typeentityconfidencemediumcreated2026-07-28updated2026-09-03malware-familyloaderqt5peevasionc2signing

GhostPulse

A commodity Windows loader family distributed as 7-Zip SFX archives containing a Qt5-based x64 payload and one or more high-entropy encrypted sidecar files. First identified in the PacketPursuit corpus via OpenCTI/MalwareBazaar ghostpulse labels. Fifty confirmed siblings as of July 2026. All samples share the same outer packaging pattern but vary inner-executable names and sidecar filenames.

Build Stack

  • Outer container: 7-Zip SFX mod (7ZSfxMod_x86.exe, Oleg Scherbakov, 2010), MSVC 8.0, compiled Jun 2010 ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]
  • Archive: LZMA-compressed 7z solid archive; files extracted to %TEMP% ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]
  • Inner payload (x64 InfoPath variant): PE32+ x64, MSVC 14.x (VS 2019+), renamed Microsoft InfoPath 2013 executable (GeneratorB64.exe), valid Microsoft Authenticode chain (CN=Microsoft Corporation, product version 15.0.4805.1000). No Qt5 runtime; uses native MSVC + Office Common Dialog Framework DLLs (CDLMSO.DLL, MSOCF.DLL). ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html]
  • Inner payload (x64 Qt5 variant): PE32+ x64, MSVC 14.26 (VS 2019), Qt5Core.dll-linked GUI application, no exports, no Authenticode ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]
  • Inner payload (x86 YHClient variant): PE32 x86, MSVC 14.x (VS 2019+), FrameworSwitch32.exe, imports custom Log.dll, no Authenticode ^[/intel/analyses/94db5892d51fa7f24c6f406591d5cc143f48f3f9f576c66d36a8682e3950102b.html]
  • Sidecar files: Companion files with high entropy (7.5–7.95), consistent with encrypted payload + key/config. Filenames vary by sample: texture_mon.yaml, physics1024.map, monitor.sym, sampler.xml, etc.
  • Masquerade: Inner executable names and PDB paths frequently spoof legitimate software (EaseUS Partition Manager, "YHClient" product)

Deploy / TTPs

  • Execution: Silent SFX extraction to %TEMP% via RunProgram="%%T\\<Name>.exe" with Progress=no and GUIFlags=8 (suppress GUI) ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]
  • Evasion: Qt5 runtime bundled alongside payload provides massive legitimate import surface; QProcess::startDetached used for child execution, potentially bypassing parent-child telemetry ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]
  • Evasion (x86 variant): Custom Log.dll helper provides structured logging telemetry; pipe-based cmd.exe execution with redirected I/O for stealthy shell access ^[/intel/analyses/94db5892d51fa7f24c6f406591d5cc143f48f3f9f576c66d36a8682e3950102b.html]
  • C2: No static C2 strings observed in any sample. Network config expected to be encrypted inside sidecar files and decrypted at runtime. Qt5 network stack (QNetworkAccessManager via Qt5Core) available in x64 variants; x86 variant may use companion process (BarClientView.exe) for network relay
  • Payload loading: Inner executable references sidecar filenames in .rdata or loads them dynamically at runtime

Capabilities

  • 7z-sfx-silent-extraction
  • qt5-legitimate-library-masquerade
  • infopath-signed-carrier-masquerade
  • steam-error-reporter-masquerade
  • companion-file-encrypted-payload
  • encrypted-sidecar-payload
  • easeus-partition-manager-masquerade
  • yhclient-startbc-masquerade
  • custom-logging-telemetry
  • pipe-cmd-execution
  • dynamic-c2-resolution
  • qprocess-child-execution
  • game-asset-filename-masquerade
  • kernel-layer-xml-masquerade
  • algorithmic-inner-name-generation
  • single-instance-mutex-gating
  • inter-process-communication-window-messages
  • digicert-signed-dropper — YHClient x86 morph variant carries valid DigiCert code-signing cert (CN=Hangzhou Shunwang Technology Co.,Ltd) ^[/intel/analyses/c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8.html]
  • valve-steam-error-reporter-carrier — Legitimate Steam Error Reporter binary repurposed as encrypted payload carrier ^[/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html]
  • microsoft-authenticode-signed-carrier — Legitimate Microsoft InfoPath 2013 x64 binary repurposed as encrypted payload carrier, full three-level certificate chain (Microsoft Time-Stamp Service → Microsoft Code Signing PCA → Microsoft Root Certificate Authority) ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html]

Variants / Aliases

  • OpenCTI labels: ghostpulse, urlhaus

  • MalwareBazaar family: ghostpulse

  • Inner executable names observed (non-exhaustive): CommunicMes.exe, PortTransactor.exe, PuTool.exe, DecAlpha64.exe, Data_D.exe, CommuniBi.exe, WizardDa42.exe, InjectoBan.exe, AurModule.exe, IntegratoFlux.exe, GeneratorB64.exe

  • GeneratorB64.exe (InfoPath x64 signed-carrier morph, 4a78e2ad)

Notable Analyses

  • 4a78e2ad — InfoPath x64 signed-carrier morph. 7-Zip SFX archive containing a renamed Microsoft InfoPath 2013 x64 executable (GeneratorB64.exe) with valid Microsoft Authenticode chain, Office Common Dialog Framework DLLs (CDLMSO.DLL, MSOCF.DLL), and a 7.6 MB encrypted sidecar kernel-layer.xml (entropy 7.90). No Qt5 runtime. First confirmed signed-carrier morph in this cluster using a Microsoft-signed binary as the payload carrier. ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html]
  • 833bffd0 — First detailed analysis in this corpus. Qt5 x64 dropper with CommunicMes.exe inner payload, EaseUS Partition Manager masquerade, texture_mon.yaml + physics1024.map sidecars. ^[/intel/analyses/833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334.html]
  • 943cf1eb — Confirmed twin of 833bffd0: byte-identical inner payload and shared physics1024.map key/config sidecar, but individualized texture_mon.yaml encrypted payload confirms per-sample builder reuse. ^[/intel/analyses/943cf1ebeb089abcd2e6ff0c2bfefa4631855948ab3ef3811cba1c635aa389d1.html]
  • 94db5892 — Divergent x86 MSVC C++ morph with FrameworSwitch32.exe inner payload, "YHClient" masquerade, custom Log.dll helper, monitor.sym + sampler.xml sidecars, and pipe-based cmd.exe execution capability. No Qt5 runtime. Unsigned. ^[/intel/analyses/94db5892d51fa7f24c6f406591d5cc143f48f3f9f576c66d36a8682e3950102b.html]
  • c88a5bba — DigiCert-signed twin of 94db5892 (same FrameworSwitch32.exe payload, same sidecar names, same monitor.sym/sampler.xml sidecars). Signed with valid DigiCert code-signing certificate CN=Hangzhou Shunwang Technology Co.,Ltd (valid 2023-03-24 → 2026-06-19). Confirms the YHClient morph is now being distributed with stolen or re-issued legitimate code-signing certificates. OpenCTI cloud55filecc label is a false positive; resolves to this cluster. ^[/intel/analyses/c88a5bba3b32d6c4cfe3c2d33ea8eb5ada10314a8e049ce02d5cda94abd5aeb8.html]
  • 9410374b — Steam Error Reporter x64 morph (confirmed twin of 642ecaab). Inner payload Vect_P16.exe (SHA-256 0a0c0975...) is the legitimate Valve steamerrorreporter64.exe (MSVC 14.29, Mar 2024) repurposed as a carrier. Bundles tier0_s64.dll + vstdlib_s64.dll + msvcp_win.dll + ucrtbase.dll alongside encrypted sidecars network-mon.map (6.8 MB, entropy 7.95) and process.xml (26.8 KB). No Qt5 runtime. Security directory on inner payload is corrupted/invalid despite rabin2 reporting signed: true; tier0_s64.dll retains valid DigiCert signature. ^[/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html]

Related Concepts