typeanalysisfamilyunclassified-pe64-modular-builderconfidencelowpemalware-familycompilerobfuscationc2exfiltrationpersistencedefense-evasiondiscoveryimpactmitre-attck
SHA-256: ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c

unclassified-pe64-modular-builder: ec95bcf4 — MSVC 14.50 full-spectrum modular kit with ENS C2, ChaCha20, and app-bound encryption bypass

Executive Summary

A 9 MB PE32+ x64 binary compiled with MSVC 14.50 (May 2026) that presents as a modular malware builder kit. Static evidence reveals 17+ selectable modules spanning credential theft, crypto clipping, remote desktop, Discord/Exodus injection, data encryption, and worm propagation. C2 is resolved via Ethereum Name Service (ENS) text records queried through 15+ public RPC endpoints, with WebSocket transport for command-and-control. Includes Chrome App-Bound Encryption bypass, SQLite 3.49.1 for local data staging, and extensive VM/sandbox detection. No siblings confirmed in corpus; singleton pending cluster.

What It Is

Field Value
SHA-256 ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c
Filename 9BRIMp6CcY4y.exe ^[metadata.json]
Type PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
Size 8,956,723 bytes ^[triage.json]
Linker MSVC 14.50 (VS 2022 17.10+) ^[exiftool.json:18]
Timestamp Sun May 17 03:23:18 2026 UTC ^[pefile.txt:352]
Signed No ^[rabin2-info.txt:27]
VS_VERSIONINFO Absent ^[pefile.txt]
PDB None (debug type IMAGE_DEBUG_TYPE_POGO + ILTCG) ^[pefile.txt:1379-1394]
Capa Failed (missing signatures) ^[capa.txt]
Floss Failed (argument parsing error) ^[floss.txt]
CAPE Skipped — no Windows guest available ^[dynamic-analysis.md]

Build artifacts: C++ STL heavy RTTI, nlohmann/json exception strings (json.exception.*, parse_error), SQLite 3.49.1 runtime, ChaCha20 quarter-round constant expand 32-byte k ^[strings.txt:5018], MSVC .fptable floating-point constant section (entropy 0.0) ^[pefile.txt:476-493]. No packing observed; .text entropy 6.53, .rdata 4.95.

How It Works

Builder-Kit Architecture

The binary carries a hardcoded license key and a features bitmask/string table indicating selectable modules at build time ^[strings.txt:4811-4833]:

  • LICKEY:282E-3295-7AF9-B92DXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX — license-key format typical of MaaS/builder kits
  • &hwid_ — hardware-ID based license gating
  • features — module toggle list
  • exe_replacer, crypto_clipper, exodus_inject, discord_inject, discord_grabber, chrome, screenshot, systeminfo, extensions, wallets, keywords, telegram, desktop_apps, firefox, vs_projects, remote_desktop, data_encryptor, ransom_note, ransom_master_key_hex, clipper_addresses, worm_messages, worm_enabled

This is the first corpus sample to exhibit ransomware + worm + clipper + stealer + RAT modules in a single binary with explicit builder-style feature gating.

Credential Theft

Browser targeting covers Chrome, Edge, Brave, Opera, Opera GX ^[strings.txt:5310-5332]. SQLite queries mirror standard Chromium credential schemas:

  • SELECT origin_url,username_value,password_value FROM logins ^[strings.txt:5278]
  • SELECT host_key,name,path,is_secure,expires_utc,value,encrypted_value FROM cookies ^[strings.txt:5276]
  • SELECT name_on_card,expiration_month,expiration_year,card_number_encrypted FROM credit_cards ^[strings.txt:5282]
  • SELECT value_encrypted, nickname FROM local_ibans ^[strings.txt:5285]
  • SELECT service, encrypted_token, binding_key FROM token_service ^[strings.txt:5295]

Chrome App-Bound Encryption (ABE) bypass is present via app_bound_encrypted_key string ^[strings.txt:5268], indicating capability to decrypt Chrome 127+ Login Data when ABE is enabled — a technique previously observed in afk-stealer and documented at app-bound-encryption-bypass.

Data is staged to TSV files (cookies.txt, cards.tsv, ibans.tsv, autofill.txt, tokens.tsv) ^[strings.txt:5298-5350].

Crypto Clipper

Hardcoded Ethereum RPC endpoints (15+ public nodes) for ENS resolution and clipboard monitoring ^[strings.txt:4971-4985]:

  • https://ethereum.publicnode.com, https://rpc.ankr.com/eth, https://eth-mainnet.public.blastapi.io, https://eth.llamarpc.com, https://ethereum-public.nodies.app, https://core.gashawk.io/rpc, https://eth.rpc.blxrbdn.com, https://rpc.mevblocker.io, https://rpc.builder0x69.io, https://rpc.flashbots.net, https://eth-mainnet.g.alchemy.com/v2/demo, https://eth-mainnet.gateway.pokt.network/v1/lb/6111567c0c9b8c0034f2f5c9, https://eth.nownodes.io

ENS resolver contract: 0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e (ENS Public Resolver v1) ^[strings.txt:4985]. Function signatures: resolver(bytes32), text(bytes32,string) ^[strings.txt:5005-5010] — confirming ENS text-record C2 resolution.

Key/seed string: JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz ^[strings.txt:5011] — likely ENS name decryption key or builder seed.

Remote Desktop / RAT

WebSocket C2 transport via WinHTTP WebSocket APIs ^[pefile.txt]:

  • WinHttpWebSocketCompleteUpgrade, WinHttpWebSocketSend, WinHttpWebSocketReceive, WinHttpWebSocketClose ^[pefile.txt]
  • wss:// string ^[strings.txt:20476]
  • Remote desktop: connect, viewer_connected, Remote desktop frame fatal ^[strings.txt:20462-20471]

WTSAPI32 imports (WTSQuerySessionInformationW, WTSQueryUserToken, WTSEnumerateSessionsW) indicate terminal-services session hijacking / RDP manipulation ^[pefile.txt].

Anti-Analysis

VM/sandbox detection strings ^[strings.txt:5080-5124]:

  • VirtualBox, VMware (Express/ESX/GSX/Workstation/Fusion/HardenedLoader), QEMU+KVM, QEMU+KVM Hyper-V Enlightenment, Parallels, Xen HVM, Hyper-V artifact, AWS Nitro System EC2 (KVM-based)

Debugger checks: IsDebuggerPresent, CheckRemoteDebuggerPresent ^[strings.txt:5266-5267].

Process Injection Surface

Extensive process manipulation imports ^[pefile.txt]:

  • WriteProcessMemory, ReadProcessMemory, VirtualProtectEx, CreateProcessW, SetThreadContext, GetThreadContext, SuspendThread, ResumeThread, OpenProcess, OpenThread, DebugActiveProcessStop, WaitForDebugEvent, ContinueDebugEvent

This supports process hollowing, thread hijacking, and debugger-based injection patterns.

Decompiled Behavior

Entry point 0x1401cec48 (entry0) initializes what appears to be a feature-gated bootstrap ^[r2:entry0]:

  1. Calls fcn.1401ce53c() — likely anti-analysis / environment check (returns boolean in al)
  2. If check fails, enters error path calling fcn.1401cf088(7) twice — possibly sleep/delay or abort
  3. Loads two vtable-like structures via fcn.1401cf284() and fcn.1401cf28c(), validates non-null
  4. Calls fcn.1401e8060(0x14022fda8, 0x14022fc98) — string comparison or config lookup; xref from entry0 confirms 0x14022fda8 is a data reference ^[r2:xrefs_to:0x14022fda8]
  5. Calls fcn.1400a4920(rcx, r8, 0) — the main orchestrator. Decompilation reveals this function constructs command-line argument strings on the fly (--binder-child, --no-binder, --no-elevation, --persistence) by writing DWORDs into thread-local storage via gs:[0x58] offsets, then calling fcn.1401d06fc() to check/presence-test each flag ^[r2:fcn.1400a4920]

The --binder-child, --no-binder, --no-elevation, --persistence argument construction strongly suggests the binary can re-spawn itself with different privilege or isolation flags — consistent with builder-kit process staging and UAC elevation patterns.

C2 Infrastructure

Primary C2 mechanism: ENS text-record resolution over Ethereum mainnet, followed by WebSocket C2.

Indicator Value Source
ENS resolver contract 0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e ^[strings.txt:4985]
ENS registry function resolver(bytes32) ^[strings.txt:5009]
ENS resolver function text(bytes32,string) ^[strings.txt:5010]
RPC endpoints 15+ public Ethereum nodes (see above) ^[strings.txt:4971-4984]
Transport WebSocket (wss://) via WinHTTP ^[strings.txt:20476], ^[pefile.txt]
Key/seed JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz ^[strings.txt:5011]

No hardcoded IP, domain, or traditional C2 URL was recovered. The ENS name itself is likely encrypted or derived from the JfR9z1!... seed.

Interesting Tidbits

  • Builder-kit license format: LICKEY:XXXX-XXXX-XXXX-XXXX... is identical to commercial software license patterns, suggesting the malware is sold as a builder with per-customer licensing ^[strings.txt:4811].
  • SQLite 3.49.1: Very recent version (Feb 2025), indicating active development and modern dependency management ^[strings.txt:5025].
  • No social-engineering masquerade: Filename 9BRIMp6CcY4y.exe is random alphanumeric, not a document lure. No VS_VERSIONINFO, no icons. The builder operator may apply masquerade at distribution time, not build time.
  • ChaCha20 quarter-round constant: expand 32-byte k confirms ChaCha20 use for payload/config encryption ^[strings.txt:5018]. Same constant seen in chacha8 family but different build stack (MSVC vs MinGW).
  • GDI+ and Media Foundation: gdiplus.dll (screenshot encoding) + d3d11.dll/dxgi.dll/MF.dll/MFPlat.DLL/MFReadWrite.dll suggest screen capture and media streaming capabilities for the remote-desktop module ^[pefile.txt].
  • Windows Event Log queries: wevtapi.dll (EvtQuery, EvtRender) for log clearing or reconnaissance ^[pefile.txt].

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2022 17.10+ (MSVC 14.50), C++17/20, x64 release build.

Key dependencies:

  • nlohmann/json (single-header, v3.11.3+) for config/telemetry JSON
  • SQLite 3.49.1 (amalgamation) for local credential staging
  • WinHTTP (system) for WebSocket and HTTPS
  • bcrypt.dll (CNG) for AES/ChaCha20 key operations
  • GDI+ for screenshot capture

Compiler flags (inferred from PE):

  • /O2 or /Ox (LTCG present — debug type IMAGE_DEBUG_TYPE_ILTCG ^[pefile.txt:1394])
  • /fp:precise (.fptable section present)
  • /GS (canary enabled ^[rabin2-info.txt:6])
  • /DYNAMICBASE / HIGHENTROPYVA / NXCOMPAT (DllCharacteristics 0x8160 ^[pefile.txt:384])

Verification: Build a minimal PE with nlohmann/json + SQLite + WinHTTP WebSocket imports + ChaCha20 constant string. Run capa (with signatures installed) and compare capability hits. This sample's capa failed due to missing signatures, not due to anti-analysis.

Deployable Signatures

YARA Rule

rule Unclassified_PE64_Modular_Builder
{
    meta:
        description = "MSVC 14.50 PE64 modular builder kit with ENS C2, ChaCha20, and feature gating"
        author = "PacketPursuit"
        date = "2026-08-26"
        sha256 = "ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c"
    strings:
        $lickey = "LICKEY:"
        $hwid = "&hwid_"
        $features = "features"
        $a1 = "exe_replacer"
        $a2 = "crypto_clipper"
        $a3 = "exodus_inject"
        $a4 = "discord_inject"
        $a5 = "discord_grabber"
        $a6 = "data_encryptor"
        $a7 = "ransom_note"
        $a8 = "ransom_master_key_hex"
        $a9 = "clipper_addresses"
        $a10 = "worm_messages"
        $a11 = "worm_enabled"
        $a12 = "remote_desktop"
        $chacha = "expand 32-byte k"
        $ens = "0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e"
        $eth1 = "eth_blockNumber"
        $eth2 = "eth_call"
        $ens1 = "resolver(bytes32)"
        $ens2 = "text(bytes32,string)"
        $key = "JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz"
        $abe = "app_bound_encrypted_key"
        $ws1 = "WinHttpWebSocketCompleteUpgrade"
        $ws2 = "WinHttpWebSocketSend"
        $ws3 = "WinHttpWebSocketReceive"
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)+0x18) == 0x20B and // PE32+
        pe.number_of_sections >= 7 and
        ($lickey or $hwid or $features) and
        4 of ($a*) and
        ($chacha or $ens or $key or $abe) and
        2 of ($ws*)
}

Behavioral Hunt Query (KQL / Microsoft Sentinel)

let ens_resolver = "0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e";
let rpc_endpoints = dynamic([
    "ethereum.publicnode.com", "rpc.ankr.com/eth", "eth-mainnet.public.blastapi.io",
    "eth.llamarpc.com", "ethereum-public.nodies.app", "core.gashawk.io",
    "eth.rpc.blxrbdn.com", "rpc.mevblocker.io", "rpc.builder0x69.io",
    "rpc.flashbots.net", "eth-mainnet.g.alchemy.com", "eth-mainnet.gateway.pokt.network",
    "eth.nownodes.io"]);
DeviceNetworkEvents
| where (RemoteUrl contains ens_resolver or RemoteUrl in (rpc_endpoints))
    or (InitiatingProcessCommandLine contains "9BRIMp6CcY4y" or InitiatingProcessCommandLine contains "--binder-child")
| summarize count() by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl

IOC List

Type Value Notes
SHA-256 ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c
Filename 9BRIMp6CcY4y.exe Random alphanumeric; builder default
License prefix LICKEY:282E-3295-7AF9-B92D Builder-kit fingerprint
Seed/key JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz Likely ENS name decryption key
ENS resolver 0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e Ethereum mainnet public resolver
ABE bypass string app_bound_encrypted_key Chrome 127+ credential theft
ChaCha20 constant expand 32-byte k Payload/config encryption
Staging files cookies.txt, cards.tsv, ibans.tsv, autofill.txt, tokens.tsv Local TSV staging
Registry recon read_registry_string System fingerprinting
System fields cpu_brand, mac_address, gpu_name, disk_serial, computer_name, username, volume_serial, cpu_id, total_ram, bios_serial, baseboard, windows_id, screen_res Victim profiling

Behavioral Fingerprint

This binary is a 9 MB MSVC 14.50 PE64+ with no version info, no exports, and no authenticode. It imports WinHTTP WebSocket APIs, bcrypt CNG, WTSAPI32 terminal services, GDI+, and Media Foundation. At runtime it resolves C2 via Ethereum ENS text records queried through public RPC nodes, then establishes a WebSocket-over-TLS session. It stages stolen browser credentials (Chrome/Edge/Brave/Opera including ABE-bypassed Chrome 127+ data) to local SQLite-backed TSV files, monitors the clipboard for cryptocurrency addresses, and can spawn child processes with --binder-child, --no-binder, --no-elevation, and --persistence command-line flags. It detects VirtualBox, VMware, QEMU, Parallels, Xen, Hyper-V, and AWS Nitro via string matching.

Detection Signatures

MITRE ATT&CK Technique Evidence
T1555.003 Credentials from Web Browsers / App-Bound Encryption Bypass app_bound_encrypted_key, Chrome Local State path strings, ABE bypass capability ^[strings.txt:5268-5332]
T1071.001 Application Layer Protocol: WebSockets WinHttpWebSocket*, wss:// ^[pefile.txt], ^[strings.txt:20476]
T1497.001 Virtualization/Sandbox Evasion: System Checks VM vendor strings (VirtualBox, VMware, QEMU, Xen, etc.) ^[strings.txt:5080-5124]
T1055 Process Injection WriteProcessMemory, SetThreadContext, SuspendThread, ResumeThread, VirtualProtectEx ^[pefile.txt]
T1113 Screen Capture GDI+ imports, screenshot feature string, remote_desktop frame strings ^[pefile.txt], ^[strings.txt:4820]
T1115 Clipboard Data OpenClipboard, GetClipboardData, SetClipboardData, EmptyClipboard, crypto_clipper ^[pefile.txt], ^[strings.txt:4826]
T1083 File and Directory Discovery FindFirstFileW, FindNextFileW, GetLogicalDriveStringsW ^[pefile.txt]
T1012 Query Registry RegQueryValueExA/W, RegOpenKeyExW, read_registry_string ^[pefile.txt], ^[strings.txt:5436]
T1490 Inhibit System Recovery ransom_note, ransom_master_key_hex, data_encryptor ^[strings.txt:4831-4833]
T1491.001 Defacement: Internal Defacement worm_enabled, worm_messages ^[strings.txt:4834-4835]
T1559.001 Inter-Process Communication: Component Object Model CoTaskMemFree, CreateStreamOnHGlobal ^[pefile.txt]
T1567.002 Exfiltration Over Web Service: WebSocket WinHTTP WebSocket APIs, wss:// ^[pefile.txt], ^[strings.txt:20476]

References

Provenance

Analysis based on static artifacts only (CAPE skipped — no Windows guest). Tools: file (PE32+ x64), exiftool (linker 14.50), pefile (sections, imports, debug types), rabin2 -I (no signing, canary, PIC), strings (capability strings, C2 indicators), binwalk (SQLite 3.x at 0x2497C8, XML manifest at 0x354A60), radare2 (entry0 decompilation, xrefs, function list, import list). Capa and floss failed due to environment issues. No dynamic execution available.