f016df16d0f34aaae36bf10e0ca6bccdce2a4d552fcc6444e6f48318ef0b2c4ablackmatter: f016df16 — twenty-fourth confirmed sibling in MSVC 14.12 PEB-walking reflective-loader cluster
Executive Summary
A 150 KB PE32 GUI binary compiled with MSVC 14.12 (VS 2017 15.5+) on 9 Sep 2022. Tagged blackmatter and dropped-by-phorpiex by OpenCTI. Static analysis confirms it is a binary twin of the unattributed MSVC reflective-loader cluster (136b5750, 9d8526b0, etc.) — same stub, same compilation timestamp, same .text hash, same XOR key 0x10035fff, same anti-analysis gates, same LCG PRNG. The only delta is an individualized encrypted .data payload and a unique PE checksum. This is the twenty-fourth confirmed sibling in the cluster. Static-only (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | f016df16d0f34aaae36bf10e0ca6bccdce2a4d552fcc6444e6f48318ef0b2c4a |
| Size | 149,504 bytes (150 KB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | MSVC 14.12 — Visual Studio 2017 15.5+ ^[exiftool.json] |
| Timestamp | 0x631A9665 — Fri Sep 9 01:27:01 2022 UTC ^[pefile.txt] |
| Debug | POGO (IMAGE_DEBUG_TYPE_POGO, size 0xF4) ^[pefile.txt] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt] |
| Canary | Enabled ^[rabin2-info.txt] |
| Signed | Unsigned ^[rabin2-info.txt] |
| Overlay | None ^[rabin2-info.txt] |
| Static imports | Minimal facade: GDI32 (6), USER32 (11), KERNEL32 (8) GUI functions only ^[pefile.txt] |
| YARA | Generic PE only ^[yara.txt] |
Section Hashes
| Section | Size | MD5 | SHA-256 | Entropy |
|---|---|---|---|---|
.text |
97,792 | cfbda2c44e51b3b0b00bcbbc767c62a2 |
000a9a8b1440e44cde00fd7acc5bdda6efc34f09e404de77cff1f5298e0af369 |
6.6341 |
.itext |
1,536 | 6f4cd57381bb5584c0a0755384d25180 |
38f20ce7e2c9381f3a07f666269d4f509565f5aa40d19aa383a8afd583bf60c2 |
2.9337 |
.rdata |
1,536 | bd829aa493ecd52fe5bec776d207f206 |
ce47d70dffec241b1a8e768bc48eb91352a2275202b52ec299995bdee67a426a |
3.5366 |
.data |
40,960 | da17379db90b4a18e8632b19a623a245 |
e4c7fc9440e0badcf119b682b8ca892f783f151fb1e34bf0ffbdcc4e10535816 |
7.9871 |
.pdata |
2,560 | b07bc1ec7fa32feb56ec3b41e5e8c15e |
9e14162f553aa81b98b6e007f54dfb83187bfdbc04f85b01885a3cf7f6ba2864 |
7.3351 |
.reloc |
4,096 | 3f87e4c23650dfad0bee7da98889ba94 |
7b8a35469d264f92e4d13f7537e5ee98d40b2776426c0ad90298326533ad9e5e |
6.7390 |
The .text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 matches the majority of the cluster (siblings 136b5750, 9d8526b0, 0b525c35, 370415c8, c527ebf0, d715b248, f8850a32, 73841818, 0017ecc5, 34ca794e, a2dca6ef, cdc7d79a, ae02bd22, 7e9bbc5c, e67dbabcd, 2ac8295381, 89dc341bbd, 8655b3b9b2, 91e39f6bb60a, 65844473d39b, 044539a2eacf). The .data SHA-256 is unique per sibling, confirming individualized payload injection.
How It Works
Identical to sibling 136b5750 and all confirmed twins. See the primary report for full decompiled details:
/intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
Behavioral summary:
- Entry Point (
0x41946FRVA) → delegates to runtime orchestrator at0x417034. - PEB-Walking API Resolution — walks
InMemoryOrderModuleListviafs:[0x30], resolves ~30+ threat APIs by export hash, caches in.datapseudo-import table at0x425xxx. ^[techniques/peb-walking-api-resolution.md] - String Encryption — XOR
0x10035fffthen NOT; builds a base-62 alphabet table (A-Z a-z 0-9). C2 URLs and User-Agent are generated at runtime via LCG PRNG + alphabet lookup. ^[r2:fcn.0040123d] - Anti-VM / Anti-Debug — CPUID leaf 1 ECX[31] (hypervisor bit) and leaf 7 EBX[18]; RDTSC differential timing with rotate-13. ^[r2:fcn.004010bc]
- LCG PRNG —
seed = (seed * 0x19660d + 0x3c6ef35f) & 0x7ffffff. ^[r2:fcn.00401109] - Network / C2 — HTTP POST body assembly with encrypted payload; WinInet handle allocation. No hard-coded domains. ^[r2:fcn.00406665]
- File-System Enumeration — recursive
"*"wildcard enumeration via resolvedFindFirstFile/FindNextFile. - Reflective Loader —
VirtualAlloc→ write decrypted payload →VirtualProtect→ thread creation.
Decompiled Behavior
| Address | Role | Evidence |
|---|---|---|
0x4010bc |
Anti-debug/VM gate | CPUID leaf 1 ECX[31] + leaf 7 EBX[18]; RDTSC rotate-13 timing ^[r2:fcn.004010bc] |
0x401109 |
LCG PRNG stub | Multiplier 0x19660d, increment 0x3c6ef35f ^[r2:fcn.00401109] |
0x40123d |
Decrypt stub | XOR 0x10035fff then NOT ^[r2:fcn.0040123d] |
0x406665 |
Reflective mapper / network init | Allocates memory, resolves handles, builds HTTP POST body ^[r2:fcn.00406665] |
0x417034 |
Main orchestrator | PEB-walk, thread creation, flag-gated execution |
C2 Infrastructure
No hard-coded C2 endpoints. Runtime-generated via LCG + alphabet table. See 136b5750 report for detailed inference.
Interesting Tidbits
- Twenty-fourth sibling: The
.texthashcfbda2c4...confirms this sample belongs to the majority stub group within the cluster. The PE checksum (0x306e9) and unique.datapayload confirm per-sample customization. - BlackMatter mislabel persists: OpenCTI continues tagging these as
blackmatter, but no ransomware behavior is present. The label is a false-positive attribution from upstream clustering. ^[triage.json] - Phorpiex delivery chain: The
dropped-by-phorpiextag is accurate for delivery — these loaders are distributed by Phorpiex spam infrastructure — but the payload itself is a distinct MSVC reflective loader, not a Phorpiex downloader. ^[metadata.json] - GUI subsystem decoy: Declares
Windows GUIwith minimal USER32/GDI32 imports, but no window-creation logic in the entry path. The imports are scaffolding. ^[file.txt]
How To Mess With It (Homelab Replication)
See 136b5750 report — identical stub template. Reproduce the PEB-walker, XOR-NOT cipher, LCG PRNG, and CPUID anti-VM gate. Per-sample customization is limited to the encrypted .data payload blob.
Deployable Signatures
YARA Rule
rule blackmatter_f016df16_msvc_pe32_reflective_loader
{
meta:
description = "MSVC 14.12 PE32 reflective loader twin (blackmatter OpenCTI label) with PEB-walking API resolution and XOR-NOT string crypto"
author = "PacketPursuit"
date = "2026-08-29"
sha256 = "f016df16d0f34aaae36bf10e0ca6bccdce2a4d552fcc6444e6f48318ef0b2c4a"
strings:
$xor_not_key = { 81 31 FF 5F 03 10 }
$lcg_mul = { 0D 66 19 00 00 }
$lcg_inc = { 35 3C EF C6 03 }
$lcg_mask = { 25 FF FF FF 07 }
$alphabet_1 = { 41 BB BF EA }
$alphabet_2 = { 45 E6 BB A7 }
$post_wide = { 50 A0 B3 EF 53 A0 A8 EF 00 A0 FC EF }
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C) + 0x18) == 0x10B and
2 of ($xor_not_*) and
2 of ($lcg_*) and
2 of ($alphabet_*) and
$post_wide
}
Behavioral Fingerprint
This binary presents a minimal import table (GDI32, USER32, KERNEL32 GUI functions only). Within seconds of execution, it walks the PEB InMemoryOrderModuleList to resolve VirtualAlloc, CreateThread, InternetOpen, and cryptographic APIs by export hash, caching pointers in a
.datapseudo-import table. It allocates RWX memory, maps a decrypted payload, and spawns parallel threads for file-system enumeration (FindFirstFilewith"*"wildcard) and HTTP POST C2 communication. The POST body is encrypted; C2 domain and User-Agent are generated at runtime via a seeded LCG PRNG indexing a base-62 alphabet table. VM execution triggers altered paths via CPUID hypervisor-bit checks and RDTSC timing gates.
IOCs
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | f016df16d0f34aaae36bf10e0ca6bccdce2a4d552fcc6444e6f48318ef0b2c4a |
This sample (24th sibling) |
| SHA-256 (primary twin) | 136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51 |
Primary analysis |
| Compilation | Sep 9 2022 01:27:01 UTC | Timestamp 0x631A9665 (shared across cluster) |
| Linker | 14.12 | VS 2017 15.5+ |
| PE checksum | 0x306e9 |
Unique per sibling |
| .text MD5 | cfbda2c44e51b3b0b00bcbbc767c62a2 |
Majority group stub hash |
| .data SHA-256 | e4c7fc9440e0badcf119b682b8ca892f783f151fb1e34bf0ffbdcc4e10535816 |
Individualized payload |
| XOR Key | 0x10035fff |
String + pointer encryption |
| LCG multiplier | 0x19660d |
PRNG constant |
| LCG increment | 0x3c6ef35f |
PRNG constant |
Detection Signatures
| ATT&CK Technique | Implementation |
|---|---|
| T1055 — Process Injection | Reflective PE loader: VirtualAlloc → write → VirtualProtect → thread creation |
| T1071.001 — Application Layer Protocol: Web Protocols | HTTP POST C2 with encrypted body; WinInet API resolution |
| T1027 — Obfuscated Files or Information | XOR-NOT encrypted strings, base-62 alphabet encoding, runtime C2 URL generation |
| T1497.001 — Virtualization/Sandbox Evasion: System Checks | CPUID hypervisor-bit checks (leaf 1 ECX[31], leaf 7 EBX[18]) |
| T1497.002 — Virtualization/Sandbox Evasion: User Activity Based | RDTSC differential timing gate |
| T1083 — File and Directory Discovery | Recursive "*" enumeration via FindFirstFile / FindNextFile |
| T1573.001 — Encrypted Channel: Symmetric Cryptography | CryptEncrypt / CryptDecrypt for C2 payload body |
| T1105 — Ingress Tool Transfer | Downloader / payload retrieval via HTTP POST response handling |
References
- OpenCTI artifact:
4972300c-d9f9-4f2e-b54e-3fc5b3458b77, labels:blackmatter,dropped-by-phorpiex,exe,malware-bazaar^[metadata.json] - Primary analysis (confirmed twin): /intel/analyses/136b57507a3cfe1fc39cf6973869dca7e871e91d63f283c77380fc33298d6d51.html
- Related entity pages: blackmatter, unattributed, phorpiex
- Technique page: peb-walking-api-resolution
Provenance
Analysis produced from static triage inputs (file.txt, pefile.txt, exiftool.json, metadata.json, rabin2-info.txt, yara.txt, ssdeep.txt, tlsh.txt, strings.txt, floss.txt, capa.txt, binwalk.txt, dynamic-analysis.md) and radare2 decompilation (analysis level 3) of the binary at <sample f016df16d0f3.bin>. CAPA failed due to missing signature database. floss failed due to CLI invocation error. CAPE dynamic analysis skipped — no Windows guest available. Behavioral claims are statically inferred from the confirmed-twin 136b5750 report and radare2 decompilation of this sample.