ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8cunclassified-pe64-modular-builder: ec95bcf4 — MSVC 14.50 full-spectrum modular kit with ENS C2, ChaCha20, and app-bound encryption bypass
Executive Summary
A 9 MB PE32+ x64 binary compiled with MSVC 14.50 (May 2026) that presents as a modular malware builder kit. Static evidence reveals 17+ selectable modules spanning credential theft, crypto clipping, remote desktop, Discord/Exodus injection, data encryption, and worm propagation. C2 is resolved via Ethereum Name Service (ENS) text records queried through 15+ public RPC endpoints, with WebSocket transport for command-and-control. Includes Chrome App-Bound Encryption bypass, SQLite 3.49.1 for local data staging, and extensive VM/sandbox detection. No siblings confirmed in corpus; singleton pending cluster.
What It Is
| Field | Value |
|---|---|
| SHA-256 | ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c |
| Filename | 9BRIMp6CcY4y.exe ^[metadata.json] |
| Type | PE32+ executable (GUI) x86-64, 7 sections ^[file.txt] |
| Size | 8,956,723 bytes ^[triage.json] |
| Linker | MSVC 14.50 (VS 2022 17.10+) ^[exiftool.json:18] |
| Timestamp | Sun May 17 03:23:18 2026 UTC ^[pefile.txt:352] |
| Signed | No ^[rabin2-info.txt:27] |
| VS_VERSIONINFO | Absent ^[pefile.txt] |
| PDB | None (debug type IMAGE_DEBUG_TYPE_POGO + ILTCG) ^[pefile.txt:1379-1394] |
| Capa | Failed (missing signatures) ^[capa.txt] |
| Floss | Failed (argument parsing error) ^[floss.txt] |
| CAPE | Skipped — no Windows guest available ^[dynamic-analysis.md] |
Build artifacts: C++ STL heavy RTTI, nlohmann/json exception strings (json.exception.*, parse_error), SQLite 3.49.1 runtime, ChaCha20 quarter-round constant expand 32-byte k ^[strings.txt:5018], MSVC .fptable floating-point constant section (entropy 0.0) ^[pefile.txt:476-493]. No packing observed; .text entropy 6.53, .rdata 4.95.
How It Works
Builder-Kit Architecture
The binary carries a hardcoded license key and a features bitmask/string table indicating selectable modules at build time ^[strings.txt:4811-4833]:
LICKEY:282E-3295-7AF9-B92DXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX— license-key format typical of MaaS/builder kits&hwid_— hardware-ID based license gatingfeatures— module toggle listexe_replacer,crypto_clipper,exodus_inject,discord_inject,discord_grabber,chrome,screenshot,systeminfo,extensions,wallets,keywords,telegram,desktop_apps,firefox,vs_projects,remote_desktop,data_encryptor,ransom_note,ransom_master_key_hex,clipper_addresses,worm_messages,worm_enabled
This is the first corpus sample to exhibit ransomware + worm + clipper + stealer + RAT modules in a single binary with explicit builder-style feature gating.
Credential Theft
Browser targeting covers Chrome, Edge, Brave, Opera, Opera GX ^[strings.txt:5310-5332]. SQLite queries mirror standard Chromium credential schemas:
SELECT origin_url,username_value,password_value FROM logins^[strings.txt:5278]SELECT host_key,name,path,is_secure,expires_utc,value,encrypted_value FROM cookies^[strings.txt:5276]SELECT name_on_card,expiration_month,expiration_year,card_number_encrypted FROM credit_cards^[strings.txt:5282]SELECT value_encrypted, nickname FROM local_ibans^[strings.txt:5285]SELECT service, encrypted_token, binding_key FROM token_service^[strings.txt:5295]
Chrome App-Bound Encryption (ABE) bypass is present via app_bound_encrypted_key string ^[strings.txt:5268], indicating capability to decrypt Chrome 127+ Login Data when ABE is enabled — a technique previously observed in afk-stealer and documented at app-bound-encryption-bypass.
Data is staged to TSV files (cookies.txt, cards.tsv, ibans.tsv, autofill.txt, tokens.tsv) ^[strings.txt:5298-5350].
Crypto Clipper
Hardcoded Ethereum RPC endpoints (15+ public nodes) for ENS resolution and clipboard monitoring ^[strings.txt:4971-4985]:
https://ethereum.publicnode.com,https://rpc.ankr.com/eth,https://eth-mainnet.public.blastapi.io,https://eth.llamarpc.com,https://ethereum-public.nodies.app,https://core.gashawk.io/rpc,https://eth.rpc.blxrbdn.com,https://rpc.mevblocker.io,https://rpc.builder0x69.io,https://rpc.flashbots.net,https://eth-mainnet.g.alchemy.com/v2/demo,https://eth-mainnet.gateway.pokt.network/v1/lb/6111567c0c9b8c0034f2f5c9,https://eth.nownodes.io
ENS resolver contract: 0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e (ENS Public Resolver v1) ^[strings.txt:4985].
Function signatures: resolver(bytes32), text(bytes32,string) ^[strings.txt:5005-5010] — confirming ENS text-record C2 resolution.
Key/seed string: JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz ^[strings.txt:5011] — likely ENS name decryption key or builder seed.
Remote Desktop / RAT
WebSocket C2 transport via WinHTTP WebSocket APIs ^[pefile.txt]:
WinHttpWebSocketCompleteUpgrade,WinHttpWebSocketSend,WinHttpWebSocketReceive,WinHttpWebSocketClose^[pefile.txt]wss://string ^[strings.txt:20476]Remote desktop: connect,viewer_connected,Remote desktop frame fatal^[strings.txt:20462-20471]
WTSAPI32 imports (WTSQuerySessionInformationW, WTSQueryUserToken, WTSEnumerateSessionsW) indicate terminal-services session hijacking / RDP manipulation ^[pefile.txt].
Anti-Analysis
VM/sandbox detection strings ^[strings.txt:5080-5124]:
- VirtualBox, VMware (Express/ESX/GSX/Workstation/Fusion/HardenedLoader), QEMU+KVM, QEMU+KVM Hyper-V Enlightenment, Parallels, Xen HVM, Hyper-V artifact, AWS Nitro System EC2 (KVM-based)
Debugger checks: IsDebuggerPresent, CheckRemoteDebuggerPresent ^[strings.txt:5266-5267].
Process Injection Surface
Extensive process manipulation imports ^[pefile.txt]:
WriteProcessMemory,ReadProcessMemory,VirtualProtectEx,CreateProcessW,SetThreadContext,GetThreadContext,SuspendThread,ResumeThread,OpenProcess,OpenThread,DebugActiveProcessStop,WaitForDebugEvent,ContinueDebugEvent
This supports process hollowing, thread hijacking, and debugger-based injection patterns.
Decompiled Behavior
Entry point 0x1401cec48 (entry0) initializes what appears to be a feature-gated bootstrap ^[r2:entry0]:
- Calls
fcn.1401ce53c()— likely anti-analysis / environment check (returns boolean inal) - If check fails, enters error path calling
fcn.1401cf088(7)twice — possibly sleep/delay or abort - Loads two vtable-like structures via
fcn.1401cf284()andfcn.1401cf28c(), validates non-null - Calls
fcn.1401e8060(0x14022fda8, 0x14022fc98)— string comparison or config lookup; xref from entry0 confirms0x14022fda8is a data reference ^[r2:xrefs_to:0x14022fda8] - Calls
fcn.1400a4920(rcx, r8, 0)— the main orchestrator. Decompilation reveals this function constructs command-line argument strings on the fly (--binder-child,--no-binder,--no-elevation,--persistence) by writing DWORDs into thread-local storage viags:[0x58]offsets, then callingfcn.1401d06fc()to check/presence-test each flag ^[r2:fcn.1400a4920]
The --binder-child, --no-binder, --no-elevation, --persistence argument construction strongly suggests the binary can re-spawn itself with different privilege or isolation flags — consistent with builder-kit process staging and UAC elevation patterns.
C2 Infrastructure
Primary C2 mechanism: ENS text-record resolution over Ethereum mainnet, followed by WebSocket C2.
| Indicator | Value | Source |
|---|---|---|
| ENS resolver contract | 0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e |
^[strings.txt:4985] |
| ENS registry function | resolver(bytes32) |
^[strings.txt:5009] |
| ENS resolver function | text(bytes32,string) |
^[strings.txt:5010] |
| RPC endpoints | 15+ public Ethereum nodes (see above) | ^[strings.txt:4971-4984] |
| Transport | WebSocket (wss://) via WinHTTP |
^[strings.txt:20476], ^[pefile.txt] |
| Key/seed | JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz |
^[strings.txt:5011] |
No hardcoded IP, domain, or traditional C2 URL was recovered. The ENS name itself is likely encrypted or derived from the JfR9z1!... seed.
Interesting Tidbits
- Builder-kit license format:
LICKEY:XXXX-XXXX-XXXX-XXXX...is identical to commercial software license patterns, suggesting the malware is sold as a builder with per-customer licensing ^[strings.txt:4811]. - SQLite 3.49.1: Very recent version (Feb 2025), indicating active development and modern dependency management ^[strings.txt:5025].
- No social-engineering masquerade: Filename
9BRIMp6CcY4y.exeis random alphanumeric, not a document lure. No VS_VERSIONINFO, no icons. The builder operator may apply masquerade at distribution time, not build time. - ChaCha20 quarter-round constant:
expand 32-byte kconfirms ChaCha20 use for payload/config encryption ^[strings.txt:5018]. Same constant seen in chacha8 family but different build stack (MSVC vs MinGW). - GDI+ and Media Foundation:
gdiplus.dll(screenshot encoding) +d3d11.dll/dxgi.dll/MF.dll/MFPlat.DLL/MFReadWrite.dllsuggest screen capture and media streaming capabilities for the remote-desktop module ^[pefile.txt]. - Windows Event Log queries:
wevtapi.dll(EvtQuery,EvtRender) for log clearing or reconnaissance ^[pefile.txt].
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2022 17.10+ (MSVC 14.50), C++17/20, x64 release build.
Key dependencies:
- nlohmann/json (single-header, v3.11.3+) for config/telemetry JSON
- SQLite 3.49.1 (amalgamation) for local credential staging
- WinHTTP (system) for WebSocket and HTTPS
- bcrypt.dll (CNG) for AES/ChaCha20 key operations
- GDI+ for screenshot capture
Compiler flags (inferred from PE):
/O2or/Ox(LTCG present — debug type IMAGE_DEBUG_TYPE_ILTCG ^[pefile.txt:1394])/fp:precise(.fptablesection present)/GS(canary enabled ^[rabin2-info.txt:6])/DYNAMICBASE/HIGHENTROPYVA/NXCOMPAT(DllCharacteristics 0x8160 ^[pefile.txt:384])
Verification: Build a minimal PE with nlohmann/json + SQLite + WinHTTP WebSocket imports + ChaCha20 constant string. Run capa (with signatures installed) and compare capability hits. This sample's capa failed due to missing signatures, not due to anti-analysis.
Deployable Signatures
YARA Rule
rule Unclassified_PE64_Modular_Builder
{
meta:
description = "MSVC 14.50 PE64 modular builder kit with ENS C2, ChaCha20, and feature gating"
author = "PacketPursuit"
date = "2026-08-26"
sha256 = "ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c"
strings:
$lickey = "LICKEY:"
$hwid = "&hwid_"
$features = "features"
$a1 = "exe_replacer"
$a2 = "crypto_clipper"
$a3 = "exodus_inject"
$a4 = "discord_inject"
$a5 = "discord_grabber"
$a6 = "data_encryptor"
$a7 = "ransom_note"
$a8 = "ransom_master_key_hex"
$a9 = "clipper_addresses"
$a10 = "worm_messages"
$a11 = "worm_enabled"
$a12 = "remote_desktop"
$chacha = "expand 32-byte k"
$ens = "0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e"
$eth1 = "eth_blockNumber"
$eth2 = "eth_call"
$ens1 = "resolver(bytes32)"
$ens2 = "text(bytes32,string)"
$key = "JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz"
$abe = "app_bound_encrypted_key"
$ws1 = "WinHttpWebSocketCompleteUpgrade"
$ws2 = "WinHttpWebSocketSend"
$ws3 = "WinHttpWebSocketReceive"
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)+0x18) == 0x20B and // PE32+
pe.number_of_sections >= 7 and
($lickey or $hwid or $features) and
4 of ($a*) and
($chacha or $ens or $key or $abe) and
2 of ($ws*)
}
Behavioral Hunt Query (KQL / Microsoft Sentinel)
let ens_resolver = "0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e";
let rpc_endpoints = dynamic([
"ethereum.publicnode.com", "rpc.ankr.com/eth", "eth-mainnet.public.blastapi.io",
"eth.llamarpc.com", "ethereum-public.nodies.app", "core.gashawk.io",
"eth.rpc.blxrbdn.com", "rpc.mevblocker.io", "rpc.builder0x69.io",
"rpc.flashbots.net", "eth-mainnet.g.alchemy.com", "eth-mainnet.gateway.pokt.network",
"eth.nownodes.io"]);
DeviceNetworkEvents
| where (RemoteUrl contains ens_resolver or RemoteUrl in (rpc_endpoints))
or (InitiatingProcessCommandLine contains "9BRIMp6CcY4y" or InitiatingProcessCommandLine contains "--binder-child")
| summarize count() by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c |
|
| Filename | 9BRIMp6CcY4y.exe |
Random alphanumeric; builder default |
| License prefix | LICKEY:282E-3295-7AF9-B92D |
Builder-kit fingerprint |
| Seed/key | JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz |
Likely ENS name decryption key |
| ENS resolver | 0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e |
Ethereum mainnet public resolver |
| ABE bypass string | app_bound_encrypted_key |
Chrome 127+ credential theft |
| ChaCha20 constant | expand 32-byte k |
Payload/config encryption |
| Staging files | cookies.txt, cards.tsv, ibans.tsv, autofill.txt, tokens.tsv |
Local TSV staging |
| Registry recon | read_registry_string |
System fingerprinting |
| System fields | cpu_brand, mac_address, gpu_name, disk_serial, computer_name, username, volume_serial, cpu_id, total_ram, bios_serial, baseboard, windows_id, screen_res |
Victim profiling |
Behavioral Fingerprint
This binary is a 9 MB MSVC 14.50 PE64+ with no version info, no exports, and no authenticode. It imports WinHTTP WebSocket APIs, bcrypt CNG, WTSAPI32 terminal services, GDI+, and Media Foundation. At runtime it resolves C2 via Ethereum ENS text records queried through public RPC nodes, then establishes a WebSocket-over-TLS session. It stages stolen browser credentials (Chrome/Edge/Brave/Opera including ABE-bypassed Chrome 127+ data) to local SQLite-backed TSV files, monitors the clipboard for cryptocurrency addresses, and can spawn child processes with --binder-child, --no-binder, --no-elevation, and --persistence command-line flags. It detects VirtualBox, VMware, QEMU, Parallels, Xen, Hyper-V, and AWS Nitro via string matching.
Detection Signatures
| MITRE ATT&CK | Technique | Evidence |
|---|---|---|
| T1555.003 | Credentials from Web Browsers / App-Bound Encryption Bypass | app_bound_encrypted_key, Chrome Local State path strings, ABE bypass capability ^[strings.txt:5268-5332] |
| T1071.001 | Application Layer Protocol: WebSockets | WinHttpWebSocket*, wss:// ^[pefile.txt], ^[strings.txt:20476] |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | VM vendor strings (VirtualBox, VMware, QEMU, Xen, etc.) ^[strings.txt:5080-5124] |
| T1055 | Process Injection | WriteProcessMemory, SetThreadContext, SuspendThread, ResumeThread, VirtualProtectEx ^[pefile.txt] |
| T1113 | Screen Capture | GDI+ imports, screenshot feature string, remote_desktop frame strings ^[pefile.txt], ^[strings.txt:4820] |
| T1115 | Clipboard Data | OpenClipboard, GetClipboardData, SetClipboardData, EmptyClipboard, crypto_clipper ^[pefile.txt], ^[strings.txt:4826] |
| T1083 | File and Directory Discovery | FindFirstFileW, FindNextFileW, GetLogicalDriveStringsW ^[pefile.txt] |
| T1012 | Query Registry | RegQueryValueExA/W, RegOpenKeyExW, read_registry_string ^[pefile.txt], ^[strings.txt:5436] |
| T1490 | Inhibit System Recovery | ransom_note, ransom_master_key_hex, data_encryptor ^[strings.txt:4831-4833] |
| T1491.001 | Defacement: Internal Defacement | worm_enabled, worm_messages ^[strings.txt:4834-4835] |
| T1559.001 | Inter-Process Communication: Component Object Model | CoTaskMemFree, CreateStreamOnHGlobal ^[pefile.txt] |
| T1567.002 | Exfiltration Over Web Service: WebSocket | WinHTTP WebSocket APIs, wss:// ^[pefile.txt], ^[strings.txt:20476] |
References
- Artifact ID:
aeff3457-f201-4a87-acb7-a8fa5e9a7dc5 - Source: OpenCTI / MalwareBazaar
- Related wiki pages: unclassified-pe64-modular-builder, ens-ethereum-c2-resolution, modular-builder-license-fingerprint, app-bound-encryption-bypass, websocket-c2-transport, chacha8, browser-credential-harvesting, clipboard-hijack-cryptocurrency
Provenance
Analysis based on static artifacts only (CAPE skipped — no Windows guest). Tools: file (PE32+ x64), exiftool (linker 14.50), pefile (sections, imports, debug types), rabin2 -I (no signing, canary, PIC), strings (capability strings, C2 indicators), binwalk (SQLite 3.x at 0x2497C8, XML manifest at 0x354A60), radare2 (entry0 decompilation, xrefs, function list, import list). Capa and floss failed due to environment issues. No dynamic execution available.