54e64e
OpenCTI opaque family label. Currently a single-sample family: a MSVC C++ x64 dropper masquerading as a system-analyzer tool.
Overview
The 54e64e label is assigned by OpenCTI/MalwareBazaar as a family identifier for a Windows loader/dropper cluster. As of 2026-09-07, fourteen distinct build morphs have been confirmed under this umbrella label, spanning MSVC C++, Go, .NET, VB6, IExpress/AutoIt3, Go infostealer, additional MSVC reflective-loader toolchains, a Go reflective PE loader, and a new MSVC 2019/2022 HTTP loader with XOR-0x43 string encryption. The common thread is delivery-chain behaviour (payload download, staging, execution) and the dropped-by-amadey co-label, though independent Amadey confirmation is lacking. OpenCTI also co-labels this sample dropped-by-amadey, suggesting it is part of the Amadey downloader delivery chain, though this relationship is not independently confirmed.
Build Stack
Fourteen distinct build morphs observed within the same OpenCTI umbrella label:
Morph 14 — Go 1.25.9 reflective PE loader with PRNG payload decoding (d8a6366c)
- Compiler: Go 1.25.9,
CGO_ENABLED=0,trimpath=true,GOOS=windows,GOARCH=amd64,GOAMD64=v1^[/intel/analyses/d8a6366c9fbf5a41c82774f1e499aebe1a9bf9b078331f5a2c174ca0785c3b92.html] - Architecture: AMD64, GUI subsystem
- Signing: Self-signed Authenticode, 4096-bit RSA. Subject CN=
unscramblex.com, issuer CN=E7, validity 2026-04-06 to 2026-07-05. - Obfuscation: 13 randomized
main.*function names (smallest Go loader namespace in cluster)..symtabpreserved (95 KB, 2,219 symbols) — unusual for Go malware, suggests builder does not strip. - Resources: No
.rsrcsection, no version info, no icon, no masquerade. Zero timestamp. - C2: No hardcoded strings; payload is decrypted at runtime. Runtime
syscall.Syscallsurface can resolve any API dynamically. - Notable: Newer Go toolchain than Morph 12 (1.25.9 vs 1.25.4). Reduced function count (13 vs 55) suggests compiler inlining or stripped-down builder template. Pure loader; no infostealer surface. First sibling with
unscramblex.commasquerade domain.
Morph 1 — Null-padded MSVC C++ (3b13b28c)
- Compiler: MSVC 19.43 (Visual Studio 2022 17.3+) ^[/intel/analyses/3b13b28ca3a6d3c82228f5cc6a6e0bef583e9c3b3092da4c20fe72c75f3dd386.html]
- Language: C++ with full MSVC standard library (STL strings, streams, exception support)
- Packing/Obfuscation: None. No packer, no strip, no encryption. Binary is padded to ~5 MB with null bytes after a small overlay UAC manifest.
- Signing: Unsigned
- C2:
URLDownloadToFileWtohttp://80.253.249.169:5000/upfevb.exe - Notable: Defender exclusion via PowerShell
Add-MpPreference -ExclusionPath,ShellExecuteAto launch downloaded payload, admin gate viaAllocateAndInitializeSid+CheckTokenMembership. Fake diagnostic masquerade "System Analyzer Tool v4.2.1".
Morph 2 — UPX-packed x64 (c8db13c1)
- Packer: UPX (3 sections: UPX0, UPX1, UPX2) with modified/hacked header that defeats standard UPX decompression. ^[/intel/analyses/c8db13c15ad99cc002dda644384e730497972a9995510918f5fc7e2c071b9a0f.html]
- Compiler: Unknown — timestamp zeroed by UPX
- Import table: Stripped to four KERNEL32 functions (
LoadLibraryA,GetProcAddress,VirtualProtect,ExitProcess) rebuilt at runtime - Signing: Unsigned
- Payload indicators: AES S-Box tables found inside compressed UPX1 section, suggesting encrypted second-stage content
Morph 3 — Go 1.25.4 signed PE64+ infostealer cluster (cc4aa789, 8017acd5)
- Compiler: Go 1.25.4,
CGO_ENABLED=0,-trimpath=true^[/intel/analyses/8017acd59116f1a84c43953daa1fc856afb65f34b72f438710fcd6094ac9486b.html] - Architecture: AMD64, GUI subsystem
- Signing: Fabricated Authenticode with subject CN=
WE1, issuer CN=godaddy.com(self-signed template, 3-month validity) - Obfuscation: ~32 randomized
main.*function names (10–20 chars each) to fragment control flow - Resources: No
.rsrcsection, no embedded icons - C2: No hardcoded strings; runtime-decoded or DGA resolution inferred from cluster siblings
Morph 4 — MSVC 14.0 XMM-loader with encrypted .data (6e0ef3af)
- Compiler: MSVC 14.0 (Visual Studio 2015+) ^[/intel/analyses/6e0ef3af90cd3e4a8d48b6e5fee62e5d88f69d007135314f9014e63cfb179e93.html]
- Architecture: AMD64, GUI subsystem
- Packing/Obfuscation: None — outer PE is not packed, but the 2.8 MB
.datasection is encrypted in-place via SSE2paddw/pandloops. - Signing: Unsigned
- Resources: No
.rsrcsection, no version info, no icons - C2: No hardcoded strings; decrypted payload may contain C2 configuration
- Notable: Mixed CRT — MSVC PE structure with MinGW-w64 pseudo-relocation handler and error strings. Decryption is gated by boolean flags in
.bss.
Morph 5 — Signed MSVC 14.0 XMM-loader with Chrome masquerade (536a323c)
- Compiler: MSVC 14.0 (Visual Studio 2015+) ^[/intel/analyses/536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119.html]
- Architecture: AMD64, GUI subsystem
- Packing/Obfuscation: None — 2.5 MB
.datasection encrypted in-place via SSE2paddw/pandloops (same morph as6e0ef3af). - Signing: Valid Microsoft Authenticode — CN=
Microsoft Corporation/ Microsoft Code Signing PCA 2011 / Microsoft Root Certificate Authority 2011. Chain verified via PKCS#7 signature block. - Resources: Single RT_VERSION resource with Google Chrome v70.0.3538.110 masquerade (
CompanyName: Google Inc.,FileDescription: Google Chrome,FileTitle: chrome.exe). - C2: No hardcoded strings; decrypted payload may contain C2 configuration.
- Notable: Smaller encrypted
.datapayload than6e0ef3af(2.43 MB vs 2.73 MB), suggesting builder parameterization. Chrome version string is from October 2018, eight years before PE timestamp. OpenCTI mislabels this samplecoinminer; it is not a coinminer.
Morph 6 — Go 1.20.6 signed PE64+ infostealer (2f23087f)
- Compiler: Go 1.20.6,
GOOS=windows, stripped ^[sample 2f23087f/strings.txt:1250] - Architecture: AMD64, GUI subsystem
- Signing: Valid GlobalSign DV TLS certificate — CN=
seekingalpha.com, issuer=GlobalSign Atlas R3 DV TLS CA 2025 Q4. TLS certificate (not code-signing) abused for Authenticode; chain verifies against Microsoft Trusted Root. ^[sample 2f23087f/binwalk.txt] - Obfuscation: 37 randomized
main.*function names (6–17 chars, alphanumeric) ^[sample 2f23087f/strings.txt:4330] - Resources: No
.rsrcsection, no embedded icons, no version info - C2: No hardcoded strings; Winsock (
ws2_32.dll) surface suggests TCP/UDP C2 - Notable:
.symtabsection present (unusual for stripped Go malware); module pathBqQoxabRybICTZs(randomized) - Build ID:
j4TU-TUCinBSRq731KfD/46rs2fE3K03_WH702efI/rExPYpfWfYGdZACfJ5CC/iGgE5wPJV-mL0oAGkjmz
Morph 7 — .NET Framework 4.7.2 ILRepack crypter with JC-1-2 decryptor (e14cb7f3)
- Compiler: C# compiled to IL, merged with ILRepack (
LX_QhSq5nqlwW05ftemp prefix) ^[sample e14cb7f3/rabin2-info.txt] - Architecture: AMD64, GUI subsystem, .NET Framework 4.7.2
- Packing/Obfuscation: None on outer PE; inner assemblies (
MQCommon.UI.AutoUpdater+JC-1-2decryption DLL) merged via ILRepack. No ConfuserEx, SmartAssembly, or Xenocode. - Signing: Unsigned
- Resources: PNG icon (48×48), RT_VERSION with all-zero fields, RT_MANIFEST with
asInvokerexecution level. Embedded XML config at offset0xBA36. - C2: WCF SOAP endpoint
http://mes.zy.com/MES.Wcf/MSI/MES/AutoupdateService.xmland internal IPhttp://<lan>/Mes.WCF/MSI/MES.WorkMode=Clientconfig-driven update loop. - Notable: MES (Manufacturing Execution System) WCF masquerade suggesting OT/ICS targeting. Custom AES-Z85-column-permutation cipher in embedded
JC-1-2DLL. WinForms UI scaffolding (progressBar1,timer1,backgroundWorker1). Reflective DLL loading viaAssembly.Load(byte[])equivalent. Ten hardcoded 64-char hex strings likely serve as decryption keys or integrity hashes. Administrator build environment (Terminal Services session temp pathTemp\2). Static-only (CAPE skipped).
Morph 8 — VB6-native PowerShell/WMI cradle dropper (4544f0e5)
- Compiler: Visual Basic 6 (VB6), native x86 via
MSVBVM60.DLLruntime. ^[/intel/analyses/4544f0e53697d770eac70abad5790433d5e0b70282758c0b3383bf04a4f7f9ba.html] - Architecture: PE32, Intel 80386, GUI subsystem, 3 sections (
.text,.data,.rsrc). Linker version 6.0. - Packing/Obfuscation: None. Not packed, not stripped.
.datasectionVirtualSize=0xA38withSizeOfRawData=0x0— null-padded on-disk image expands to zero-initialized data at runtime. - Signing: Unsigned
- Resources: RT_VERSION with fabricated, LLM-scraped strings:
CompanyName: "To give an accurate answer",LegalCopyright: "still popular for GPUs",InternalName: "WMI",OriginalFilename: "WMI.exe",ProductName: "Project1". RT_ICON and RT_GROUP_ICON present. - C2: Two embedded PowerShell cradles retrieving from
http://91.92.240.125:8888/2jand/w5viairm | iex. Strings obfuscated with trivialreplace('s','')stripping. - Execution: VB6 runtime instantiates WMI COM objects (
Win32_ProcessStartup,Win32_Process,root\cimv2) to spawn PowerShell in a hidden window (ShowWindow = 0). - Notable: Default VB6 IDE project/module/form names (
Project1,Module1,MDIForm1) indicate low-effort builder. Absurd version strings are a new builder artefact not seen in prior morphs.
Morph 9 — Go 1.24.0 UPX-packed x86 infostealer (0b6c65cd)
- Compiler: Go 1.24.0,
GOOS=windows,GOARCH=386(x86). ^[/intel/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a.html] - Architecture: PE32, Intel 80386, GUI subsystem, 6 sections after UPX decompression.
- Packing/Obfuscation: UPX 3.96 outer compression; standard
upx -ddecompresses cleanly to 12.5 MB unstripped PE. - Signing: Unsigned. No
.rsrc, no version info, no icon. - Resources: None. GUI subsystem with no visible window code.
- C2: QUIC/HTTP3 via
github.com/quic-go/quic-go(TLS 1.3, X25519+MLKEM768, 0-RTT); DNS-over-HTTPS fallback to Cloudflare/Google/Quad9. No hardcoded C2 domain in strings. Telegram exfil (steal finished!). - Notable: Rich dependency graph for a stealer:
wazero(Wasm runtime),taskmaster(Task Scheduler persistence),go-sqlite3(browser DB parsing),tonutils-go(TON blockchain).[AFK] 0.28.1 (x86)version string identifies this as AFK Stealer (AFKSystems), a commodity Go infostealer sold on Russian-speaking forums. Not build-related to prior Go morphs (Morph 3, Morph 6) — different family, different builder, different capabilities. Static-only (CAPE skipped).
Morph 10 — MSVC 14.44 reflective loader with Google Drive staging (de601a8a)
- Compiler: MSVC 14.44 (Visual Studio 2022 v143), build timestamp 2026-03-31 15:39:36 UTC. ^[sample de601a8a/rabin2-info.txt]
- Architecture: PE32+ x64, GUI subsystem, 5 sections. No packing, no stripping.
- Signing: Unsigned. No
.rsrcbeyond RT_MANIFEST; no VS_VERSIONINFO, no icon, no masquerade. - IAT: 6 KERNEL32 imports only (
GetModuleHandleW,GetProcAddress,LoadLibraryW,VirtualAlloc,VirtualFree,ExitProcess). - API resolution: Runtime
LoadLibraryW+GetProcAddressforwinhttp.dll,shell32.dll,ole32.dll, resolving ~30 APIs into global.datapointers. Not PEB-walking. - C2 / staging: Primary: HTTPS GET to
drive.usercontent.google.com/download?id=1YBVIDkZgygNfUU2rbJXXCYdrzay5rMdY&export=download&authuser=0&confirm=t. Fallback:158.94.209.95/good?s=ztest&substr=one. - Payload handling: Downloads printable-ASCII encoded payload (custom Base85-like decoder), decodes into RWX buffer, then copies to larger 0x235000-byte staging region via AVX2-optimized
memcpy(vmovdqu/vmovntdq). - Process creation surface: Resolved but not statically called:
CreateProcessW,InitializeProcThreadAttributeList,UpdateProcThreadAttribute,CreatePipe,PeekNamedPipe,ReadFile,WriteFile. Indicates extended-attribute process creation with IPC pipe redirection. - Notable: AVX2 YMM registers in both
memsetandmemcpywithvzeroupperdiscipline — compiled with/arch:AVX2.IMAGE_DEBUG_TYPE_POGOconfirms Profile-Guided Optimization release build. This is the smallest confirmed sibling at 10.5 KB. Static-only (CAPE skipped — no Windows guest).
Morph 11 — MSVC 14.44 reflective loader with 7.3 MB encrypted payload (16520f80)
- Compiler: MSVC 14.44 (Visual Studio 2022 v143), build timestamp 2026-05-29 03:04:59 UTC. ^[sample 16520f80/rabin2-info.txt]
- Architecture: PE32+ x64, GUI subsystem, 8 sections. No packing, no stripping.
- Signing: Unsigned. No
.rsrcsection at all. - IAT: 7 KERNEL32 imports only (
GetSystemDirectoryW,HeapAlloc,HeapFree,ExitProcess,LoadLibraryA,GetModuleHandleA,GetProcAddress). - API resolution: Same runtime
LoadLibraryA+GetProcAddresspattern as Morph 10. - Payload: 7.3 MB encrypted payload in section
02(entropy 7.81,r-x+not_paged). Entry point RVA0x7D8504falls inside encrypted section — self-decrypting entry point. - Anti-triage: First four sections (
.text,.rdata,.data,.pdata) haveSizeOfRawData=0— null-padded on-disk, allocated at runtime. - C2 / staging: No hardcoded C2 recovered statically; encrypted payload likely contains staging URLs.
- Notable: Scaled sibling of Morph 10 — same MSVC 14.44 toolchain, same
IMAGE_DEBUG_TYPE_POGO, same null-pad anti-triage, same minimal IAT, but 700× larger payload. Suggests parameterized builder with constant stub and variable payload. Static-only (CAPE skipped — no Windows guest).
Morph 12 — Go 1.25.4 reflective PE loader with PRNG payload decoding (018ef44b)
- Compiler: Go 1.25.4,
CGO_ENABLED=0,trimpath=true,GOOS=windows,GOARCH=amd64. ^[sample 018ef44b/strings.txt:1510] - Architecture: PE32+ x64, GUI subsystem, 8 sections. No packing, no stripping.
- Signing: Self-signed Authenticode, CN=
xxx.com, issuerE7, 4096-bit RSA, 3-month validity. Chain fails validation. ^[sample 018ef44b/binwalk.txt] - IAT: Only
kernel32.dllimported statically. ^[sample 018ef44b/pefile.txt] - Obfuscation: 55 randomized
main.*function names (10–20 chars). Module pathRAwSPJDqREzkxCz(randomized). ^[sample 018ef44b/strings.txt:1512] - API resolution: All non-KERNEL32 APIs invoked via Go
syscall.SyscallN/syscall.Syscall— nonet/httporcrypto/tlssymbols recovered. ^[sample 018ef44b/rabin2-info.txt] - Payload handling: Custom multi-stage decryptor (
main.sensmww) using modular arithmetic, XOR, and byte shuffle, driven bymath/randPRNG parameters. Decoded payload parsed by embedded PE header walker (main.chdldv), mapped into RWX memory viaVirtualAlloc(main.vwhubhlxgr), then execution transferred (main.bjlkfhfvo). Runtime DLL loader (main.lhtbglfiqdcosne) resolves additional APIs viaLoadLibraryW+GetProcAddress. ^[/intel/analyses/018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a.html] |- Notable: First Go-based loader/injector in the54e64ecluster — prior Go morphs (3, 6, 9) were infostealers. No credential-harvesting surface, no browser/crypto strings. Reflective PE loader pattern matches MSVC Morphs 10–11 but implemented in Go with syscall-level API resolution. No hardcoded network IOCs. Static-only (CAPE skipped — no Windows guest).
Morph 13 — MSVC 2019/2022 x64 HTTP loader with XOR-0x43 string encryption (37d8875b)
|- Compiler: MSVC 2019/2022 — Rich header shows Utc1900_C (×10), Utc1900_CPP, Linker1400. ^[sample 37d8875b/rabin2-info.txt]
|- Architecture: PE32+ x64, GUI subsystem, 5 sections. No packing, no stripping.
|- Signing: Unsigned. No .rsrc section, no version info, no icon.
|- Obfuscation: Single-byte XOR 0x43 string encryption across all embedded API names, C2 IPs, registry paths, and error messages. Decrypted at runtime via fcn.14000557c.
|- IAT: Standard static imports (KERNEL32.dll, ADVAPI32.dll, ole32.dll, OLEAUT32.dll, USER32.dll, ws2_32.dll absent but winhttp.dll/wininet.dll runtime-resolved).
|- API resolution: HTTP APIs (WinHttpOpen, InternetOpenW, etc.) resolved at runtime via indirect calls through a global function-pointer table (0x140009f20–0x140009f58), not via static IAT.
|- C2 / staging: Hardcoded IPs 62.60.226.159, 196.251.107.130, 196.251.107.104; endpoint /api.php; beacon parameters include uid, user, pc, os, ver, ram, adm.
|- Process creation: Imports CreateProcessW, WriteProcessMemory, SetThreadContext, ResumeThread, NtCreateSection, NtMapViewOfSection, NtUnmapViewOfSection, VirtualProtect — hollowing or section-mapping injection inferred.
|- COM automation: CoInitializeEx → VariantClear → vtable dispatch at offsets 0x38, 0x50, 0x78, 0x48, 0x88, 0xB0, 0x90, 0x80, 0xE0, 0x110, 0x10 — WMI or Task Scheduler COM surface.
|- Persistence: Software\Microsoft\Windows\CurrentVersion\Run referenced in decrypted strings.
|- Anti-triage: CreateMutexW singleton gate; process exits immediately if mutex already exists.
|- Notable: Dual-thread architecture (identity thread + HTTP thread); structured error strings (Err_Download_Failed, Err_Invalid_PE_Header_Not_MZ, etc.) suggest framework-level C2 error reporting; cmd.exe /C timeout /T 3 & del "%s" & start "" "%s" self-erasure pattern. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7.html]
Deploy / TTPs
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Ingress Tool Transfer | T1105 | URLDownloadToFileW to fetch http://80.253.249.169:5000/upfevb.exe (Morph 1 only) |
| Impair Defenses | T1562.001 | Spawns hidden powershell Add-MpPreference -ExclusionPath (Morph 1 only) |
| Virtualization/Sandbox Evasion | T1497.001 | PRNG-based delay loop and verbose fake diagnostic output (Morph 1) |
| Signed Binary Proxy Execution | T1218.011 | ShellExecuteA to launch downloaded payload (Morph 1) |
| User Execution | T1204.002 | PE GUI executable, user-launched |
| Bypass UAC | T1548.002 | Admin gate via AllocateAndInitializeSid + CheckTokenMembership (Morph 1) |
| Match Legitimate Name or Location | T1036.005 | Masquerades as "System Analyzer Tool v4.2.1" (Morph 1) |
| Masquerading | T1036 | Go morph presents fabricated godaddy.com code-signing cert ^[/intel/analyses/8017acd59116f1a84c43953daa1fc856afb65f34b72f438710fcd6094ac9486b.html] |
| Ingress Tool Transfer | T1105 | WebClient.DownloadFileAsync to WCF SOAP endpoint mes.zy.com (Morph 7) |
| Reflective Code Loading | T1620 | Assembly.Load of embedded JC-1-2 DLL via ExtractEmbeddedJcDecryptorDll (Morph 7) |
| Match Legitimate Name or Location | T1036.005 | Masquerades as "MQCommon.UI.AutoUpdater" / MES WCF auto-updater (Morph 7) |
| Command and Scripting Interpreter | T1059.001 | PowerShell expression execution (capa hit, Morph 7) |
| System Information Discovery | T1082 | GetCurrentPrivilegeLevel, WindowsPrincipal, hostname enumeration (Morph 7) |
| Application Window Discovery | T1010 | FindWindow, WinForms GUI enumeration (Morph 7) |
| File and Directory Discovery | T1083 | CheckUpdateFiles, GetFiles, directory existence checks (Morph 7) |
| Command and Scripting Interpreter: PowerShell | T1059.001 | Embedded `powershell iex('irm ... |
| Ingress Tool Transfer | T1105 | irm 91.92.240.125:8888/2j and /w5 — HTTP payload retrieval (Morph 8) |
| Hide Artifacts: Hidden Window | T1564.003 | WMI Win32_ProcessStartup.ShowWindow = 0 + Win32_Process.Create (Morph 8) |
| Masquerading: Match Legitimate Name or Location | T1036.005 | OriginalFilename: WMI.exe, InternalName: WMI (Morph 8) |
| Credentials from Web Browsers | T1555.003 | main.getChromeCookies, main.getGeckoCookies, Login Data, logins.json, key4.db (Morph 9) |
| Screen Capture | T1113 | PrintScreen, GetClipboardData, CreateCompatibleBitmap (Morph 9) |
| Clipboard Data | T1115 | Clipboard:, Clipboard: MachineGuid (Morph 9) |
| System Information Discovery | T1082 | HWID:, PC Name:, CPU:, GPU:, GEO:, MachineGuid (Morph 9) |
| Create or Modify System Process | T1543 | github.com/capnspacehook/taskmaster, error creating registered task (Morph 9) |
| Application Layer Protocol | T1071 | quic-go, http3, quic iv, quic hp, quic key (Morph 9) |
| Protocol Tunneling | T1572 | DoH endpoints https://1.1.1.1/dns-query, https://dns.google/resolve (Morph 9) |
| Exfiltration Over Web Service | T1567 | application/json, POST, steal finished!, Telegram Desktop paths (Morph 9) |
| File and Directory Discovery | T1083 | Enumerates %LOCALAPPDATA%, %APPDATA%, browser profile paths for 15+ browsers (Morph 9) |
| Ingress Tool Transfer | T1105 | WinHttpOpenRequest GET to drive.usercontent.google.com (Morph 10) |
| Ingress Tool Transfer | T1105 | HTTP GET to 158.94.209.95/good fallback (Morph 10) |
| Reflective Code Loading | T1620 | Custom decoder → RWX VirtualAlloc → AVX2 memcpy staging (Morph 10) |
| Reflective Code Loading | T1620 | Self-decrypting entry point inside encrypted r-x section, runtime API resolution (Morph 11) |
| Obfuscated Files or Information | T1027 | 7.3 MB encrypted payload section with no packer signature (Morph 11) |
| Masquerading | T1036.005 | Null-padded on-disk sections hide true structure from file-offset scanners (Morph 11) |
| Reflective Code Loading | T1620 | Go main.chdldv parses PE headers; main.vwhubhlxgr allocates RWX memory; execution transferred to decoded payload (Morph 12) |
| Native API | T1106 | Go syscall.SyscallN / syscall.Syscall direct Windows API invocation (Morph 12) |
| Deobfuscate/Decode Files or Information | T1027 | math/rand-driven custom decryptor (main.sensmww) with modular arithmetic + XOR + byte shuffle (Morph 12) |
| Process Injection | T1055 | |
| Virtualization/Sandbox Evasion | T1497.001 | |
| Ingress Tool Transfer | T1105 | |
| Obfuscated Files or Information | T1027 | |
| Create or Modify System Process | T1543 | |
| Process Injection | T1055 | |
| Native API | T1106 | |
| Hide Artifacts | T1564.001 | |
| System Information Discovery | T1082 | |
| Command and Scripting Interpreter | T1059.003 | |
| Application Layer Protocol | T1071.001 | |
| Masquerading | T1036.005 | |
| Reflective Code Loading | T1620 | |
| Native API | T1106 | |
| Deobfuscate/Decode Files or Information | T1027 | |
| Process Injection | T1055 | |
| Virtualization/Sandbox Evasion | T1497.001 | |
| Masquerading | T1036.005 |
Variants / Aliases
- Amadey dropper (unconfirmed upstream relationship; OpenCTI co-label:
dropped-by-amadey) - Build artifact name:
certpert(from PDB path, Morph 1)
Notable Analyses
- raw/analyses/3b13b28ca3a6d3c82228f5cc6a6e0bef583e9c3b3092da4c20fe72c75f3dd386 — Deep static analysis; static-only (CAPE skipped). Null-padded MSVC C++ "certpert" dropper with fake diagnostic masquerade, Defender exclusion via PowerShell, HTTP payload fetch.
- raw/analyses/c8db13c15ad99cc002dda644384e730497972a9995510918f5fc7e2c071b9a0f — UPX-packed x64 sibling with modified/hacked packer. Three sections, four KERNEL32 imports, compressed payload with AES S-Box indicators. Standard UPX decompression fails. Static-only (CAPE skipped).
- raw/analyses/cc4aa789cf0c80b32004b90be6be0ad80944ad85730c6095cc3ca29469059503 — Go 1.25.4 PE64 infostealer. Signed DV cert CN=
askart.com, 24 randomizedmain.*functions, GUI subsystem, no.rsrc, no hardcoded C2. Matchesgolang-stealer-build-patterncluster; not build-related to prior MSVC siblings. Static-only (CAPE skipped). - raw/analyses/8017acd59116f1a84c43953daa1fc856afb65f34b72f438710fcd6094ac9486b — Go 1.25.4 PE64+ infostealer sibling. Fabricated Authenticode CN=
WE1/ issuer=godaddy.com, 32 randomizedmain.*functions, build IDM5d1UAj2sgoz.... Static-only (CAPE skipped). - raw/analyses/6e0ef3af90cd3e4a8d48b6e5fee62e5d88f69d007135314f9014e63cfb179e93 — MSVC 14.0 XMM-loader with 2.8 MB encrypted
.data. SSE2paddw/pandin-place decryption, MinGW-w64 pseudo-relocation handler, indirect thunk dispatch. No hardcoded C2. Static-only (CAPE skipped). - raw/analyses/536a323c04e73ef4b9b5e2bb9f0c7ee464f8ec443bf8e85a7ffd06087f2f0119 — Signed MSVC 14.0 XMM-loader with Chrome masquerade. Valid Microsoft Authenticode, Google Chrome v70 VS_VERSIONINFO, SSE2
paddw/panddecryption, 2.5 MB encrypted.data. Second confirmed sibling of the XMM-loader morph. Static-only (CAPE skipped). - raw/analyses/7aed04abf7cc42695481b89e4db2e8760eb56dd0fafc7da9f13a43c1158efc5e — Signed IExpress SFX with AutoIt3 payload. Valid Sectigo Authenticode on
wextract.exe; 22 CAB fragments reassembled by obfuscated batch script intoAutoIt3.exe+.a3xscript. No C2 strings in outer stages. Static-only (CAPE skipped). - raw/analyses/2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5 — Go 1.20.6 signed PE64+ infostealer. Valid GlobalSign DV TLS certificate CN=
seekingalpha.com, 37 randomizedmain.*functions,.symtabpresent, no.rsrc, Winsock C2 surface. Static-only (CAPE skipped). - raw/analyses/e14cb7f34407a042fc6a20aebd73d36b0d7a91a724872988ec08e7e4e39934a6 — .NET Framework 4.7.2 ILRepack crypter with JC-1-2 decryptor. MES WCF C2 (
mes.zy.com), custom AES-Z85-column-permutation cipher, embedded decryptor DLL at0xBCF3, WinForms UI scaffolding, admin TS build environment PDB. Static-only (CAPE skipped). - raw/analyses/4544f0e53697d770eac70abad5790433d5e0b70282758c0b3383bf04a4f7f9ba — VB6-native PowerShell/WMI cradle dropper. Minimal
MSVBVM60.DLLPE with tworeplace('s','')-obfuscatedirm | iexcradles to91.92.240.125:8888/2jand/w5. WMIWin32_Processhidden window spawn. Absurd LLM-scraped VS_VERSIONINFO ("To give an accurate answer","still popular for GPUs"). Static-only (CAPE skipped). - raw/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a — Go 1.24.0 UPX-packed x86 infostealer (AFK Stealer). QUIC/HTTP3 C2,
wazeroWasm runtime,taskmasterpersistence,go-sqlite3browser DB parsing,tonutils-goTON blockchain, DoH fallback, Telegram exfil.[AFK] 0.28.1 (x86)version string. Static-only (CAPE skipped). - raw/analyses/de601a8a3d45d818f6bd867f5bba33d576bc1d9d983511b66f2b22447dd5d8e4 — MSVC 14.44 reflective loader with Google Drive staging and custom Base85 decoder. 10.5 KB, AVX2-optimized,
/arch:AVX2, PGO release build. RuntimeLoadLibraryW/GetProcAddressforwinhttp.dll/shell32.dll/ole32.dll. HTTPS GET to Google Drive primary,158.94.209.95IP fallback. Process-creation surface indicators (InitializeProcThreadAttributeList,CreatePipe, etc.) resolved but not statically called. Smallest confirmed sibling. Static-only (CAPE skipped). - raw/analyses/16520f80193c6e45d207ac0ffad8b29446194ad9734d7ee2ea8178f91eacf491 — MSVC 14.44 reflective loader with 7.3 MB encrypted payload (Morph 11). Scaled sibling of
de601a8a— same toolchain, sameIMAGE_DEBUG_TYPE_POGO, same null-pad anti-triage, same minimal IAT, but 700× larger encrypted payload in section02. Entry point RVA0x7D8504falls inside encrypted region (self-decrypting entry point). No hardcoded C2 recovered statically. Suggests parameterized builder with constant stub and variable payload. Static-only (CAPE skipped — no Windows guest). - raw/analyses/018ef44b2d71de8d1bfb768592daa406a91a6187bc87a74dee67cb2a0d344f0a — Go 1.25.4 reflective PE loader with PRNG payload decoding (Morph 12). 55 randomized
main.*functions, self-signed CN=xxx.com, minimal IAT (kernel32.dll only), runtime API resolution viasyscall.SyscallN, custom decryptor (main.sensmww) withmath/rand-driven parameters, PE parser (main.chdldv), RWXVirtualAllocmapping (main.vwhubhlxgr), and DLL loader (main.lhtbglfiqdcosne). First Go loader/injector in cluster; prior Go morphs were infostealers. No hardcoded network IOCs. Static-only (CAPE skipped — no Windows guest). - raw/analyses/37d8875b983771758b7ad2abcd68672315558811a2c52aee59d3ac4cd3cb79f7 — MSVC 2019/2022 x64 HTTP loader with XOR-0x43 string encryption (Morph 13). 40 KB, 5 sections, unsigned. Single-byte XOR
0x43string obfuscation across all C2/API/registry/error strings. Dual-thread architecture: identity collection + HTTP beaconing. Runtime-resolved WinHttp/WinInet APIs via global function-pointer table. Hardcoded C2 IPs62.60.226.159,196.251.107.130,196.251.107.104; endpoint/api.php. Structured error-reporting strings (Err_Download_Failed,Err_Invalid_PE_Header_Not_MZ, etc.). COM automation via vtable dispatch (WMI/Task Scheduler surface). Process injection imports (CreateProcessW,WriteProcessMemory,SetThreadContext,NtCreateSection,NtMapViewOfSection). Registry Run persistence + cmd.exe self-erasure. Static-only (CAPE skipped — no Windows guest). - raw/analyses/d8a6366c9fbf5a41c82774f1e499aebe1a9bf9b078331f5a2c174ca0785c3b92 — Go 1.25.9 reflective PE loader with PRNG payload decoding (Morph 14). 13 randomized
main.*functions (smallest Go loader namespace in cluster), self-signed CN=unscramblex.com/ issuer=E7,.symtabpreserved (95 KB, 2,219 symbols), zero timestamp, no.rsrc. PRNG seeded withtime.Now().UnixNano()+ constant0xdd7b17f80, floating-point delay gates,0xe200quadword payload copy from.rdata, word-wise XOR/ADD transforms (main.wmisltgay), RWXVirtualAllocwrapper (main.gibxwporkamofscwith args0x40/0x3000), execution transfer viasyscall.Syscall. No hardcoded C2. Pure loader; no infostealer surface. Static-only (CAPE skipped — no Windows guest). |
Capabilities
- admin-rights-gate-sid-check
- prng-delay-loop-evasion
- fake-diagnostic-output-masquerade
- http-payload-download
- defender-exclusion-powershell
- shell-execute-dropped-payload
- upx-compression-with-modified-header
- runtime-import-table-rebuild
- go-infostealer-randomized-function-names
- authenticode-signing-throwaway-dv-cert
- gui-subsystem-no-window-code
- runtime-c2-resolution-no-hardcoded-ioc
- xmm-sse2-wordwise-payload-decryption
- mingw-pseudo-relocation-handler
- indirect-thunk-api-resolution
- large-encrypted-data-section
- valid-microsoft-authenticode-signing
- chrome-version-info-masquerade
- tls-cert-authenticode-abuse-seekingalpha
- symtab-present-stripped-go-binary
- self-decrypting-entry-point-in-encrypted-section
- pgo-release-build-profile-guided-optimization
- runtime-api-resolution-loadlibrarya-getprocaddress
- large-null-padded-section-anti-triage
- go-version-1.20.6-build
- dotnet-ilrepack-merged-crypter
- aes-z85-column-permutation-decryption
- embedded-pe-dll-reflective-load
- wcf-soap-c2-config-driven
- mes-ot-masquerade-update-framework
- hardcoded-64char-hex-key-material
- admin-ts-build-environment-pdb-artifact
- empty-vs-versioninfo-masquerade
- vb6-native-compiled-dropper
- powershell-cradle-embedded-strings
- trivial-character-stripping-obfuscation
- wmi-hidden-process-powershell-spawn
- http-irm-iex-payload-retrieval
- llm-scraped-version-info-masquerade
- credential-harvesting-chrome-dpapi
- credential-harvesting-firefox-nss
- credential-harvesting-brave-ielevator
- crypto-wallet-seed-extraction
- crypto-wallet-file-extraction
- telegram-desktop-data-theft
- steam-credential-theft
- clipboard-hijack-cryptocurrency
- system-information-enumeration
- screen-capture-bitmap
- quic-http3-c2-transport
- dns-over-https-fallback
- wasm-in-process-module-loader
- windows-task-scheduler-persistence
- ton-blockchain-address-generation
- sqlite3-browser-database-parsing
- browser-cookie-sqlite-extraction
- gecko-cookie-json-extraction
- json-exfiltration-post
- telegram-bot-exfiltration
- machineguid-fingerprinting
- google-drive-payload-staging
- custom-base85-like-decoder
- avx2-optimized-memcpy
- runtime-getprocaddress-resolution
- proc-thread-attribute-process-creation-surface
- winhttp-https-download
- pgo-release-build
- go-reflective-pe-loader-prng-decoding
- syscall-native-api-resolution
- rwx-virtualalloc-payload-mapping
- runtime-dll-loader-getprocaddress
- pe-header-parser-in-memory
- prng-seeded-custom-decryptor
- xor-0x43-string-encryption
- mutex-singleton-gate
- winhttp-wininet-runtime-resolution
- com-automation-vtable-dispatch
- digitalproductid-fingerprinting
- structured-error-c2-reporting
- cmd-self-erasure-pattern
- go-1.25.9-build
- symtab-preserved-go-binary
- unscramblex-cert-masquerade
- prng-constant-seed-gate