9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51fphorpiex: 9570038453 — business-app masquerade downloader with geolocation gating
Executive Summary: MSVC C++ PE32 downloader compiled 26 May 2026, part of the active Phorpiex campaign. Fetches payloads from 178.16.54.109 over cleartext HTTP, gates execution on a %TEMP% marker file and on the victim country (excludes CN), and stages the downloaded payload under the name of a legitimate business app (Slack, Teams, Zoom, SAP GUI, Power BI Desktop, Tableau). Shares C2 infrastructure, toolchain, and behavioral chain with the May 2026 Phorpiex thin-downloader cluster.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f |
| File type | PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt] |
| Size | 113,152 bytes |
| Linker | MSVC 14.x (MajorLinkerVersion 9.0) ^[pefile.txt:45] |
| Compiled | 2026-05-26 07:35:20 UTC ^[pefile.txt:34] |
| ASLR / NX | Yes (DllCharacteristics 0x8140) ^[pefile.txt:67] |
| Signed | No ^[rabin2-info.txt:27] |
| Stripped | No ^[rabin2-info.txt:30] |
| Packed | No ^[binwalk.txt] |
C++ binary with heavy STL surface: std::string, std::locale, std::iostream, std::ios_base, std::ostream, and Dinkumware CRT strings ("Copyright (c) 1992-2004 by P.J. Plauger...") ^[strings.txt:400] ^[binwalk.txt:5]. Rich header present (oRich). ASLR and NX compatible. No packing, no obfuscation, no anti-debug beyond timing.
How It Works
Entry-point flow (decompiled)
main() at 0x004016a0 follows this sequence ^[r2:main]:
Sleep(2000)— 2-second pre-execution delay.GetTickCount()+fcn.00405baa()— seeds an internal PRNG using the tick count ^[r2:fcn.00405baa].fcn.004010b0()— marker-file gate. Checks for%TEMP%\w4f4wffwf.txtviaPathFileExistsW. If the file already exists, the binary returns 0 and exits immediately (single-instance / rerun prevention). If absent, it creates the file and proceeds ^[r2:fcn.004010b0].- If the marker was newly created, fetches
http://ip-api.com/json/viaInternetOpenW/InternetOpenUrlW/InternetReadFile^[strings.txt:70] ^[r2:main]. - Parses the JSON response for
countryCode^[strings.txt:72]. - Compares the extracted country code to
"CN"(China) ^[strings.txt:76] ^[r2:main]. - If the country is not CN, it selects a payload URL from an array of hardcoded strings (
lb1.exethroughlb10.exeon178.16.54.109) using a PRNG-derived index, then callsfcn.00401150(url)to download and execute ^[r2:main].
Download-and-execute routine
fcn.00401150 at 0x00401150 ^[r2:fcn.00401150]:
- Calls
ExpandEnvironmentStringsW(L"%temp%")to resolve the staging directory. - Generates a random temp filename
%s\%d%d.exewhere%d%dare two PRNG values (rand % 0x7FFF + 0x3E8, giving numbers in the ~1000–34000 range). - Opens a WinInet session with a hardcoded fake Chrome User-Agent:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ... Chrome/7775543322.0.0.0 Safari/537.36^[strings.txt:67-ish] ^[r2:fcn.00401150]. - Fetches the payload via
InternetOpenUrlW→InternetReadFileloop. - Writes the payload to disk via
CreateFileW→WriteFile→CloseHandle. - Deletes the
Zone.IdentifierADS (%s:Zone.Identifier) viaDeleteFileWto strip the "Downloaded from Internet" mark ^[r2:fcn.00401150]. - Executes the downloaded file via an indirect call to
ShellExecuteW(stored function pointer).
Masquerade names
The binary contains six hardcoded legitimate application names that the downloaded payload is written as:
slack.exe^[strings.txt:51]Teams.exe^[strings.txt:52]Zoom.exe^[strings.txt:53]sapgui.exe^[strings.txt:54]PBIDesktop.exe^[strings.txt:55]tableau.exe^[strings.txt:56]
These names are passed to ShellExecuteW as the lpFile parameter, causing the downloaded malware to run under a trusted, enterprise-familiar process name in Task Manager and EDR telemetry.
C2 Infrastructure
| Type | Value |
|---|---|
| Primary C2 IP | 178.16.54.109 (cleartext HTTP) ^[strings.txt:50] |
| Payload array | http://178.16.54.109/lb1.exe – lb10.exe ^[strings.txt:57–66] |
| Additional payload | http://178.16.54.109/lkdomain.exe ^[strings.txt:50] |
| Geolocation API | http://ip-api.com/json/ ^[strings.txt:70] |
| UA string | Fake Chrome/7775543322.0.0.0 |
| Marker file | %TEMP%\w4f4wffwf.txt ^[r2:fcn.004010b0] |
Decompiled Behavior
The binary has a straightforward honest-main() flow (no initterm hijack). Key functions:
main(0x004016a0) — Orchestrates the Sleep → PRNG seed → marker gate → geolocation → country check → payload fetch chain. Returns immediately if the marker file exists or if the country code is CN ^[r2:main].fcn.004010b0— Marker-file mutex gate. Creates%TEMP%\w4f4wffwf.txtif absent; returns 0 (abort) if already present ^[r2:fcn.004010b0].fcn.00401150— WinInet downloader + stager. Expands%temp%, generates random%d%d.exefilename, fetches over HTTP, writes to disk, strips Zone.Identifier ADS, and executes via ShellExecuteW ^[r2:fcn.00401150].fcn.00405baa— PRNG seed function. Stores theGetTickCountvalue into an internal state structure ^[r2:fcn.00405baa].fcn.00401340— Array-length walker. Used to select a random index into the payload URL array ^[r2:fcn.00401340].
No process injection, no reflective loading, no API hashing observed in this sample. The threat logic is entirely in the outer PE.
Interesting Tidbits
- Absurd Chrome version: The User-Agent hardcodes
Chrome/7775543322.0.0.0— a clear anti-forensics / fingerprinting choice, also observed in earlier Phorpiex thin downloaders. This version number is impossible and trivial to hunt on. - CN exclusion: The
ip-api.comcheck with explicit "CN" skip suggests the operator wants to avoid infecting Chinese systems, a common crimeware OPSEC pattern to reduce law-enforcement attention or to avoid hitting sandboxes hosted in CN. - Business-app masquerade: Unlike prior Phorpiex downloaders that used generic names (
xmr.exe,xmrget.exe,peinf.exe,grab.exe,15.exe), this variant stages payloads as well-known enterprise applications. This is a T1036.005 (Match Legitimate Name or Location) upgrade specifically targeting corporate endpoints where Slack, Teams, Zoom, SAP, Power BI, and Tableau are expected processes. - No URLMon fallback: Earlier thin-downloader siblings (
6b8527a7,025f5798,2ffc3203,32f29422,f67e429d) used a dual WinInet + URLMon fetch path. This sample appears WinInet-only, though URLMon may still be delay-loaded or the decompile is incomplete. - Larger than thin-downloaders: At 113 KB this is ~10× larger than the 10 KB thin-downloader stubs in the same campaign. The extra size is C++ STL bloat (locale tables, iostream vtables, Dinkumware strings) and the string URL array.
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2019/2022, C++ Console/Win32 project, x86 target.
Key ingredients:
WinInetimports:InternetOpenW,InternetOpenUrlW,InternetReadFile,InternetCloseHandle.ShellExecuteWfromSHELL32.dll(orCreateProcessWfromKERNEL32.dll).PathFileExistsWfromSHLWAPI.dllfor the marker gate.ExpandEnvironmentStringsW,CreateFileW,WriteFile,DeleteFileWfor staging.Sleep(2000)+GetTickCount()for the timing/PRNG seed.- A JSON parser (or manual
strstrfor"countryCode") for the geolocation gate. - A hardcoded UA string with an absurd Chrome version.
Verification: Compile a minimal reproducer that fetches a test URL, writes it to %TEMP%\<rand>.exe, deletes Zone.Identifier, and executes it. Run capa reproducer.exe — should hit communication/http/client, host-interaction/file-system/files/write, host-interaction/process/create, and host-interaction/file-system/ads/delete. Compare against this sample's expected capa fingerprint (capa signatures were unavailable during triage but the behavioral fingerprint is predictable).
Deployable Signatures
YARA rule
rule phorpiex_business_app_masquerade_downloader {
meta:
description = "Phorpiex campaign downloader with business-app masquerade and ip-api gating"
author = "PacketPursuit"
date = "2026-07-28"
sha256 = "9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f"
strings:
$c2 = "http://178.16.54.109/" ascii wide
$ua = "Chrome/7775543322.0.0.0" ascii wide
$geo = "http://ip-api.com/json/" ascii wide
$cc = "countryCode" ascii wide
$cn = "CN" ascii wide
$marker = "w4f4wffwf.txt" ascii wide
$slack = "slack.exe" ascii wide
$teams = "Teams.exe" ascii wide
$zoom = "Zoom.exe" ascii wide
$sap = "sapgui.exe" ascii wide
$pbi = "PBIDesktop.exe" ascii wide
$tableau = "tableau.exe" ascii wide
$zone = ":Zone.Identifier" ascii wide
$dll_wininet = "WININET.dll" ascii
condition:
uint16(0) == 0x5A4D and
$dll_wininet and
$c2 and
($ua or $geo or $marker) and
(2 of ($slack, $teams, $zoom, $sap, $pbi, $tableau))
}
Behavioral hunt query (Sigma-like pseudocode)
Target: Process creation events where a parent process writes to %TEMP%\[0-9]{4,5}[0-9]{4,5}.exe and then executes it with a masquerade name.
title: Phorpiex Business-App Masquerade Downloader
logsource:
product: windows
category: process_creation
detection:
selection_exec:
CommandLine|endswith:
- 'slack.exe'
- 'Teams.exe'
- 'Zoom.exe'
- 'sapgui.exe'
- 'PBIDesktop.exe'
- 'tableau.exe'
Image|contains: '\Temp\'
Image|re: '\Temp\\d{4,5}\d{4,5}\.exe$'
selection_parent:
ParentImage|endswith:
- '.exe'
selection_network:
Initiated: 'true'
DestinationIp: '178.16.54.109'
condition: selection_exec and selection_parent and selection_network
falsepositives:
- Unknown
level: high
IOC list
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | Hash | 9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f |
| C2 IP | IPv4 | 178.16.54.109 |
| Payload URLs | URL | http://178.16.54.109/lkdomain.exe, http://178.16.54.109/lb1.exe – lb10.exe |
| Geolocation API | URL | http://ip-api.com/json/ |
| Marker file | File path | %TEMP%\w4f4wffwf.txt |
| Staging pattern | File path | %TEMP%\<4-5 digits><4-5 digits>.exe |
| Masquerade names | File name | slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe |
| UA fingerprint | String | Chrome/7775543322.0.0.0 |
Behavioral fingerprint statement
This binary is a WinInet-based HTTP downloader that gates execution on a %TEMP%\w4f4wffwf.txt marker file and on the victim's country code (excludes CN). It fetches a payload from 178.16.54.109 over cleartext HTTP using a fake Chrome User-Agent with version 7775543322.0.0.0, writes the payload to %TEMP% under a random numeric filename %d%d.exe, strips the Zone.Identifier ADS, and executes the payload masquerading as a legitimate enterprise application (Slack, Teams, Zoom, SAP GUI, Power BI Desktop, or Tableau). The PRNG is seeded from GetTickCount() after a 2-second Sleep.
Detection Signatures
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Ingress Tool Transfer | T1105 | Downloads lb*.exe / lkdomain.exe from 178.16.54.109 via WinInet ^[strings.txt:50–66] ^[r2:fcn.00401150] |
| Match Legitimate Name or Location | T1036.005 | Hardcoded masquerade names: slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe ^[strings.txt:51–56] |
| Virtualization/Sandbox Evasion: System Checks | T1497.001 | ip-api.com/json geolocation + CN exclusion ^[strings.txt:70–76] ^[r2:main] |
| Indicator Removal: File Deletion | T1070.004 | DeleteFileW(L"%s:Zone.Identifier") ^[r2:fcn.00401150] |
| Native API | T1106 | WinInet InternetOpenUrlW / InternetReadFile, ShellExecuteW, CreateFileW ^[pefile.txt:239–361] |
| User Execution: Malicious File | T1204.002 | Social-engineering delivery (implied by OpenCTI dropped-by-phorpiex label) ^[metadata.json] |
| Application Layer Protocol: Web Protocols | T1071.001 | Cleartext HTTP C2 to 178.16.54.109 ^[strings.txt:50–66] |
References
- OpenCTI artifact:
67f4cecc-d93d-4b40-9f4c-f52f6b67979a^[metadata.json] - Source: MalwareBazaar (tagged
dropped-by-phorpiex) ^[metadata.json] - Related wiki: phorpiex — shared campaign analysis and sibling cluster
- Related techniques: marker-file-mutex-gating, zone-identifier-deletion, gettickcount-anti-emulation-loop, rtlgversion-build-gating
Provenance
Analysis derived from:
file.txt,pefile.txt,rabin2-info.txt,exiftool.json— build metadatastrings.txt— static string surface (line numbers cited)binwalk.txt— packing / embedded artefact scandynamic-analysis.md— CAPE skipped (no Windows guest available); all behavior inferred from static RE- Radare2 decompilation of
main,fcn.00401150,fcn.004010b0,fcn.00405baa,fcn.00401340— control-flow and API call evidence