familyphorpiexconfidencehighcreated2026-07-28malware-familyloadermalware-bazaarattributionc2-protocolpersistencedefense-evasionmitre-attck
SHA-256: 9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f

phorpiex: 9570038453 — business-app masquerade downloader with geolocation gating

Executive Summary: MSVC C++ PE32 downloader compiled 26 May 2026, part of the active Phorpiex campaign. Fetches payloads from 178.16.54.109 over cleartext HTTP, gates execution on a %TEMP% marker file and on the victim country (excludes CN), and stages the downloaded payload under the name of a legitimate business app (Slack, Teams, Zoom, SAP GUI, Power BI Desktop, Tableau). Shares C2 infrastructure, toolchain, and behavioral chain with the May 2026 Phorpiex thin-downloader cluster.

What It Is

Field Value
SHA-256 9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f
File type PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
Size 113,152 bytes
Linker MSVC 14.x (MajorLinkerVersion 9.0) ^[pefile.txt:45]
Compiled 2026-05-26 07:35:20 UTC ^[pefile.txt:34]
ASLR / NX Yes (DllCharacteristics 0x8140) ^[pefile.txt:67]
Signed No ^[rabin2-info.txt:27]
Stripped No ^[rabin2-info.txt:30]
Packed No ^[binwalk.txt]

C++ binary with heavy STL surface: std::string, std::locale, std::iostream, std::ios_base, std::ostream, and Dinkumware CRT strings ("Copyright (c) 1992-2004 by P.J. Plauger...") ^[strings.txt:400] ^[binwalk.txt:5]. Rich header present (oRich). ASLR and NX compatible. No packing, no obfuscation, no anti-debug beyond timing.

How It Works

Entry-point flow (decompiled)

main() at 0x004016a0 follows this sequence ^[r2:main]:

  1. Sleep(2000) — 2-second pre-execution delay.
  2. GetTickCount() + fcn.00405baa() — seeds an internal PRNG using the tick count ^[r2:fcn.00405baa].
  3. fcn.004010b0() — marker-file gate. Checks for %TEMP%\w4f4wffwf.txt via PathFileExistsW. If the file already exists, the binary returns 0 and exits immediately (single-instance / rerun prevention). If absent, it creates the file and proceeds ^[r2:fcn.004010b0].
  4. If the marker was newly created, fetches http://ip-api.com/json/ via InternetOpenW / InternetOpenUrlW / InternetReadFile ^[strings.txt:70] ^[r2:main].
  5. Parses the JSON response for countryCode ^[strings.txt:72].
  6. Compares the extracted country code to "CN" (China) ^[strings.txt:76] ^[r2:main].
  7. If the country is not CN, it selects a payload URL from an array of hardcoded strings (lb1.exe through lb10.exe on 178.16.54.109) using a PRNG-derived index, then calls fcn.00401150(url) to download and execute ^[r2:main].

Download-and-execute routine

fcn.00401150 at 0x00401150 ^[r2:fcn.00401150]:

  1. Calls ExpandEnvironmentStringsW(L"%temp%") to resolve the staging directory.
  2. Generates a random temp filename %s\%d%d.exe where %d%d are two PRNG values (rand % 0x7FFF + 0x3E8, giving numbers in the ~1000–34000 range).
  3. Opens a WinInet session with a hardcoded fake Chrome User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ... Chrome/7775543322.0.0.0 Safari/537.36 ^[strings.txt:67-ish] ^[r2:fcn.00401150].
  4. Fetches the payload via InternetOpenUrlW → InternetReadFile loop.
  5. Writes the payload to disk via CreateFileW → WriteFile → CloseHandle.
  6. Deletes the Zone.Identifier ADS (%s:Zone.Identifier) via DeleteFileW to strip the "Downloaded from Internet" mark ^[r2:fcn.00401150].
  7. Executes the downloaded file via an indirect call to ShellExecuteW (stored function pointer).

Masquerade names

The binary contains six hardcoded legitimate application names that the downloaded payload is written as:

  • slack.exe ^[strings.txt:51]
  • Teams.exe ^[strings.txt:52]
  • Zoom.exe ^[strings.txt:53]
  • sapgui.exe ^[strings.txt:54]
  • PBIDesktop.exe ^[strings.txt:55]
  • tableau.exe ^[strings.txt:56]

These names are passed to ShellExecuteW as the lpFile parameter, causing the downloaded malware to run under a trusted, enterprise-familiar process name in Task Manager and EDR telemetry.

C2 Infrastructure

Type Value
Primary C2 IP 178.16.54.109 (cleartext HTTP) ^[strings.txt:50]
Payload array http://178.16.54.109/lb1.exe – lb10.exe ^[strings.txt:57–66]
Additional payload http://178.16.54.109/lkdomain.exe ^[strings.txt:50]
Geolocation API http://ip-api.com/json/ ^[strings.txt:70]
UA string Fake Chrome/7775543322.0.0.0
Marker file %TEMP%\w4f4wffwf.txt ^[r2:fcn.004010b0]

Decompiled Behavior

The binary has a straightforward honest-main() flow (no initterm hijack). Key functions:

  • main (0x004016a0) — Orchestrates the Sleep → PRNG seed → marker gate → geolocation → country check → payload fetch chain. Returns immediately if the marker file exists or if the country code is CN ^[r2:main].
  • fcn.004010b0 — Marker-file mutex gate. Creates %TEMP%\w4f4wffwf.txt if absent; returns 0 (abort) if already present ^[r2:fcn.004010b0].
  • fcn.00401150 — WinInet downloader + stager. Expands %temp%, generates random %d%d.exe filename, fetches over HTTP, writes to disk, strips Zone.Identifier ADS, and executes via ShellExecuteW ^[r2:fcn.00401150].
  • fcn.00405baa — PRNG seed function. Stores the GetTickCount value into an internal state structure ^[r2:fcn.00405baa].
  • fcn.00401340 — Array-length walker. Used to select a random index into the payload URL array ^[r2:fcn.00401340].

No process injection, no reflective loading, no API hashing observed in this sample. The threat logic is entirely in the outer PE.

Interesting Tidbits

  • Absurd Chrome version: The User-Agent hardcodes Chrome/7775543322.0.0.0 — a clear anti-forensics / fingerprinting choice, also observed in earlier Phorpiex thin downloaders. This version number is impossible and trivial to hunt on.
  • CN exclusion: The ip-api.com check with explicit "CN" skip suggests the operator wants to avoid infecting Chinese systems, a common crimeware OPSEC pattern to reduce law-enforcement attention or to avoid hitting sandboxes hosted in CN.
  • Business-app masquerade: Unlike prior Phorpiex downloaders that used generic names (xmr.exe, xmrget.exe, peinf.exe, grab.exe, 15.exe), this variant stages payloads as well-known enterprise applications. This is a T1036.005 (Match Legitimate Name or Location) upgrade specifically targeting corporate endpoints where Slack, Teams, Zoom, SAP, Power BI, and Tableau are expected processes.
  • No URLMon fallback: Earlier thin-downloader siblings (6b8527a7, 025f5798, 2ffc3203, 32f29422, f67e429d) used a dual WinInet + URLMon fetch path. This sample appears WinInet-only, though URLMon may still be delay-loaded or the decompile is incomplete.
  • Larger than thin-downloaders: At 113 KB this is ~10× larger than the 10 KB thin-downloader stubs in the same campaign. The extra size is C++ STL bloat (locale tables, iostream vtables, Dinkumware strings) and the string URL array.

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2019/2022, C++ Console/Win32 project, x86 target.

Key ingredients:

  1. WinInet imports: InternetOpenW, InternetOpenUrlW, InternetReadFile, InternetCloseHandle.
  2. ShellExecuteW from SHELL32.dll (or CreateProcessW from KERNEL32.dll).
  3. PathFileExistsW from SHLWAPI.dll for the marker gate.
  4. ExpandEnvironmentStringsW, CreateFileW, WriteFile, DeleteFileW for staging.
  5. Sleep(2000) + GetTickCount() for the timing/PRNG seed.
  6. A JSON parser (or manual strstr for "countryCode") for the geolocation gate.
  7. A hardcoded UA string with an absurd Chrome version.

Verification: Compile a minimal reproducer that fetches a test URL, writes it to %TEMP%\<rand>.exe, deletes Zone.Identifier, and executes it. Run capa reproducer.exe — should hit communication/http/client, host-interaction/file-system/files/write, host-interaction/process/create, and host-interaction/file-system/ads/delete. Compare against this sample's expected capa fingerprint (capa signatures were unavailable during triage but the behavioral fingerprint is predictable).

Deployable Signatures

YARA rule

rule phorpiex_business_app_masquerade_downloader {
    meta:
        description = "Phorpiex campaign downloader with business-app masquerade and ip-api gating"
        author = "PacketPursuit"
        date = "2026-07-28"
        sha256 = "9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f"
    strings:
        $c2 = "http://178.16.54.109/" ascii wide
        $ua = "Chrome/7775543322.0.0.0" ascii wide
        $geo = "http://ip-api.com/json/" ascii wide
        $cc = "countryCode" ascii wide
        $cn = "CN" ascii wide
        $marker = "w4f4wffwf.txt" ascii wide
        $slack = "slack.exe" ascii wide
        $teams = "Teams.exe" ascii wide
        $zoom = "Zoom.exe" ascii wide
        $sap = "sapgui.exe" ascii wide
        $pbi = "PBIDesktop.exe" ascii wide
        $tableau = "tableau.exe" ascii wide
        $zone = ":Zone.Identifier" ascii wide
        $dll_wininet = "WININET.dll" ascii
    condition:
        uint16(0) == 0x5A4D and
        $dll_wininet and
        $c2 and
        ($ua or $geo or $marker) and
        (2 of ($slack, $teams, $zoom, $sap, $pbi, $tableau))
}

Behavioral hunt query (Sigma-like pseudocode)

Target: Process creation events where a parent process writes to %TEMP%\[0-9]{4,5}[0-9]{4,5}.exe and then executes it with a masquerade name.

title: Phorpiex Business-App Masquerade Downloader
logsource:
  product: windows
  category: process_creation
detection:
  selection_exec:
    CommandLine|endswith:
      - 'slack.exe'
      - 'Teams.exe'
      - 'Zoom.exe'
      - 'sapgui.exe'
      - 'PBIDesktop.exe'
      - 'tableau.exe'
    Image|contains: '\Temp\'
    Image|re: '\Temp\\d{4,5}\d{4,5}\.exe$'
  selection_parent:
    ParentImage|endswith:
      - '.exe'
  selection_network:
    Initiated: 'true'
    DestinationIp: '178.16.54.109'
  condition: selection_exec and selection_parent and selection_network
falsepositives:
  - Unknown
level: high

IOC list

Indicator Type Value
SHA-256 Hash 9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f
C2 IP IPv4 178.16.54.109
Payload URLs URL http://178.16.54.109/lkdomain.exe, http://178.16.54.109/lb1.exe – lb10.exe
Geolocation API URL http://ip-api.com/json/
Marker file File path %TEMP%\w4f4wffwf.txt
Staging pattern File path %TEMP%\<4-5 digits><4-5 digits>.exe
Masquerade names File name slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe
UA fingerprint String Chrome/7775543322.0.0.0

Behavioral fingerprint statement

This binary is a WinInet-based HTTP downloader that gates execution on a %TEMP%\w4f4wffwf.txt marker file and on the victim's country code (excludes CN). It fetches a payload from 178.16.54.109 over cleartext HTTP using a fake Chrome User-Agent with version 7775543322.0.0.0, writes the payload to %TEMP% under a random numeric filename %d%d.exe, strips the Zone.Identifier ADS, and executes the payload masquerading as a legitimate enterprise application (Slack, Teams, Zoom, SAP GUI, Power BI Desktop, or Tableau). The PRNG is seeded from GetTickCount() after a 2-second Sleep.

Detection Signatures

Technique ATT&CK ID Evidence
Ingress Tool Transfer T1105 Downloads lb*.exe / lkdomain.exe from 178.16.54.109 via WinInet ^[strings.txt:50–66] ^[r2:fcn.00401150]
Match Legitimate Name or Location T1036.005 Hardcoded masquerade names: slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe ^[strings.txt:51–56]
Virtualization/Sandbox Evasion: System Checks T1497.001 ip-api.com/json geolocation + CN exclusion ^[strings.txt:70–76] ^[r2:main]
Indicator Removal: File Deletion T1070.004 DeleteFileW(L"%s:Zone.Identifier") ^[r2:fcn.00401150]
Native API T1106 WinInet InternetOpenUrlW / InternetReadFile, ShellExecuteW, CreateFileW ^[pefile.txt:239–361]
User Execution: Malicious File T1204.002 Social-engineering delivery (implied by OpenCTI dropped-by-phorpiex label) ^[metadata.json]
Application Layer Protocol: Web Protocols T1071.001 Cleartext HTTP C2 to 178.16.54.109 ^[strings.txt:50–66]

References

Provenance

Analysis derived from:

  • file.txt, pefile.txt, rabin2-info.txt, exiftool.json — build metadata
  • strings.txt — static string surface (line numbers cited)
  • binwalk.txt — packing / embedded artefact scan
  • dynamic-analysis.md — CAPE skipped (no Windows guest available); all behavior inferred from static RE
  • Radare2 decompilation of main, fcn.00401150, fcn.004010b0, fcn.00405baa, fcn.00401340 — control-flow and API call evidence