typeentityconfidencelowcreated2026-08-26updated2026-08-26malware-familypecompilerc2exfiltrationpersistencedefense-evasiondiscoveryimpactmitre-attck

unclassified-pe64-modular-builder

Umbrella entity for a singleton MSVC 14.50 PE64+ modular malware builder kit observed in sample ec95bcf4. The binary carries 17+ selectable feature modules (stealer, clipper, RAT, ransomware, worm, injector) and resolves C2 via Ethereum ENS text records over public RPC endpoints. No siblings confirmed in corpus.

Build Stack

  • Compiler: MSVC 14.50 (Visual Studio 2022 17.10+)
  • Language: C++ (heavy STL RTTI, nlohmann/json strings, no nlohmann version string recovered)
  • Crypto: ChaCha20 (expand 32-byte k constant), bcrypt.dll CNG (AES/SHA)
  • Database: SQLite 3.49.1 (amalgamation) for local credential staging
  • Network: WinHTTP with WebSocket upgrade (WinHttpWebSocket* APIs)
  • Graphics: GDI+ (screenshot encoding), D3D11/DXGI/MF (media capture for RAT)
  • Anti-analysis: VM/sandbox string detection (VirtualBox, VMware, QEMU, Xen, Hyper-V, AWS Nitro), IsDebuggerPresent, CheckRemoteDebuggerPresent
  • License gating: LICKEY:XXXX-XXXX-XXXX-XXXX... format with hwid_ hardware-ID check

Deploy / TTPs

ATT&CK ID Technique Implementation
T1555.003 Credentials from Web Browsers / App-Bound Encryption Bypass Chrome 127+ ABE bypass via app_bound_encrypted_key; SQLite queries for logins, cookies, credit cards, autofill, tokens ^[sample ec95bcf4/strings.txt:5268-5295]
T1071.001 Application Layer Protocol: WebSockets WinHTTP WebSocket APIs; wss:// transport ^[sample ec95bcf4/pefile.txt]
T1497.001 Virtualization/Sandbox Evasion: System Checks String-based VM detection for 10+ hypervisor families ^[sample ec95bcf4/strings.txt:5080-5124]
T1055 Process Injection WriteProcessMemory, SetThreadContext, SuspendThread, ResumeThread, VirtualProtectEx ^[sample ec95bcf4/pefile.txt]
T1113 Screen Capture GDI+ imports, screenshot feature, remote_desktop frame strings ^[sample ec95bcf4/strings.txt:4820]
T1115 Clipboard Data OpenClipboard, GetClipboardData, SetClipboardData, EmptyClipboard, crypto_clipper module ^[sample ec95bcf4/pefile.txt]
T1490 Inhibit System Recovery ransom_note, ransom_master_key_hex, data_encryptor modules ^[sample ec95bcf4/strings.txt:4831-4833]
T1491.001 Defacement: Internal Defacement worm_enabled, worm_messages modules ^[sample ec95bcf4/strings.txt:4834-4835]
T1567.002 Exfiltration Over Web Service: WebSocket WebSocket-over-TLS C2 after ENS resolution ^[sample ec95bcf4/strings.txt:20476]

Capabilities

  • ens-ethereum-c2-resolution — C2 resolved via ENS text records on Ethereum mainnet
  • websocket-c2-transport — WebSocket-over-TLS command channel
  • modular-builder-license-fingerprint — Builder-kit with LICKEY license gating and hwid_ hardware ID check
  • chrome-app-bound-encryption-bypass — Chrome 127+ ABE credential database decryption
  • browser-credential-harvesting — Chromium-family login/cookie/credit-card/token extraction
  • clipboard-hijack-cryptocurrency — Crypto-address replacement via clipboard monitoring
  • remote-desktop-hvnc — WebSocket-based remote desktop with GDI+ frame capture
  • discord-injection — Discord client injection module
  • exodus-wallet-injection — Exodus wallet injection module
  • telegram-exfiltration — Telegram data theft module
  • data-encryption-ransomware — File encryption / ransom note module
  • worm-propagation — Self-spreading module
  • process-injection-writeprocessmemory — Process hollowing / thread hijacking
  • vm-sandbox-detection-string-matching — Hypervisor family string detection
  • debug-detection-isdebuggerpresent — Debugger presence checks
  • sqlite-local-staging — SQLite 3.49.1 for local data staging
  • chacha20-payload-encryption — ChaCha20 for config/payload encryption

Variants / Aliases

None confirmed. Singleton pending cluster.

Notable Analyses

  • ec95bcf4 — First observed sample (May 2026, 9BRIMp6CcY4y.exe). Static-only. ^[/intel/analyses/ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c.html]

Related Entities / Techniques