typeentityconfidencemediumcreated2026-06-05updated2026-09-06dotnetobfuscationloaderbitmap-steganographyunclassified

Unclassified .NET Bitmap-Stego Loader

Umbrella label for a .NET Framework PE32 loader family characterized by embedding ~20 small bitmap resources (typically 76×76×24) that serve as encrypted payload or config carriers. Static analysis shows heavy name mangling, control-flow flattening, and System.Resources.ResourceReader stream extraction, but the final decrypted payload is not recoverable without dynamic execution.

Build / RE

  • Format: PE32 (GUI) .NET assembly, minimal IAT (mscoree.dll!_CorExeMain only). ^[sample 4bf14434/pefile.txt]
  • Obfuscation: Random alphanumeric name mangling (not ConfuserEx base64), flattened IL dispatchers, encrypted strings. floss yields no plaintext API names. ^[sample 4bf14434/floss.txt]
  • Resources: Repeated System.Drawing.Bitmap objects referenced in strings; binwalk confirms 20+ PC bitmap structures in .rsrc. ^[sample 4bf14434/binwalk.txt]
  • Masquerade: Fabricated VS_VERSIONINFO with nonsense company/product names and version 21.19.1.278. ^[sample 4bf14434/exiftool.json]

Deploy / ATT&CK

  • T1620 Reflective Code Loading — Assembly.Load / GetMethod / Invoke strings present; capa confirms. ^[sample 4bf14434/capa.txt]
  • T1497.001 Virtualization/Sandbox Evasion — Anti-VM Xen strings detected by capa. ^[sample 4bf14434/capa.txt]
  • T1083 File and Directory Discovery — File existence/extension checks flagged by capa. ^[sample 4bf14434/capa.txt]
  • T1036.002 Masquerading — Fake version-info block. ^[sample 4bf14434/exiftool.json]

Capabilities

  • dotnet-manifest-resource-decryption

  • bitmap-embedded-payload-steganography

  • name-mangling-obfuscation

  • control-flow-flattening

  • version-info-masquerade

  • reflective-assembly-loading

  • anti-vm-xen-detection

  • aes-deflate-stream-decryption-chain

  • soap-http-client-protocol-reference

  • bank-gui-masquerade-iban-cnp-transfer

  • mixed-format-png-bmp-carriers

  • pixel-extraction-rgba-channels

  • clinical-trial-lab-equipment-gui-masquerade

  • backgroundworker-async-payload-staging

  • vb-net-compiler-artefacts

  • swift-banking-filename-lure — MT103 SWIFT-transfer lure with currency symbol and typo (Febeuary) plus .bat extension masquerade (sibling 0cfbc10a)

Related

Notable Analyses

  • db0d6bc0 (May 2022) — Second confirmed sibling. Version 24.11.37.197, internal name KKKKK.exe, filename Purchase Order.exe, ~24 embedded bitmaps. Same build pattern, same obfuscation style. Static-only analysis. ^[/intel/analyses/db0d6bc0d73b6e2cf8dedde102e67ab2ad6233c9ff93f29be39351c1580dec8f.html]

  • f74d8a51 (Mar 2023) — Third confirmed sibling. Version 20.3.49.113, internal name NEW QUOTE.exe, filename NEW QUOTE.COM, ~24 embedded bitmaps, fleet-maintenance GUI masquerade with OBD2/service-record/report-generation UI, SoapHttpClientProtocol SOAP reference, SHA256 + PRNG strings. Largest sibling at 984 KB. Static-only analysis. ^[/intel/analyses/f74d8a51625a7a66a4bdd5f569221bc492f5f61d6828fe6f9546368a040a5461.html]

  • f6b5bdd5 (Feb 2020) — Fourth confirmed sibling. Version 11.9.34.178, internal name djfcgvjhbkjnlm;,'.'.exe, filename copia del pago anticipado.exe, ~20 embedded bitmaps, Spanish payment-lure social engineering, BackgroundWorker-driven async staging, SoapHttpClientProtocol + System.Net.Sockets network references. Earliest known build in cluster. Static-only analysis. ^[/intel/analyses/f6b5bdd5958eefc7f7e595ee8e91c2407193226acad0bfa939f3a1a42cf08396.html]

  • f230118d (May 2026) — Fifth confirmed sibling. Version 2.4.5.6, internal name filr.exe, filename Drawing_specification_and_August_PO_#07329.exe, 16 embedded bitmaps at 88×88×24 (fewer and larger than prior 76×76×24 siblings), explicit DeflateStream / System.IO.Compression strings suggesting AES+Deflate decryption chain, minimal GUI depth (no functional WinForms shell). Engineering-procurement lure. Static-only analysis. ^[/intel/analyses/f230118d14a393bc3af4ff150e719f215a2fe7a024734de1c44ce12b987a7706.html]

  • d4d106f8 (Jun 2026) — Sixth confirmed sibling. Version 1.1.1.1, internal name Order.exe, filename Order.exe, 8 embedded bitmaps at 136×136×24 (fewer and larger than all prior siblings), bitmaps embedded in .text section rather than .rsrc, event-registration / attendee-management GUI masquerade (RegisteredAttendees, TransferOffered, AttendeeRegistered, InjuryReported, registrationFee), System.Net.Http without SoapHttpClientProtocol, no DeflateStream / System.IO.Compression strings. Static-only analysis. ^[/intel/analyses/d4d106f84bafa58d7b26128c6c32f80ebdaa7c333fc341ed119405434dde2751.html]

| a497a066 (Feb 2020) — Seventh confirmed sibling. Version 10.21.32.8, internal name done.exe, filename vessel's_main_particulars.exe, 21 embedded bitmaps at 76×76×24 (highest bitmap count in cluster), maritime shipping-lure social engineering, RijndaelManaged + SHA256 strings, SoapHttpClientProtocol retained, no DeflateStream / System.IO.Compression. Leap-day build timestamp. Simplest AES-only decryption chain among siblings. Static-only analysis. ^[/intel/analyses/a497a066fe94fbfad7361eee98b725cc0c32be13bd0c1742d010a98c97a483d7.html]

|- f31920ba (Nov 2024) — Eighth confirmed sibling. Version 1.0.0.0, internal name vdfj.exe, filename Order_PI.exe, 4 mixed-format carriers (3 PNG 256×256 RGBA + 1 BMP 129×128×32 + 1 PNG 513×513 RGBA) in .text section (no .rsrc bitmaps), bank/purchase-order GUI masquerade (Bank, BankBLL, IBAN, CNP, TransferBL), pixel-extraction routines named _GClr / _AClrData / _PixProcess / _ProcessYCoords, no anti-VM, no SoapHttpClientProtocol, no DeflateStream / System.IO.Compression. Light obfuscation; no ConfuserEx. Static-only analysis. ^[/intel/analyses/f31920ba7bb3d9a49382e06cfe13eddee4c4375cacd93c74794f1c7ec342c707.html]

|- 9ac1c1db (May 2019) — Ninth confirmed sibling. Version 17.28.43.78, internal name Cbz cc.exe, filename Especificaciones del presupuesto _ PO-20260525048166 E2S A105N.pdf(783KB).lha.exe, 283 embedded BMPs at 76×76×24 in .text section (order-of-magnitude increase over prior siblings), clinical-trial / lab-equipment management GUI masquerade (protocol tracking, consent forms, IRB documentation, equipment calibration, usage logs, participant tracking), SoapHttpClientProtocol retained, BackgroundWorker-driven async staging, no DeflateStream / System.IO.Compression, no anti-VM. VB.NET compiler artefacts (Microsoft.VisualBasic, NewLateBinding). Static-only analysis. ^[/intel/analyses/9ac1c1dba1be97cd28dd88c4c8b33a7cb08d7601157278e49433eb9b1c283cf0.html]

||- 966baf32 (Apr 2026) — Tenth confirmed sibling. Version 10.21.31.2, internal name sdfgchvjbknkhvgfnd.exe, filename nueva orden de compra.exe, 22 embedded BMPs at 76×76×24 (typical cluster count), Spanish purchase-order lure (first Spanish-language sibling), RijndaelManaged + CryptoStream + MemoryStream + CreateDecryptor strings present, Assembly.Load → GetMethod → Invoke reflective loading, SoapHttpClientProtocol retained, no DeflateStream / System.IO.Compression, no BackgroundWorker, no anti-VM. Randomized namespace 6ajWgBb4Pf3. Static-only analysis. ^[/intel/analyses/966baf32504c07e467c8bdddd35a43b4908a8a7b1eb54cb14edc056608604d47.html]

||- 0becdb662b (May 2026) — Eleventh confirmed sibling. Version 1.0.0.0, internal name wBjo.exe, filename MV_Lila_Houston_Vessel_Information_Particulars.exe, "FlashQuiz" Uzbek-language quiz GUI masquerade (FormViktorina, FormNatija, FormKategoriya), 2 embedded image carriers (BMP 180×180×32 + PNG 650×698 RGBA), ExtractPixelBytes method present, Activator.CreateInstance reflective loading. No network APIs, no persistence, no anti-analysis. Builder template identical to siblings 0cfbc10a and 1d3e20ae. Static-only analysis. ^[/intel/analyses/0becdb662b66302f1391bb651af0f8eadf42bac64654db18ddd13d860377cacb.html]

||- 0cfbc10a (May 2026) — Twelfth confirmed sibling. Version 0.0.0.0, internal name rmgW.exe, filename MT103_€162,024,40_Febeuary-May 2026_pdf.bat, identical "FlashQuiz" Uzbek quiz GUI masquerade and builder template, 2 embedded image carriers (BMP 180×180×32 + PNG 622×670 RGBA), ExtractPixelBytes + Activator.CreateInstance reflective loading pattern. SWIFT/banking-filename social engineering with .bat extension masquerade. OpenCTI mislabelled spamita. Built 55 minutes after sibling 0becdb662b. Static-only analysis. ^[/intel/analyses/0cfbc10a408c5747c977cbac7e92bee4aaac42f6fb8d3d73b6e3b0de05208ba0.html]

Note

No runtime C2 IOCs recovered; payload logic is ciphertext inside bitmaps. Requires detonation or manual bitmap extraction + decryption key recovery.