5549d978e2e00768fc99d95bd7644dfebacc261284e3b19a79e6e4c1f320fa3aphorpiex: 5549d978e2e0 — 15-payload cleartext HTTP fetcher with dual anti-sandbox gates
Executive Summary: An 11.8 KB MSVC 9.0 x86 PE32 downloader compiled 2026-05-26 and tagged dropped-by-phorpiex by OpenCTI. Fetches up to 15 payloads from 178.16.54.109 via a dual WinInet/URLMon path, stages to %TEMP% with randomized filenames, deletes Zone.Identifier ADS, and executes via ShellExecuteW. Gated by RtlGetVersion build-number check (≥22000) and x64 Program Files (x86) presence check. Confirmed sibling of the Phorpiex thin-downloader campaign.
What It Is
- File: PE32 executable (GUI) Intel 80386, 5 sections, 11,776 bytes ^[file.txt]
- Toolchain: MSVC 9.0 (VS 2008) linker, MSVCR90.dll CRT, compiled Tue May 26 10:32:54 2026 UTC ^[rabin2-info.txt:11] ^[pefile.txt:34]
- Entry: Honest
__wgetmainargs→mainat0x4014b3^[r2:main] ^[r2:entry0] - Signing: Unsigned ^[rabin2-info.txt:27]
- Packing: None —
.textentropy 5.78,.rdataentropy 4.14 ^[pefile.txt:92] ^[pefile.txt:112]
How It Works
main() sleeps 2000 ms, then iterates 15 hardcoded HTTP URLs on 178.16.54.109 (1.exe–14.exe, peinf.exe, xmr.exe, xmrget.exe, grab.exe), passing each to the downloader worker fcn.004010a8 ^[r2:main]. Before the fetch loop, two anti-sandbox gates are evaluated:
- OS build gate (
fcn.00401435): resolvesRtlGetVersionfromntdll.dll, checksdwBuildNumber >= 0x55f0(22000, Windows 11 / Server 2022) ^[r2:fcn.00401435] - x64 arch gate (
fcn.004013e5): verifies%SYSTEMDRIVE%\Program Files (x86)exists viaPathFileExistsW^[r2:fcn.004013e5]
If either gate fails, the payload branch is skipped. After the gates, two marker-file mutex checks (fcn.004012fb and fcn.00401370) test for %appdata%\d3333333333333333333.txt and %appdata%\f3f3f3d3d.txt; if present, execution halts ^[r2:fcn.004012fb] ^[r2:fcn.00401370].
The downloader worker (fcn.004010a8) ^[r2:fcn.004010a8]:
- Seeds
srand(GetTickCount()) - Expands
%TEMP%and generates a random filename (%s\%d%d.exe) - Opens a WinInet session with fake Chrome 128 UA:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36^[r2:fcn.004010a8] - Primary path:
InternetOpenUrlW→InternetReadFile→WriteFileto%TEMP%\<rand>.exe - On failure: sleeps 1000 ms, falls back to
URLDownloadToFileWwith a fresh random filename - Post-download: deletes
Zone.IdentifierADS viaDeleteFileW^[r2:fcn.004010a8] - Executes the staged file via
ShellExecuteWwith verbopen^[r2:section..text]
C2 Infrastructure
- IP:
178.16.54.109(hardcoded, cleartext HTTP) - Payload URLs:
http://178.16.54.109/1.exethrough14.exehttp://178.16.54.109/peinf.exehttp://178.16.54.109/xmr.exehttp://178.16.54.109/xmrget.exehttp://178.16.54.109/grab.exe^[r2:main]
Deploy / ATT&CK
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | Spam-distributed PE with social-engineered name ^[metadata.json] |
| Ingress Tool Transfer | T1105 | Dual WinInet + URLMon HTTP fetch to %TEMP% ^[r2:fcn.004010a8] |
| Anti-sandbox: OS build gating | T1497.001 | RtlGetVersion → dwBuildNumber >= 0x55f0 ^[r2:fcn.00401435] |
| Anti-sandbox: Architecture check | T1497.001 | PathFileExistsW on %SYSTEMDRIVE%\Program Files (x86) ^[r2:fcn.004013e5] |
| Defense Evasion: ADS deletion | T1070.004 | DeleteFileW on %s:Zone.Identifier ^[r2:fcn.004010a8] |
| Marker-file mutex gating | — | CreateFileW on %appdata%\d333...txt and f3f3...txt ^[r2:fcn.004012fb] |
Persistence: Not observed in this sample. Campaign-level persistence (scheduled tasks, registry Run) documented on phorpiex entity page.
Interesting Tidbits
- Largest payload list in the thin-downloader campaign: 15 URLs vs 5 in the earliest sibling (
f67e429d) ^[entities/phorpiex.md] - Same C2 IP and toolchain as nine confirmed campaign siblings; this is the tenth thin-downloader sibling in the corpus
- Honest
main()flow — noinittermhijack, no reflective loader, no shellcode. The anti-analysis is entirely in pre-execution gates IsDebuggerPresentis imported but not called in the decompiled main path; likely residual CRT linkage ^[pefile.txt:331]
Deployable Signatures
YARA
rule phorpiex_thin_downloader_15payload {
meta:
description = "Phorpiex thin MSVC9 downloader with 15-payload cleartext HTTP list"
author = "PacketPursuit"
date = "2026-07-31"
sha256 = "5549d978e2e00768fc99d95bd7644dfebacc261284e3b19a79e6e4c1f320fa3a"
strings:
$ua = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" wide
$c2 = "http://178.16.54.109/" ascii wide
$zone = "%s:Zone.Identifier" wide
$temp_fmt = "%s\\%d%d.exe" wide
$marker1 = "d3333333333333333333.txt" wide
$marker2 = "f3f3f3d3d.txt" wide
$ntdll = "ntdll.dll" wide
$progfiles = "%s\\Program Files (x86)" wide
condition:
uint16(0) == 0x5A4D and
filesize < 20KB and
4 of them and
pe.imports("WININET.dll", "InternetOpenUrlW") and
pe.imports("urlmon.dll", "URLDownloadToFileW")
}
IOCs
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 5549d978e2e00768fc99d95bd7644dfebacc261284e3b19a79e6e4c1f320fa3a |
Hash |
| C2 IP | 178.16.54.109 |
IPv4 |
| Payload URLs | http://178.16.54.109/{1..14,peinf,xmr,xmrget,grab}.exe |
URL |
| Marker files | %appdata%\d3333333333333333333.txt, %appdata%\f3f3f3d3d.txt |
File |
| Staging path | %TEMP%\<rand><rand>.exe |
File |
| User-Agent | Chrome/128.0.0.0 |
Network |
Behavioral Fingerprint
This binary is a thin MSVC9 x86 PE (<20 KB) with minimal IAT (WININET + URLMon + KERNEL32 + MSVCR90 + SHLWAPI + SHELL32). On launch it gates execution via RtlGetVersion build-number check (≥22000) and PathFileExistsW on Program Files (x86). If passed, it fetches one or more payloads from hardcoded HTTP URLs using WinInet primary and URLMon fallback, writes to a random %TEMP% filename, strips Zone.Identifier ADS, and executes via ShellExecuteW. Random filename generation is seeded with GetTickCount. Typical execution shows 1–3 second Sleep delays and 2–4 HTTP GETs to the same IP with sequential numeric paths.
References
- phorpiex — campaign entity page
- rtlgversion-build-gating — technique page
- x64-arch-check-progfiles-x86 — technique page
- marker-file-mutex-gating — technique page
- wininet-urlmon-dual-download — technique page
- zone-identifier-deletion — technique page
- gettickcount-anti-emulation-loop — technique page
Provenance
file.txt—filev5.44pefile.txt—pefilev2023.2.7rabin2-info.txt—radare2v5.9.8r2:fcn.004010a8,r2:fcn.004012fb,r2:fcn.00401370,r2:fcn.004013e5,r2:fcn.00401435,r2:main,r2:entry0,r2:section..text— radare2 decompilation via r2mcpexiftool.json—exiftoolv12.76metadata.json— OpenCTI artifact record