GhostPulse
A commodity Windows loader family distributed as 7-Zip SFX archives containing a Qt5-based x64 payload and one or more high-entropy encrypted sidecar files. First identified in the PacketPursuit corpus via OpenCTI/MalwareBazaar ghostpulse labels. Fifty confirmed siblings as of July 2026. All samples share the same outer packaging pattern but vary inner-executable names and sidecar filenames.
Build Stack
- Outer container: 7-Zip SFX mod (
7ZSfxMod_x86.exe, Oleg Scherbakov, 2010), MSVC 8.0, compiled Jun 2010 ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html] - Archive: LZMA-compressed 7z solid archive; files extracted to
%TEMP%^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html] - Inner payload (x64 InfoPath variant): PE32+ x64, MSVC 14.x (VS 2019+), renamed Microsoft InfoPath 2013 executable (
GeneratorB64.exe), valid Microsoft Authenticode chain (CN=Microsoft Corporation, product version 15.0.4805.1000). No Qt5 runtime; uses native MSVC + Office Common Dialog Framework DLLs (CDLMSO.DLL,MSOCF.DLL). ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html] - Inner payload (x64 Qt5 variant): PE32+ x64, MSVC 14.26 (VS 2019), Qt5Core.dll-linked GUI application, no exports, no Authenticode ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]
- Inner payload (x86 YHClient variant): PE32 x86, MSVC 14.x (VS 2019+),
FrameworSwitch32.exe, imports customLog.dll, no Authenticode ^[/intel/analyses/94db5892d51fa7f24c6f406591d5cc143f48f3f9f576c66d36a8682e3950102b.html] - Sidecar files: Companion files with high entropy (7.5–7.95), consistent with encrypted payload + key/config. Filenames vary by sample:
texture_mon.yaml,physics1024.map,monitor.sym,sampler.xml, etc. - Masquerade: Inner executable names and PDB paths frequently spoof legitimate software (EaseUS Partition Manager, "YHClient" product)
Deploy / TTPs
- Execution: Silent SFX extraction to
%TEMP%viaRunProgram="%%T\\<Name>.exe"withProgress=noandGUIFlags=8(suppress GUI) ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html] - Evasion: Qt5 runtime bundled alongside payload provides massive legitimate import surface;
QProcess::startDetachedused for child execution, potentially bypassing parent-child telemetry ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html] - Evasion (x86 variant): Custom
Log.dllhelper provides structured logging telemetry; pipe-basedcmd.exeexecution with redirected I/O for stealthy shell access ^[/intel/analyses/94db5892d51fa7f24c6f406591d5cc143f48f3f9f576c66d36a8682e3950102b.html] - C2: No static C2 strings observed in any sample. Network config expected to be encrypted inside sidecar files and decrypted at runtime. Qt5 network stack (QNetworkAccessManager via Qt5Core) available in x64 variants; x86 variant may use companion process (
BarClientView.exe) for network relay - Payload loading: Inner executable references sidecar filenames in
.rdataor loads them dynamically at runtime
Capabilities
7z-sfx-silent-extractionqt5-legitimate-library-masqueradeinfopath-signed-carrier-masqueradesteam-error-reporter-masqueradecompanion-file-encrypted-payloadencrypted-sidecar-payloadeaseus-partition-manager-masqueradeyhclient-startbc-masqueradecustom-logging-telemetrypipe-cmd-executiondynamic-c2-resolutionqprocess-child-executiongame-asset-filename-masqueradekernel-layer-xml-masqueradealgorithmic-inner-name-generationsingle-instance-mutex-gatinginter-process-communication-window-messagesdigicert-signed-dropper— YHClient x86 morph variant carries valid DigiCert code-signing cert (CN=Hangzhou Shunwang Technology Co.,Ltd) ^[/intel/analyses/c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8.html]valve-steam-error-reporter-carrier— Legitimate Steam Error Reporter binary repurposed as encrypted payload carrier ^[/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html]microsoft-authenticode-signed-carrier— Legitimate Microsoft InfoPath 2013 x64 binary repurposed as encrypted payload carrier, full three-level certificate chain (Microsoft Time-Stamp Service → Microsoft Code Signing PCA → Microsoft Root Certificate Authority) ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html]
Variants / Aliases
-
OpenCTI labels:
ghostpulse,urlhaus -
MalwareBazaar family:
ghostpulse -
Inner executable names observed (non-exhaustive):
CommunicMes.exe,PortTransactor.exe,PuTool.exe,DecAlpha64.exe,Data_D.exe,CommuniBi.exe,WizardDa42.exe,InjectoBan.exe,AurModule.exe,IntegratoFlux.exe,GeneratorB64.exe -
GeneratorB64.exe(InfoPath x64 signed-carrier morph,4a78e2ad)
Notable Analyses
4a78e2ad— InfoPath x64 signed-carrier morph. 7-Zip SFX archive containing a renamed Microsoft InfoPath 2013 x64 executable (GeneratorB64.exe) with valid Microsoft Authenticode chain, Office Common Dialog Framework DLLs (CDLMSO.DLL,MSOCF.DLL), and a 7.6 MB encrypted sidecarkernel-layer.xml(entropy 7.90). No Qt5 runtime. First confirmed signed-carrier morph in this cluster using a Microsoft-signed binary as the payload carrier. ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html]833bffd0— First detailed analysis in this corpus. Qt5 x64 dropper withCommunicMes.exeinner payload, EaseUS Partition Manager masquerade,texture_mon.yaml+physics1024.mapsidecars. ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]943cf1eb— Confirmed twin of833bffd0: byte-identical inner payload and sharedphysics1024.mapkey/config sidecar, but individualizedtexture_mon.yamlencrypted payload confirms per-sample builder reuse. ^[/intel/analyses/943cf1ebeb089abcd2e6ff0c2bfefa4631855948ab3ef3811cba1c635aa389d1.html]94db5892— Divergent x86 MSVC C++ morph withFrameworSwitch32.exeinner payload, "YHClient" masquerade, customLog.dllhelper,monitor.sym+sampler.xmlsidecars, and pipe-basedcmd.exeexecution capability. No Qt5 runtime. Unsigned. ^[/intel/analyses/94db5892d51fa7f24c6f406591d5cc143f48f3f9f576c66d36a8682e3950102b.html]c88a5bba— DigiCert-signed twin of94db5892(sameFrameworSwitch32.exepayload, same sidecar names, samemonitor.sym/sampler.xmlsidecars). Signed with valid DigiCert code-signing certificate CN=Hangzhou Shunwang Technology Co.,Ltd(valid 2023-03-24 → 2026-06-19). Confirms the YHClient morph is now being distributed with stolen or re-issued legitimate code-signing certificates. OpenCTIcloud55filecclabel is a false positive; resolves to this cluster. ^[/intel/analyses/c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8.html]9410374b— Steam Error Reporter x64 morph (confirmed twin of642ecaab). Inner payloadVect_P16.exe(SHA-2560a0c0975...) is the legitimate Valvesteamerrorreporter64.exe(MSVC 14.29, Mar 2024) repurposed as a carrier. Bundlestier0_s64.dll+vstdlib_s64.dll+msvcp_win.dll+ucrtbase.dllalongside encrypted sidecarsnetwork-mon.map(6.8 MB, entropy 7.95) andprocess.xml(26.8 KB). No Qt5 runtime. Security directory on inner payload is corrupted/invalid despite rabin2 reportingsigned: true;tier0_s64.dllretains valid DigiCert signature. ^[/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html]
Related Concepts
- iexpress-sfx-dropper — Shared SFX dropper pattern (different builder)
- legitimate-library-masquerade — Using large legitimate runtime libraries to bury malicious imports