typeanalysisfamilysilverfoxconfidencelowcreated2026-08-08updated2026-08-08pecompilermalware-familyloaderdefense-evasionevasion
SHA-256: 7dc5d926d6f83fa5b23ac8024e87f6552364053a55ba7704f0811fb203223350

silverfox: 7dc5d926 — FALSE POSITIVE: NetEase game launcher mislabeled by OpenCTI

Executive Summary

This sample is a legitimate NetEase game launcher (Fantasy Westward Journey: Space-Time / 梦幻西游:时空, v1.415.0.0) mislabeled silverfox and valleyrat by OpenCTI. The binary is an MSVC 2019 C/C++ PE32+ x64 compiled from a real Jenkins CI pipeline (rel_engine_branch3), bundles OpenSSL and libcurl, and contacts NetEase CDN endpoints. Zero SilverFox fingerprints are present. The social-engineering filename (点击切换简体中文语言包.exe — "Click to switch Simplified Chinese language pack") is the only malicious thing about it.

What It Is

Attribute Detail
SHA-256 7dc5d926d6f83fa5b23ac8024e87f6552364053a55ba7704f0811fb203223350
File type PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
Size 3,613,632 bytes (3.6 MB) ^[triage.json]
Timestamp Mon Apr 7 11:36:10 2025 UTC ^[pefile.txt:172]
Linker MSVC 14.29 (Visual Studio 2019) ^[exiftool.json:18]
Language C/C++ (rabin2 lang: c) ^[rabin2-info.txt:19]
Stripped No — full PDB reference present ^[rabin2-info.txt:32]
PDB path D:\Jenkins\work\workspace\rel_engine_branch3\Engine\Binaries\Win64\MyLauncher_x64r.pdb ^[rabin2-info.txt:13]
Signed signed: true per rabin2, but security-directory raw data does not parse as valid DER PKCS#7 ^[rabin2-info.txt:29] ^[pefile.txt:370-371]
Filename (source) 点击切换简体中文语言包.exe (Simplified Chinese language-pack lure) ^[triage.json:5]

Version Information (VS_VERSIONINFO)

  • CompanyName: Netease
  • FileDescription: 梦幻西游:时空 (Fantasy Westward Journey: Space-Time) ^[pefile.txt:439-440]
  • FileVersion: 1.415.0.0
  • InternalName: MyLauncher.rc
  • OriginalFilename: MyLauncher.exe
  • ProductName: MyLauncher ^[pefile.txt:441-445]
  • LegalCopyright: Copyright (c)2023 Netease, inc. ^[pefile.txt:443]

Why It Is NOT SilverFox

Absent: SilverFox stream-cipher constants

The C-variant SilverFox stub (82d42551) embeds four fixed 32-bit constants (0xcaaafe23, 0x3d57aa23, 0x44d9bb23, 0x9e37cb23) used in its custom stream cipher ^[entities/silverfox.md]. A full byte-level search across the entire binary returns zero matches for any of these values. ^[strings.txt] ^[r2:strings-search]

Absent: LZSS payload decompressor

SilverFox variants embed an in-memory LZSS decompressor (typically at FUN_140004000 in the C x64 builds) ^[entities/silverfox.md]. No LZSS window table, bit-stream parser, or sliding-window copy routine is observed in the disassembly. The .rsrc section is 12,544 bytes of standard Windows icon/manifest data (entropy 7.63 — normal for compressed PNGs), not an encrypted payload blob.

Absent: XOR-thunk API dispatch

The 50K C stub (82d42551) indirects every API call through a single XOR-decrypt thunk with >222 call sites ^[entities/silverfox.md]. The import table here is a standard MSVC IAT with 215 imports from KERNEL32, USER32, SHELL32, WS2_32, WLDAP32, ADVAPI32, and bcrypt ^[pefile.txt:461+] — no thunk obfuscation, no FNV-1a hash resolver, no PEB-walking.

Absent: Process hollowing / injection APIs

SilverFox uses NtAllocateVirtualMemory, NtWriteVirtualMemory, and CreateProcessW with CREATE_SUSPENDED for process hollowing ^[entities/silverfox.md]. This binary imports CreateProcessW and OpenProcess (standard launcher APIs) but has no NtAllocateVirtualMemory, NtWriteVirtualMemory, NtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory, or CreateRemoteThread imports. ^[pefile.txt:461-537]

Absent: Anti-analysis / evasion

No debugger checks, no VM detection, no sandbox gates, no IsDebuggerPresent loops, no Sleep obfuscation, no GetTickCount timing gates. The entry point is a straightforward MSVC CRT initialisation followed by WinMain.

Present: Legitimate game-launcher artefacts

  • 334 distinct Jenkins build-path strings referencing rel_engine_branch3 ^[strings.txt]
  • OpenSSL source paths (D:\Jenkins\work\workspace\rel_engine_branch3\Engine\Sources\External\openssl\...) for 50+ crypto files ^[strings.txt]
  • NetEase CDN endpoints: g18.gph.netease.com, g18.gdl.netease.com, g18.gsf.netease.com ^[strings.txt:5209-5213]
  • Game patch-update logic: PatchUpdate::find pc launcher files need to copy, http://update.my.163.com/my_patchlist_win32 ^[strings.txt:5217-5225]
  • libcurl error strings (Couldn't connect to server, SSL connect error, Connection timed out) ^[strings.txt]

Build / RE Lens

Toolchain

  • Compiler: MSVC 2019 (Utc1900_C v30146 × 576 objects, Utc1900_CPP v30034 × 279 objects, Masm1400 v30034 × 10 objects) ^[rabin2-info.txt:Rich Header]
  • Linker: MSVC 14.29 (Linker1400 v30146) ^[rabin2-info.txt]
  • Build system: Jenkins CI on Windows (D:\Jenkins\work\workspace\rel_engine_branch3) ^[rabin2-info.txt:13]
  • Crypto library: OpenSSL (static-linked, embedded source paths confirm) ^[strings.txt]
  • Networking: libcurl + WS2_32 (Winsock) ^[pefile.txt:461+]

Sections (standard MSVC)

Section Size Entropy Notes
.text 2,514,240 6.41 Normal code entropy
.rdata 894,230 5.80 Import table + read-only data
.data 52,048 3.40 Mutable data (low entropy = normal)
.pdata 121,552 6.33 Exception/unwind info
_RDATA 244 2.46 Small read-only block (TLS-related)
.rsrc 12,544 7.63 Icons + manifest (PNG compression)
.reloc 29,408 5.44 Base relocation table

No RWX sections, no null-named sections, no encrypted overlays, no packed stubs. ^[pefile.txt:213-353]

Signing anomaly

The IMAGE_DIRECTORY_ENTRY_SECURITY points to 10,688 bytes at file offset 0x36FA00, but the raw bytes do not begin with a valid DER ASN.1 sequence tag (0x30). The first byte is 0xC0 — this is either a corrupted/fabricated signature block or non-standard Authenticode wrapping. The binary reports signed: true in rabin2, yet the signature is not cryptographically verifiable. This is the one suspicious feature, but it is insufficient to override the overwhelming benign evidence. ^[rabin2-info.txt:29] ^[pefile.txt:370-371]

Deploy / ATT&CK Lens

Not applicable. This binary exhibits no malicious TTPs. The only threat vector is the social-engineering filename — a technique already documented at social-engineering-filename-lure — which tricks the victim into executing a legitimate program under a false pretense.

If an attacker were distributing this binary, the chain would be:

  • T1204.002 (User Execution: Malicious File) — victim double-clicks the .exe believing it is a language-pack installer.
  • T1036.005 (Masquerading: Match Legitimate Name or Location) — filename mimics a system utility.

The binary itself is not the payload; the payload is the trust transfer from a real, signed-looking executable to a social-engineering campaign.

Interesting Tidbits

  • Jenkins bloat as provenance: The 334 Jenkins/OpenSSL path strings are an unintentional but powerful benign-fingerprint. No malware author embeds 50+ OpenSSL source file paths into a stub.
  • NetEase CDN as C2 false positive: Analysts hunting for netease.com network IOCs would flag the three g18.*.netease.com endpoints. These are legitimate game-patch CDN hosts.
  • PDB path as origin marker: rel_engine_branch3 suggests this is a release-engineering branch build, not a debug or test build. The _x64r suffix likely means "x64 Release".
  • Rich Header is clean: The Rich Header shows only Microsoft toolchain products (Utc1900_C, Utc1900_CPP, Masm1400, Linker1400, Cvtres1400, Implib1400) with version numbers consistent with Visual Studio 2019. No third-party packer/crypter products. ^[rabin2-info.txt]

How To Mess With It (Homelab Replication)

This is a negative-control exercise — learn to distinguish false positives from real threats.

  1. Verify the PDB path: Run rabin2 -P /path/to/sample | grep dbg_file. A real Jenkins path with Engine/Binaries/Win64 strongly suggests a Unreal Engine-derived game launcher (NetEase uses UE for Fantasy Westward Journey).
  2. Check for SilverFox constants: python3 -c "import sys; data=open(sys.argv[1],'rb').read(); print(any(c in data.hex() for c in ['caaafe23','3d57aa23','44d9bb23','9e37cb23']))" sample.bin — should return False for this sample.
  3. Inspect .rsrc entropy: Use pefile to dump section entropies. A .rsrc of ~12 KB with entropy ~7.6 is normal (PNG icons). A .rsrc of 50K+ with entropy 7.9+ is suspicious for an encrypted payload.
  4. Read VersionInfo in Chinese: The FileDescription field contains Chinese characters. If you don't read Chinese, pipe through exiftool -b or a hex viewer — don't assume it's random noise.

Deployable Signatures

YARA — SilverFox false-positive exclusion

Use this rule to filter out NetEase launcher noise when hunting for SilverFox. It targets the benign fingerprint, not the threat.

rule silverfox_false_positive_netease_launcher
{
    meta:
        description = "Excludes NetEase MyLauncher binaries from SilverFox hunts"
        author = "Titus"
        date = "2026-08-08"
        hash = "7dc5d926d6f83fa5b23ac8024e87f6552364053a55ba7704f0811fb203223350"
    strings:
        $pdb = "MyLauncher_x64r.pdb" ascii wide
        $company = "Netease" ascii wide
        $product = "MyLauncher" ascii wide
        $cdn1 = "g18.gph.netease.com" ascii wide
        $cdn2 = "g18.gdl.netease.com" ascii wide
        $patch = "http://update.my.163.com/my_patchlist_win32" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections == 7 and
        3 of them
}

IOC List

Type Value Assessment
SHA-256 7dc5d926d6f83fa5b23ac8024e87f6552364053a55ba7704f0811fb203223350 Benign (false positive)
Filename 点击切换简体中文语言包.exe Social-engineering lure
PDB D:\Jenkins\work\workspace\rel_engine_branch3\Engine\Binaries\Win64\MyLauncher_x64r.pdb Benign build artefact
CDN g18.gph.netease.com Legitimate NetEase game patch CDN
CDN g18.gdl.netease.com Legitimate NetEase game patch CDN
CDN g18.gsf.netease.com Legitimate NetEase game patch CDN
Update URL http://update.my.163.com/my_patchlist_win32 Legitimate NetEase patch list

Behavioral Fingerprint

This binary is a 3.6 MB MSVC 2019 PE32+ x64 GUI executable with standard 7-section layout, a readable PDB path pointing to a Jenkins CI workspace for a NetEase game engine branch, and 300+ OpenSSL build-path strings. It imports KERNEL32, USER32, SHELL32, WS2_32, WLDAP32, ADVAPI32, and bcrypt via a standard IAT with 215 entries. It does not import NtAllocateVirtualMemory, NtWriteVirtualMemory, VirtualAllocEx, WriteProcessMemory, or CreateRemoteThread. No SilverFox stream-cipher constants, LZSS decompressor, or XOR-thunk dispatch are present. The .rsrc section contains standard Windows icons and manifest data. The security directory is present but does not contain a valid DER-encoded PKCS#7 signature.

Detection Signatures

No capa output available (signature path error during triage) ^[capa.txt]. A manual capability assessment shows zero ATT&CK-mappable malicious behaviours.

References

  • NetEase Fantasy Westward Journey: https://my.163.com (legitimate game portal)
  • OpenCTI labels: exe, malware-bazaar, shellcode, silverfox, valleyrat — all contested for this sample
  • Related wiki page: silverfox — actual SilverFox family entity (do not confuse with this false positive)
  • Related concept: social-engineering-filename-lure — the real threat here is the filename, not the binary

Provenance

Analysis based on:

  • file.txt — file command output
  • pefile.txt — pefile Python library full PE dump (7.5 MB)
  • exiftool.json — ExifTool metadata
  • strings.txt — strings -a -n 6 output (275 KB)
  • rabin2-info.txt — radare2 rabin2 -I header summary
  • triage.json — triage pipeline metadata
  • metadata.json — OpenCTI connector metadata
  • binwalk.txt — binwalk entropy signatures
  • capa.txt — capa error log (signatures missing)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • Radare2 live analysis (level 2, 10,420 functions) — import table, string search, entry-point decompilation

Tools: radare2 5.9.x, pefile 2023.x, ExifTool 12.76, binwalk 2.x, capa 7.x (signature path error).


This sample is catalogued under the silverfox family slug for indexing purposes only. The analysis contests that attribution. Treat as benign / false positive.