7dc5d926d6f83fa5b23ac8024e87f6552364053a55ba7704f0811fb203223350silverfox: 7dc5d926 — FALSE POSITIVE: NetEase game launcher mislabeled by OpenCTI
Executive Summary
This sample is a legitimate NetEase game launcher (Fantasy Westward Journey: Space-Time / 梦幻西游:时空, v1.415.0.0) mislabeled silverfox and valleyrat by OpenCTI. The binary is an MSVC 2019 C/C++ PE32+ x64 compiled from a real Jenkins CI pipeline (rel_engine_branch3), bundles OpenSSL and libcurl, and contacts NetEase CDN endpoints. Zero SilverFox fingerprints are present. The social-engineering filename (点击切换简体中文语言包.exe — "Click to switch Simplified Chinese language pack") is the only malicious thing about it.
What It Is
| Attribute | Detail |
|---|---|
| SHA-256 | 7dc5d926d6f83fa5b23ac8024e87f6552364053a55ba7704f0811fb203223350 |
| File type | PE32+ executable (GUI) x86-64, 7 sections ^[file.txt] |
| Size | 3,613,632 bytes (3.6 MB) ^[triage.json] |
| Timestamp | Mon Apr 7 11:36:10 2025 UTC ^[pefile.txt:172] |
| Linker | MSVC 14.29 (Visual Studio 2019) ^[exiftool.json:18] |
| Language | C/C++ (rabin2 lang: c) ^[rabin2-info.txt:19] |
| Stripped | No — full PDB reference present ^[rabin2-info.txt:32] |
| PDB path | D:\Jenkins\work\workspace\rel_engine_branch3\Engine\Binaries\Win64\MyLauncher_x64r.pdb ^[rabin2-info.txt:13] |
| Signed | signed: true per rabin2, but security-directory raw data does not parse as valid DER PKCS#7 ^[rabin2-info.txt:29] ^[pefile.txt:370-371] |
| Filename (source) | 点击切换简体中文语言包.exe (Simplified Chinese language-pack lure) ^[triage.json:5] |
Version Information (VS_VERSIONINFO)
- CompanyName: Netease
- FileDescription: 梦幻西游:时空 (Fantasy Westward Journey: Space-Time) ^[pefile.txt:439-440]
- FileVersion: 1.415.0.0
- InternalName: MyLauncher.rc
- OriginalFilename: MyLauncher.exe
- ProductName: MyLauncher ^[pefile.txt:441-445]
- LegalCopyright: Copyright (c)2023 Netease, inc. ^[pefile.txt:443]
Why It Is NOT SilverFox
Absent: SilverFox stream-cipher constants
The C-variant SilverFox stub (82d42551) embeds four fixed 32-bit constants (0xcaaafe23, 0x3d57aa23, 0x44d9bb23, 0x9e37cb23) used in its custom stream cipher ^[entities/silverfox.md]. A full byte-level search across the entire binary returns zero matches for any of these values. ^[strings.txt] ^[r2:strings-search]
Absent: LZSS payload decompressor
SilverFox variants embed an in-memory LZSS decompressor (typically at FUN_140004000 in the C x64 builds) ^[entities/silverfox.md]. No LZSS window table, bit-stream parser, or sliding-window copy routine is observed in the disassembly. The .rsrc section is 12,544 bytes of standard Windows icon/manifest data (entropy 7.63 — normal for compressed PNGs), not an encrypted payload blob.
Absent: XOR-thunk API dispatch
The 50K C stub (82d42551) indirects every API call through a single XOR-decrypt thunk with >222 call sites ^[entities/silverfox.md]. The import table here is a standard MSVC IAT with 215 imports from KERNEL32, USER32, SHELL32, WS2_32, WLDAP32, ADVAPI32, and bcrypt ^[pefile.txt:461+] — no thunk obfuscation, no FNV-1a hash resolver, no PEB-walking.
Absent: Process hollowing / injection APIs
SilverFox uses NtAllocateVirtualMemory, NtWriteVirtualMemory, and CreateProcessW with CREATE_SUSPENDED for process hollowing ^[entities/silverfox.md]. This binary imports CreateProcessW and OpenProcess (standard launcher APIs) but has no NtAllocateVirtualMemory, NtWriteVirtualMemory, NtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory, or CreateRemoteThread imports. ^[pefile.txt:461-537]
Absent: Anti-analysis / evasion
No debugger checks, no VM detection, no sandbox gates, no IsDebuggerPresent loops, no Sleep obfuscation, no GetTickCount timing gates. The entry point is a straightforward MSVC CRT initialisation followed by WinMain.
Present: Legitimate game-launcher artefacts
- 334 distinct Jenkins build-path strings referencing
rel_engine_branch3^[strings.txt] - OpenSSL source paths (
D:\Jenkins\work\workspace\rel_engine_branch3\Engine\Sources\External\openssl\...) for 50+ crypto files ^[strings.txt] - NetEase CDN endpoints:
g18.gph.netease.com,g18.gdl.netease.com,g18.gsf.netease.com^[strings.txt:5209-5213] - Game patch-update logic:
PatchUpdate::find pc launcher files need to copy,http://update.my.163.com/my_patchlist_win32^[strings.txt:5217-5225] - libcurl error strings (
Couldn't connect to server,SSL connect error,Connection timed out) ^[strings.txt]
Build / RE Lens
Toolchain
- Compiler: MSVC 2019 (Utc1900_C v30146 × 576 objects, Utc1900_CPP v30034 × 279 objects, Masm1400 v30034 × 10 objects) ^[rabin2-info.txt:Rich Header]
- Linker: MSVC 14.29 (Linker1400 v30146) ^[rabin2-info.txt]
- Build system: Jenkins CI on Windows (
D:\Jenkins\work\workspace\rel_engine_branch3) ^[rabin2-info.txt:13] - Crypto library: OpenSSL (static-linked, embedded source paths confirm) ^[strings.txt]
- Networking: libcurl + WS2_32 (Winsock) ^[pefile.txt:461+]
Sections (standard MSVC)
| Section | Size | Entropy | Notes |
|---|---|---|---|
| .text | 2,514,240 | 6.41 | Normal code entropy |
| .rdata | 894,230 | 5.80 | Import table + read-only data |
| .data | 52,048 | 3.40 | Mutable data (low entropy = normal) |
| .pdata | 121,552 | 6.33 | Exception/unwind info |
| _RDATA | 244 | 2.46 | Small read-only block (TLS-related) |
| .rsrc | 12,544 | 7.63 | Icons + manifest (PNG compression) |
| .reloc | 29,408 | 5.44 | Base relocation table |
No RWX sections, no null-named sections, no encrypted overlays, no packed stubs. ^[pefile.txt:213-353]
Signing anomaly
The IMAGE_DIRECTORY_ENTRY_SECURITY points to 10,688 bytes at file offset 0x36FA00, but the raw bytes do not begin with a valid DER ASN.1 sequence tag (0x30). The first byte is 0xC0 — this is either a corrupted/fabricated signature block or non-standard Authenticode wrapping. The binary reports signed: true in rabin2, yet the signature is not cryptographically verifiable. This is the one suspicious feature, but it is insufficient to override the overwhelming benign evidence. ^[rabin2-info.txt:29] ^[pefile.txt:370-371]
Deploy / ATT&CK Lens
Not applicable. This binary exhibits no malicious TTPs. The only threat vector is the social-engineering filename — a technique already documented at social-engineering-filename-lure — which tricks the victim into executing a legitimate program under a false pretense.
If an attacker were distributing this binary, the chain would be:
- T1204.002 (User Execution: Malicious File) — victim double-clicks the
.exebelieving it is a language-pack installer. - T1036.005 (Masquerading: Match Legitimate Name or Location) — filename mimics a system utility.
The binary itself is not the payload; the payload is the trust transfer from a real, signed-looking executable to a social-engineering campaign.
Interesting Tidbits
- Jenkins bloat as provenance: The 334 Jenkins/OpenSSL path strings are an unintentional but powerful benign-fingerprint. No malware author embeds 50+ OpenSSL source file paths into a stub.
- NetEase CDN as C2 false positive: Analysts hunting for
netease.comnetwork IOCs would flag the threeg18.*.netease.comendpoints. These are legitimate game-patch CDN hosts. - PDB path as origin marker:
rel_engine_branch3suggests this is a release-engineering branch build, not a debug or test build. The_x64rsuffix likely means "x64 Release". - Rich Header is clean: The Rich Header shows only Microsoft toolchain products (Utc1900_C, Utc1900_CPP, Masm1400, Linker1400, Cvtres1400, Implib1400) with version numbers consistent with Visual Studio 2019. No third-party packer/crypter products. ^[rabin2-info.txt]
How To Mess With It (Homelab Replication)
This is a negative-control exercise — learn to distinguish false positives from real threats.
- Verify the PDB path: Run
rabin2 -P /path/to/sample | grep dbg_file. A real Jenkins path withEngine/Binaries/Win64strongly suggests a Unreal Engine-derived game launcher (NetEase uses UE for Fantasy Westward Journey). - Check for SilverFox constants:
python3 -c "import sys; data=open(sys.argv[1],'rb').read(); print(any(c in data.hex() for c in ['caaafe23','3d57aa23','44d9bb23','9e37cb23']))" sample.bin— should returnFalsefor this sample. - Inspect .rsrc entropy: Use
pefileto dump section entropies. A.rsrcof ~12 KB with entropy ~7.6 is normal (PNG icons). A.rsrcof 50K+ with entropy 7.9+ is suspicious for an encrypted payload. - Read VersionInfo in Chinese: The
FileDescriptionfield contains Chinese characters. If you don't read Chinese, pipe throughexiftool -bor a hex viewer — don't assume it's random noise.
Deployable Signatures
YARA — SilverFox false-positive exclusion
Use this rule to filter out NetEase launcher noise when hunting for SilverFox. It targets the benign fingerprint, not the threat.
rule silverfox_false_positive_netease_launcher
{
meta:
description = "Excludes NetEase MyLauncher binaries from SilverFox hunts"
author = "Titus"
date = "2026-08-08"
hash = "7dc5d926d6f83fa5b23ac8024e87f6552364053a55ba7704f0811fb203223350"
strings:
$pdb = "MyLauncher_x64r.pdb" ascii wide
$company = "Netease" ascii wide
$product = "MyLauncher" ascii wide
$cdn1 = "g18.gph.netease.com" ascii wide
$cdn2 = "g18.gdl.netease.com" ascii wide
$patch = "http://update.my.163.com/my_patchlist_win32" ascii wide
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections == 7 and
3 of them
}
IOC List
| Type | Value | Assessment |
|---|---|---|
| SHA-256 | 7dc5d926d6f83fa5b23ac8024e87f6552364053a55ba7704f0811fb203223350 |
Benign (false positive) |
| Filename | 点击切换简体中文语言包.exe |
Social-engineering lure |
| PDB | D:\Jenkins\work\workspace\rel_engine_branch3\Engine\Binaries\Win64\MyLauncher_x64r.pdb |
Benign build artefact |
| CDN | g18.gph.netease.com |
Legitimate NetEase game patch CDN |
| CDN | g18.gdl.netease.com |
Legitimate NetEase game patch CDN |
| CDN | g18.gsf.netease.com |
Legitimate NetEase game patch CDN |
| Update URL | http://update.my.163.com/my_patchlist_win32 |
Legitimate NetEase patch list |
Behavioral Fingerprint
This binary is a 3.6 MB MSVC 2019 PE32+ x64 GUI executable with standard 7-section layout, a readable PDB path pointing to a Jenkins CI workspace for a NetEase game engine branch, and 300+ OpenSSL build-path strings. It imports KERNEL32, USER32, SHELL32, WS2_32, WLDAP32, ADVAPI32, and bcrypt via a standard IAT with 215 entries. It does not import NtAllocateVirtualMemory, NtWriteVirtualMemory, VirtualAllocEx, WriteProcessMemory, or CreateRemoteThread. No SilverFox stream-cipher constants, LZSS decompressor, or XOR-thunk dispatch are present. The .rsrc section contains standard Windows icons and manifest data. The security directory is present but does not contain a valid DER-encoded PKCS#7 signature.
Detection Signatures
No capa output available (signature path error during triage) ^[capa.txt]. A manual capability assessment shows zero ATT&CK-mappable malicious behaviours.
References
- NetEase Fantasy Westward Journey: https://my.163.com (legitimate game portal)
- OpenCTI labels:
exe,malware-bazaar,shellcode,silverfox,valleyrat— all contested for this sample - Related wiki page: silverfox — actual SilverFox family entity (do not confuse with this false positive)
- Related concept: social-engineering-filename-lure — the real threat here is the filename, not the binary
Provenance
Analysis based on:
file.txt—filecommand outputpefile.txt— pefile Python library full PE dump (7.5 MB)exiftool.json— ExifTool metadatastrings.txt—strings -a -n 6output (275 KB)rabin2-info.txt— radare2rabin2 -Iheader summarytriage.json— triage pipeline metadatametadata.json— OpenCTI connector metadatabinwalk.txt— binwalk entropy signaturescapa.txt— capa error log (signatures missing)dynamic-analysis.md— CAPE skipped (no Windows guest)- Radare2 live analysis (level 2, 10,420 functions) — import table, string search, entry-point decompilation
Tools: radare2 5.9.x, pefile 2023.x, ExifTool 12.76, binwalk 2.x, capa 7.x (signature path error).
This sample is catalogued under the silverfox family slug for indexing purposes only. The analysis contests that attribution. Treat as benign / false positive.