typetechniqueconfidencehighcreated2026-08-26updated2026-08-26obfuscationevasionmalware-family

Modular Builder License Fingerprint

Builder-kit malware that is sold as malware-as-a-service often embeds a license key and hardware-ID check to enforce per-customer licensing. The license string format and hardware-ID field become a static fingerprint that can identify samples from the same builder or author, even when the payload modules differ.

Detection / Fingerprint

  • Hardcoded license-key prefix: LICKEY: followed by a hyphen-separated alphanumeric pattern (e.g., LICKEY:282E-3295-7AF9-B92D...)
  • hwid_ or hwid string near the license key, indicating hardware-ID based activation
  • features string table listing selectable modules (e.g., exe_replacer, crypto_clipper, ransom_note, worm_enabled)
  • No VS_VERSIONINFO or social-engineering masquerade — the builder operator applies distribution packaging separately

Implementation Patterns

Sample ec95bcf4 shows the complete builder fingerprint:

  • License key: LICKEY:282E-3295-7AF9-B92DXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
  • Hardware ID gate: &hwid_
  • Feature toggle list: 22 module names including stealer, clipper, injector, RAT, ransomware, and worm components

The presence of both a license key and a modular feature list in the same binary strongly suggests a commercial builder kit rather than a single-purpose malware.

Defensive Countermeasures

  • YARA rules targeting LICKEY: + hwid_ + features in PE32+ x64 binaries with MSVC 14.50+ linker
  • Monitor for processes spawned with --binder-child, --no-binder, --no-elevation, or --persistence flags (observed in ec95bcf4 entry-point decompilation)

Pages Where Observed