion: System Checks CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) ^[r2:fcn.004010bc]
T1497.002 — Virtualization/Sandbox Evasion: User Activity Based RDTSC differential timing gate ^[r2:fcn.004010bc]
T1083 — File and Directory Discovery Recursive "*" enumeration via FindFirstFile / FindNextFile ^[r2:fcn.00407468]
T1573.001 — Encrypted Channel: Symmetric Cryptography CryptEncrypt / CryptDecrypt for C2 payload body ^[r2:fcn.0040782c]
T1105 — Ingress Tool Transfer Downloader / payload retrieval via HTTP POST response handling ^[r2:fcn.0040782c]

References

  • OpenCTI artifact: a114b133-57d6-44e2-be38-f47568b4538b, labels: dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
  • Primary cluster analysis: unattributed (sample 136b5750)
  • BlackMatter contested label page: blackmatter
  • Phorpiex delivery infrastructure: phorpiex
  • Technique page: peb-walking-api-resolution

Provenance

Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt) and radare2 decompilation (analysis level 3) of the binary at <sample e67dbabcd48b.bin>. capa failed due to missing signature database; floss failed due to incorrect CLI invocation. CAPE dynamic analysis skipped — no Windows guest available. All behavioral claims are statically inferred and marked accordingly.