eef5cb41b2c7fe11ce2a0b05de8c6ed583286a0bbc8c632aa073772dcad3efc6Build / RE
Toolchain: MSVC 14.16 (VS2017), C++ with STL/Dinkumware runtime. ^[file.txt] ^[exiftool.json]
Packing: UPX (three sections: UPX0, UPX1, .rsrc). Raw 352 KB unpacks to 884 KB. ^[file.txt] ^[pefile.txt]
Anti-analysis: IsDebuggerPresent imported; VT tags detect-debug-environment. No VM-detection strings. ^[capa.txt] ^[r2:list_imports]
Resources: RT_RCDATA blob at file offset 0xD2BBC, size 0x1375; encrypted/compressed, not plaintext. Likely holds ransom note or JSON config. ^[pefile.txt:433] ^[binwalk.txt]
Crypto: ChaCha20 quarter-round constants (expa, nd 3, 2-by, te k) at 0x408379; key-schedule function fcn.00408050 implements the 10-round loop. No AES/RC4/SHA imports. ^[r2:fcn.00408050]
Code quality: Heavy C++ STL (std::codecvt, std::vector); embeds markondej/cpp-icmplib for ICMP socket classes. ^[strings.txt] ^[floss.txt:error]
Deploy / ATT&CK
| ID | Technique | Evidence |
|---|---|---|
| T1486 | Data Encrypted for Impact | ChaCha20 constants + encryption routine ^[r2:fcn.00408050] |
| T1547.001 | Registry Run Keys / Startup Folder | SOFTWARE\Microsoft\Windows\CurrentVersion\Run value Microsoft Edge Update ^[floss.txt:157] |
| T1490 | Inhibit System Recovery | bcdedit disable recovery/bootstatuspolicy; wbadmin delete catalog; shadow-copy WMI deletion ^[floss.txt:162-169] |
| T1491.001 | Defacement: Internal Defacement | Hyper-V VM stop / VHD dismount / BitLocker suspension via PowerShell ^[floss.txt:170-173] ^[floss.txt:250] |
| T1070.001 | Indicator Removal: Clear Windows Event Logs | wevtutil.exe cl application/security/system ^[floss.txt:274-276] |
| T1070.004 | File Deletion | Self-erasure: fsutil setZeroData offset=0 length=20000000 then Del /f /q /a *.exe *.bat ... ^[floss.txt:244] |
| T1489 | Service Stop | Stops: defragsvc, wercplsupport, TroubleshootingSvc, wbengine, AppIDSvc, wuauserv, DiagTrack, dmwappushservice, WMPNetworkSvc ^[floss.txt:259-268] |
| T1083 | File and Directory Discovery | FindFirstFileW, FindNextFileW imports ^[r2:list_imports] |
| T1135 | Network Share Discovery | WNetOpenEnumW, NetShareEnum ^[pefile.txt:240] |
| T1016 | System Network Configuration Discovery | GetAdaptersInfo, GetIpNetTable, ICMP socket classes ^[pefile.txt:217] ^[strings.txt] |
| T1105 | Ingress Tool Transfer | Embedded RCDATA likely holds ransom note or config JSON ^[pefile.txt:433] |
Persistence — Registry Run key masquerading as Microsoft Edge Update. ^[floss.txt:157]
Anti-recovery — Boot config tampering (bcdedit), backup deletion (wbadmin), shadow-copy WMI query, and event-log clearing (wevtutil). ^[floss.txt:162-169] ^[floss.txt:274-276]
VM destruction — PowerShell one-liners to Stop-VM, Dismount-DiskImage on VHDs, and Suspend-BitLocker. ^[floss.txt:170-173] ^[floss.txt:250]
Network — No C2 URLs, IPs, or emails found in strings. Imports include WS2_32.dll (socket, sendto, recvfrom), IPHLPAPI.DLL (GetAdaptersInfo, GetIpNetTable), MPR.dll (WNetOpenEnumW), and NETAPI32.dll (NetShareEnum) — consistent with LAN reconnaissance and ICMP host discovery. ^[r2:list_imports] ^[pefile.txt:197-331]
Attribution — PAY2KEY_LOG.txt string at offset 0x59D93 (unpacked) is the family anchor. ^[floss.txt:179] GUID {3E5FC7F9-9A51-4367-9063-A120244FBEC7} at offset 0x5B209. ^[floss.txt:270] VT detections cluster around "Pay2Key" / Iranian Fox Kitten activity. JSON-like config fragment at 0xb6078 with fields token, type, host, user, uptime, platform, f_count, f_mb, finish, duration — telemetry/C2 payload structure.
Confidence: high on family (Pay2Key). Medium on C2 details (no network IOCs observed statically). No CAPE detonation available.