Modular Builder License Fingerprint
Builder-kit malware that is sold as malware-as-a-service often embeds a license key and hardware-ID check to enforce per-customer licensing. The license string format and hardware-ID field become a static fingerprint that can identify samples from the same builder or author, even when the payload modules differ.
Detection / Fingerprint
- Hardcoded license-key prefix:
LICKEY:followed by a hyphen-separated alphanumeric pattern (e.g.,LICKEY:282E-3295-7AF9-B92D...) hwid_orhwidstring near the license key, indicating hardware-ID based activationfeaturesstring table listing selectable modules (e.g.,exe_replacer,crypto_clipper,ransom_note,worm_enabled)- No VS_VERSIONINFO or social-engineering masquerade — the builder operator applies distribution packaging separately
Implementation Patterns
Sample ec95bcf4 shows the complete builder fingerprint:
- License key:
LICKEY:282E-3295-7AF9-B92DXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX - Hardware ID gate:
&hwid_ - Feature toggle list: 22 module names including stealer, clipper, injector, RAT, ransomware, and worm components
The presence of both a license key and a modular feature list in the same binary strongly suggests a commercial builder kit rather than a single-purpose malware.
Defensive Countermeasures
- YARA rules targeting
LICKEY:+hwid_+featuresin PE32+ x64 binaries with MSVC 14.50+ linker - Monitor for processes spawned with
--binder-child,--no-binder,--no-elevation, or--persistenceflags (observed inec95bcf4entry-point decompilation)
Pages Where Observed
- unclassified-pe64-modular-builder
ec95bcf4^[/intel/analyses/ec95bcf427c8082f97928eebd0084f31fb008c19cbb27670afedfb6533470d8c.html]