typeentityconfidencemediumcreated2026-08-26updated2026-08-26malware-familycrypterloaderpegcleanerevasion

us0file

Windows x64 encrypted-overlay dropper family with a custom crypter/loader framework internally branded GDCRYPT. Distributed via the gcleaner multi-payload bundler pipeline. First confirmed sample in this corpus (796a371d, May 2026).

Build Stack

  • Toolchain: MSVC 14.50 (Visual Studio 2019/2022), x64 Release, /MT static CRT
  • Language: C/C++ (no CLR metadata; C++ exception/RTTI strings present) ^[sample 796a371d/strings.txt]
  • Packing / Encryption: Custom — 608 KB encrypted overlay appended past the last PE section, decrypted in-memory by the GDCRYPT stub
  • Anti-analysis: Stomped PE timestamp (2007), QPC timing gate, RAM gate (≥ 256 MB), CPU-count gate (≥ 2), uptime gate (≥ 36 s), path gate (aborts if launched from PROGRAMDATA, PROGRAM FILES, or \WINDOWS\) ^[/intel/analyses/796a371d25a0a76a03f74fddd75c3774077d1329b7a27366a1bf9c6dfecd882c.html]
  • Signing: Unsigned
  • No .rsrc: No embedded icons, manifests, or RCData; all malicious content is in the overlay

Deploy / TTPs

Technique Implementation ATT&CK
Encrypted overlay dropper Reads own file, decrypts overlay, maps reflectively T1564.003
Reflective code loading NtAllocateVirtualMemory + NtProtectVirtualMemory + indirect dispatch via call-table T1620
Sandbox evasion Multi-gate: QPC timing, RAM, CPU count, uptime, execution path T1497.001, T1497.003
Native API abuse Direct ntdll primitives resolved at runtime T1106
Process injection CreateProcessA + VirtualAlloc/VirtualProtect suggests hollow or fork T1055
Distribution Via gcleaner multi-payload pipeline (OpenCTI label dropped-by-gcleaner) T1104

Variants / Aliases

  • OpenCTI label: us0.file
  • Builder/crypter internal name: GDCRYPT (marker string GDCRYPT!kernel32)
  • No confirmed siblings in corpus yet. Observed payload may be .NET-based (mscoree.dll / CorExitProcess strings present).

Notable Analyses

  • 796a371d — First confirmed sample. MSVC 14.50 x64, six clean sections, 608 KB encrypted overlay, GDCRYPT branding, five-tier anti-sandbox gating. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/796a371d25a0a76a03f74fddd75c3774077d1329b7a27366a1bf9c6dfecd882c.html]

Capabilities

  • encrypted-overlay-payload-delivery
  • reflective-pe-loader-ntdll-primitives
  • qpc-timing-sandbox-gate
  • ram-threshold-sandbox-gate
  • cpu-count-sandbox-gate
  • uptime-sandbox-gate
  • execution-path-sandbox-gate
  • gdcrypt-custom-crypter-framework
  • gcleaner-distribution-pipeline

Related