us0file
Windows x64 encrypted-overlay dropper family with a custom crypter/loader framework internally branded GDCRYPT. Distributed via the gcleaner multi-payload bundler pipeline. First confirmed sample in this corpus (796a371d, May 2026).
Build Stack
- Toolchain: MSVC 14.50 (Visual Studio 2019/2022), x64 Release,
/MTstatic CRT - Language: C/C++ (no CLR metadata; C++ exception/RTTI strings present) ^[sample 796a371d/strings.txt]
- Packing / Encryption: Custom — 608 KB encrypted overlay appended past the last PE section, decrypted in-memory by the GDCRYPT stub
- Anti-analysis: Stomped PE timestamp (2007), QPC timing gate, RAM gate (≥ 256 MB), CPU-count gate (≥ 2), uptime gate (≥ 36 s), path gate (aborts if launched from
PROGRAMDATA,PROGRAM FILES, or\WINDOWS\) ^[/intel/analyses/796a371d25a0a76a03f74fddd75c3774077d1329b7a27366a1bf9c6dfecd882c.html] - Signing: Unsigned
- No .rsrc: No embedded icons, manifests, or RCData; all malicious content is in the overlay
Deploy / TTPs
| Technique | Implementation | ATT&CK |
|---|---|---|
| Encrypted overlay dropper | Reads own file, decrypts overlay, maps reflectively | T1564.003 |
| Reflective code loading | NtAllocateVirtualMemory + NtProtectVirtualMemory + indirect dispatch via call-table |
T1620 |
| Sandbox evasion | Multi-gate: QPC timing, RAM, CPU count, uptime, execution path | T1497.001, T1497.003 |
| Native API abuse | Direct ntdll primitives resolved at runtime | T1106 |
| Process injection | CreateProcessA + VirtualAlloc/VirtualProtect suggests hollow or fork |
T1055 |
| Distribution | Via gcleaner multi-payload pipeline (OpenCTI label dropped-by-gcleaner) |
T1104 |
Variants / Aliases
- OpenCTI label:
us0.file - Builder/crypter internal name: GDCRYPT (marker string
GDCRYPT!kernel32) - No confirmed siblings in corpus yet. Observed payload may be .NET-based (
mscoree.dll/CorExitProcessstrings present).
Notable Analyses
796a371d— First confirmed sample. MSVC 14.50 x64, six clean sections, 608 KB encrypted overlay, GDCRYPT branding, five-tier anti-sandbox gating. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/796a371d25a0a76a03f74fddd75c3774077d1329b7a27366a1bf9c6dfecd882c.html]
Capabilities
encrypted-overlay-payload-deliveryreflective-pe-loader-ntdll-primitivesqpc-timing-sandbox-gateram-threshold-sandbox-gatecpu-count-sandbox-gateuptime-sandbox-gateexecution-path-sandbox-gategdcrypt-custom-crypter-frameworkgcleaner-distribution-pipeline
Related
- gcleaner — distribution infrastructure
- reflective-pe-loader — runtime payload mapping pattern