typeanalysisfamilyphorpiexconfidencehighcreated2026-07-31updated2026-07-31peloaderc2defense-evasionanti-vmmitre-attck
SHA-256: 5549d978e2e00768fc99d95bd7644dfebacc261284e3b19a79e6e4c1f320fa3a

phorpiex: 5549d978e2e0 — 15-payload cleartext HTTP fetcher with dual anti-sandbox gates

Executive Summary: An 11.8 KB MSVC 9.0 x86 PE32 downloader compiled 2026-05-26 and tagged dropped-by-phorpiex by OpenCTI. Fetches up to 15 payloads from 178.16.54.109 via a dual WinInet/URLMon path, stages to %TEMP% with randomized filenames, deletes Zone.Identifier ADS, and executes via ShellExecuteW. Gated by RtlGetVersion build-number check (≥22000) and x64 Program Files (x86) presence check. Confirmed sibling of the Phorpiex thin-downloader campaign.

What It Is

  • File: PE32 executable (GUI) Intel 80386, 5 sections, 11,776 bytes ^[file.txt]
  • Toolchain: MSVC 9.0 (VS 2008) linker, MSVCR90.dll CRT, compiled Tue May 26 10:32:54 2026 UTC ^[rabin2-info.txt:11] ^[pefile.txt:34]
  • Entry: Honest __wgetmainargs → main at 0x4014b3 ^[r2:main] ^[r2:entry0]
  • Signing: Unsigned ^[rabin2-info.txt:27]
  • Packing: None — .text entropy 5.78, .rdata entropy 4.14 ^[pefile.txt:92] ^[pefile.txt:112]

How It Works

main() sleeps 2000 ms, then iterates 15 hardcoded HTTP URLs on 178.16.54.109 (1.exe–14.exe, peinf.exe, xmr.exe, xmrget.exe, grab.exe), passing each to the downloader worker fcn.004010a8 ^[r2:main]. Before the fetch loop, two anti-sandbox gates are evaluated:

  1. OS build gate (fcn.00401435): resolves RtlGetVersion from ntdll.dll, checks dwBuildNumber >= 0x55f0 (22000, Windows 11 / Server 2022) ^[r2:fcn.00401435]
  2. x64 arch gate (fcn.004013e5): verifies %SYSTEMDRIVE%\Program Files (x86) exists via PathFileExistsW ^[r2:fcn.004013e5]

If either gate fails, the payload branch is skipped. After the gates, two marker-file mutex checks (fcn.004012fb and fcn.00401370) test for %appdata%\d3333333333333333333.txt and %appdata%\f3f3f3d3d.txt; if present, execution halts ^[r2:fcn.004012fb] ^[r2:fcn.00401370].

The downloader worker (fcn.004010a8) ^[r2:fcn.004010a8]:

  • Seeds srand(GetTickCount())
  • Expands %TEMP% and generates a random filename (%s\%d%d.exe)
  • Opens a WinInet session with fake Chrome 128 UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ^[r2:fcn.004010a8]
  • Primary path: InternetOpenUrlW → InternetReadFile → WriteFile to %TEMP%\<rand>.exe
  • On failure: sleeps 1000 ms, falls back to URLDownloadToFileW with a fresh random filename
  • Post-download: deletes Zone.Identifier ADS via DeleteFileW ^[r2:fcn.004010a8]
  • Executes the staged file via ShellExecuteW with verb open ^[r2:section..text]

C2 Infrastructure

  • IP: 178.16.54.109 (hardcoded, cleartext HTTP)
  • Payload URLs:
    • http://178.16.54.109/1.exe through 14.exe
    • http://178.16.54.109/peinf.exe
    • http://178.16.54.109/xmr.exe
    • http://178.16.54.109/xmrget.exe
    • http://178.16.54.109/grab.exe ^[r2:main]

Deploy / ATT&CK

Technique ID Evidence
User Execution: Malicious File T1204.002 Spam-distributed PE with social-engineered name ^[metadata.json]
Ingress Tool Transfer T1105 Dual WinInet + URLMon HTTP fetch to %TEMP% ^[r2:fcn.004010a8]
Anti-sandbox: OS build gating T1497.001 RtlGetVersion → dwBuildNumber >= 0x55f0 ^[r2:fcn.00401435]
Anti-sandbox: Architecture check T1497.001 PathFileExistsW on %SYSTEMDRIVE%\Program Files (x86) ^[r2:fcn.004013e5]
Defense Evasion: ADS deletion T1070.004 DeleteFileW on %s:Zone.Identifier ^[r2:fcn.004010a8]
Marker-file mutex gating — CreateFileW on %appdata%\d333...txt and f3f3...txt ^[r2:fcn.004012fb]

Persistence: Not observed in this sample. Campaign-level persistence (scheduled tasks, registry Run) documented on phorpiex entity page.

Interesting Tidbits

  • Largest payload list in the thin-downloader campaign: 15 URLs vs 5 in the earliest sibling (f67e429d) ^[entities/phorpiex.md]
  • Same C2 IP and toolchain as nine confirmed campaign siblings; this is the tenth thin-downloader sibling in the corpus
  • Honest main() flow — no initterm hijack, no reflective loader, no shellcode. The anti-analysis is entirely in pre-execution gates
  • IsDebuggerPresent is imported but not called in the decompiled main path; likely residual CRT linkage ^[pefile.txt:331]

Deployable Signatures

YARA

rule phorpiex_thin_downloader_15payload {
    meta:
        description = "Phorpiex thin MSVC9 downloader with 15-payload cleartext HTTP list"
        author = "PacketPursuit"
        date = "2026-07-31"
        sha256 = "5549d978e2e00768fc99d95bd7644dfebacc261284e3b19a79e6e4c1f320fa3a"
    strings:
        $ua = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" wide
        $c2 = "http://178.16.54.109/" ascii wide
        $zone = "%s:Zone.Identifier" wide
        $temp_fmt = "%s\\%d%d.exe" wide
        $marker1 = "d3333333333333333333.txt" wide
        $marker2 = "f3f3f3d3d.txt" wide
        $ntdll = "ntdll.dll" wide
        $progfiles = "%s\\Program Files (x86)" wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 20KB and
        4 of them and
        pe.imports("WININET.dll", "InternetOpenUrlW") and
        pe.imports("urlmon.dll", "URLDownloadToFileW")
}

IOCs

Indicator Value Type
SHA-256 5549d978e2e00768fc99d95bd7644dfebacc261284e3b19a79e6e4c1f320fa3a Hash
C2 IP 178.16.54.109 IPv4
Payload URLs http://178.16.54.109/{1..14,peinf,xmr,xmrget,grab}.exe URL
Marker files %appdata%\d3333333333333333333.txt, %appdata%\f3f3f3d3d.txt File
Staging path %TEMP%\<rand><rand>.exe File
User-Agent Chrome/128.0.0.0 Network

Behavioral Fingerprint

This binary is a thin MSVC9 x86 PE (<20 KB) with minimal IAT (WININET + URLMon + KERNEL32 + MSVCR90 + SHLWAPI + SHELL32). On launch it gates execution via RtlGetVersion build-number check (≥22000) and PathFileExistsW on Program Files (x86). If passed, it fetches one or more payloads from hardcoded HTTP URLs using WinInet primary and URLMon fallback, writes to a random %TEMP% filename, strips Zone.Identifier ADS, and executes via ShellExecuteW. Random filename generation is seeded with GetTickCount. Typical execution shows 1–3 second Sleep delays and 2–4 HTTP GETs to the same IP with sequential numeric paths.

References

Provenance

  • file.txt — file v5.44
  • pefile.txt — pefile v2023.2.7
  • rabin2-info.txt — radare2 v5.9.8
  • r2:fcn.004010a8, r2:fcn.004012fb, r2:fcn.00401370, r2:fcn.004013e5, r2:fcn.00401435, r2:main, r2:entry0, r2:section..text — radare2 decompilation via r2mcp
  • exiftool.json — exiftool v12.76
  • metadata.json — OpenCTI artifact record