confidencehigh
SHA-256: eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6

Build / RE

Toolchain: MSVC 14.16 (VS2017), C++ with STL/Dinkumware runtime. ^[file.txt] ^[exiftool.json] Packing: UPX (three sections: UPX0, UPX1, .rsrc). Raw 352 KB unpacks to 884 KB. ^[file.txt] ^[pefile.txt] Anti-analysis: IsDebuggerPresent imported; VT tags detect-debug-environment. No VM-detection strings. ^[capa.txt] ^[r2:list_imports] Resources: RT_RCDATA blob at file offset 0xD2BBC, size 0x1375; encrypted/compressed, not plaintext. Likely holds ransom note or JSON config. ^[pefile.txt:433] ^[binwalk.txt] Crypto: ChaCha20 quarter-round constants (expa, nd 3, 2-by, te k) at 0x408379; key-schedule function fcn.00408050 implements the 10-round loop. No AES/RC4/SHA imports. ^[r2:fcn.00408050] Code quality: Heavy C++ STL (std::codecvt, std::vector); embeds markondej/cpp-icmplib for ICMP socket classes. ^[strings.txt] ^[floss.txt:error]

Deploy / ATT&CK

ID Technique Evidence
T1486 Data Encrypted for Impact ChaCha20 constants + encryption routine ^[r2:fcn.00408050]
T1547.001 Registry Run Keys / Startup Folder SOFTWARE\Microsoft\Windows\CurrentVersion\Run value Microsoft Edge Update ^[floss.txt:157]
T1490 Inhibit System Recovery bcdedit disable recovery/bootstatuspolicy; wbadmin delete catalog; shadow-copy WMI deletion ^[floss.txt:162-169]
T1491.001 Defacement: Internal Defacement Hyper-V VM stop / VHD dismount / BitLocker suspension via PowerShell ^[floss.txt:170-173] ^[floss.txt:250]
T1070.001 Indicator Removal: Clear Windows Event Logs wevtutil.exe cl application/security/system ^[floss.txt:274-276]
T1070.004 File Deletion Self-erasure: fsutil setZeroData offset=0 length=20000000 then Del /f /q /a *.exe *.bat ... ^[floss.txt:244]
T1489 Service Stop Stops: defragsvc, wercplsupport, TroubleshootingSvc, wbengine, AppIDSvc, wuauserv, DiagTrack, dmwappushservice, WMPNetworkSvc ^[floss.txt:259-268]
T1083 File and Directory Discovery FindFirstFileW, FindNextFileW imports ^[r2:list_imports]
T1135 Network Share Discovery WNetOpenEnumW, NetShareEnum ^[pefile.txt:240]
T1016 System Network Configuration Discovery GetAdaptersInfo, GetIpNetTable, ICMP socket classes ^[pefile.txt:217] ^[strings.txt]
T1105 Ingress Tool Transfer Embedded RCDATA likely holds ransom note or config JSON ^[pefile.txt:433]

Persistence — Registry Run key masquerading as Microsoft Edge Update. ^[floss.txt:157]

Anti-recovery — Boot config tampering (bcdedit), backup deletion (wbadmin), shadow-copy WMI query, and event-log clearing (wevtutil). ^[floss.txt:162-169] ^[floss.txt:274-276]

VM destruction — PowerShell one-liners to Stop-VM, Dismount-DiskImage on VHDs, and Suspend-BitLocker. ^[floss.txt:170-173] ^[floss.txt:250]

Network — No C2 URLs, IPs, or emails found in strings. Imports include WS2_32.dll (socket, sendto, recvfrom), IPHLPAPI.DLL (GetAdaptersInfo, GetIpNetTable), MPR.dll (WNetOpenEnumW), and NETAPI32.dll (NetShareEnum) — consistent with LAN reconnaissance and ICMP host discovery. ^[r2:list_imports] ^[pefile.txt:197-331]

Attribution — PAY2KEY_LOG.txt string at offset 0x59D93 (unpacked) is the family anchor. ^[floss.txt:179] GUID {3E5FC7F9-9A51-4367-9063-A120244FBEC7} at offset 0x5B209. ^[floss.txt:270] VT detections cluster around "Pay2Key" / Iranian Fox Kitten activity. JSON-like config fragment at 0xb6078 with fields token, type, host, user, uptime, platform, f_count, f_mb, finish, duration — telemetry/C2 payload structure.

Confidence: high on family (Pay2Key). Medium on C2 details (no network IOCs observed statically). No CAPE detonation available.