unclassified-pe64-modular-builder
Umbrella entity for a singleton MSVC 14.50 PE64+ modular malware builder kit observed in sample ec95bcf4. The binary carries 17+ selectable feature modules (stealer, clipper, RAT, ransomware, worm, injector) and resolves C2 via Ethereum ENS text records over public RPC endpoints. No siblings confirmed in corpus.
Build Stack
- Compiler: MSVC 14.50 (Visual Studio 2022 17.10+)
- Language: C++ (heavy STL RTTI, nlohmann/json strings, no nlohmann version string recovered)
- Crypto: ChaCha20 (
expand 32-byte kconstant), bcrypt.dll CNG (AES/SHA) - Database: SQLite 3.49.1 (amalgamation) for local credential staging
- Network: WinHTTP with WebSocket upgrade (
WinHttpWebSocket*APIs) - Graphics: GDI+ (screenshot encoding), D3D11/DXGI/MF (media capture for RAT)
- Anti-analysis: VM/sandbox string detection (VirtualBox, VMware, QEMU, Xen, Hyper-V, AWS Nitro),
IsDebuggerPresent,CheckRemoteDebuggerPresent - License gating:
LICKEY:XXXX-XXXX-XXXX-XXXX...format withhwid_hardware-ID check
Deploy / TTPs
| ATT&CK ID | Technique | Implementation |
|---|---|---|
| T1555.003 | Credentials from Web Browsers / App-Bound Encryption Bypass | Chrome 127+ ABE bypass via app_bound_encrypted_key; SQLite queries for logins, cookies, credit cards, autofill, tokens ^[sample ec95bcf4/strings.txt:5268-5295] |
| T1071.001 | Application Layer Protocol: WebSockets | WinHTTP WebSocket APIs; wss:// transport ^[sample ec95bcf4/pefile.txt] |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | String-based VM detection for 10+ hypervisor families ^[sample ec95bcf4/strings.txt:5080-5124] |
| T1055 | Process Injection | WriteProcessMemory, SetThreadContext, SuspendThread, ResumeThread, VirtualProtectEx ^[sample ec95bcf4/pefile.txt] |
| T1113 | Screen Capture | GDI+ imports, screenshot feature, remote_desktop frame strings ^[sample ec95bcf4/strings.txt:4820] |
| T1115 | Clipboard Data | OpenClipboard, GetClipboardData, SetClipboardData, EmptyClipboard, crypto_clipper module ^[sample ec95bcf4/pefile.txt] |
| T1490 | Inhibit System Recovery | ransom_note, ransom_master_key_hex, data_encryptor modules ^[sample ec95bcf4/strings.txt:4831-4833] |
| T1491.001 | Defacement: Internal Defacement | worm_enabled, worm_messages modules ^[sample ec95bcf4/strings.txt:4834-4835] |
| T1567.002 | Exfiltration Over Web Service: WebSocket | WebSocket-over-TLS C2 after ENS resolution ^[sample ec95bcf4/strings.txt:20476] |
Capabilities
ens-ethereum-c2-resolution— C2 resolved via ENS text records on Ethereum mainnetwebsocket-c2-transport— WebSocket-over-TLS command channelmodular-builder-license-fingerprint— Builder-kit withLICKEYlicense gating andhwid_hardware ID checkchrome-app-bound-encryption-bypass— Chrome 127+ ABE credential database decryptionbrowser-credential-harvesting— Chromium-family login/cookie/credit-card/token extractionclipboard-hijack-cryptocurrency— Crypto-address replacement via clipboard monitoringremote-desktop-hvnc— WebSocket-based remote desktop with GDI+ frame capturediscord-injection— Discord client injection moduleexodus-wallet-injection— Exodus wallet injection moduletelegram-exfiltration— Telegram data theft moduledata-encryption-ransomware— File encryption / ransom note moduleworm-propagation— Self-spreading moduleprocess-injection-writeprocessmemory— Process hollowing / thread hijackingvm-sandbox-detection-string-matching— Hypervisor family string detectiondebug-detection-isdebuggerpresent— Debugger presence checkssqlite-local-staging— SQLite 3.49.1 for local data stagingchacha20-payload-encryption— ChaCha20 for config/payload encryption
Variants / Aliases
None confirmed. Singleton pending cluster.
Notable Analyses
ec95bcf4— First observed sample (May 2026,9BRIMp6CcY4y.exe). Static-only. ^[/intel/analyses/ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c.html]
Related Entities / Techniques
- ens-ethereum-c2-resolution — ENS text-record C2 resolution technique
- modular-builder-license-fingerprint — Builder-kit license-key gating pattern
- app-bound-encryption-bypass — Chrome ABE bypass
- websocket-c2-transport — WebSocket C2 transport
- chacha8 — ChaCha20 stream cipher family (shares
expand 32-byte kconstant) - browser-credential-harvesting — Cross-family browser credential theft concept
- clipboard-hijack-cryptocurrency — Cross-family clipboard hijacking concept