typeanalysisfamilyphorpiexconfidencemediummalware-familyloaderpeparasitic-infectorphorpiexruntime-api-resolutionregistry-evasionmsvc
SHA-256: e0de4e3c9dee9877c78832ac9ebe3fbd2de45026896d6fc2a5ca12f6b588a29a

phorpiex: e0de4e3c — TWIZTPEINF parasitic infector (byte-identical twin of d69d4497)

Executive Summary. This sample is a byte-identical twin of the Phorpiex parasitic infector d69d4497 — same binary, different OpenCTI artifact ID. It carries the dropped-by-phorpiex tag and the TWIZTPEINF infection marker. All static artifacts (section hashes, strings, imports, build fingerprint) match the sibling exactly. For full decompiled behavior, payload shellcode analysis, and deployable signatures, see the deep-dive report on d69d4497. ^[/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html]

What It Is

  • File: e0de4e3c9dee9877c78832ac9ebe3fbd2de45026896d6fc2a5ca12f6b588a29a.bin (22,528 bytes)
  • Type: PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
  • Toolchain: MSVC 9.0 (Visual Studio 2008), linker 9.0, MSVCR90.dll CRT ^[exiftool.json], ^[pefile.txt:44]
  • Timestamp: 2026-05-29 11:38:23 UTC (same build day as sibling d69d4497 at 11:32:30 UTC) ^[pefile.txt:34]
  • Family: Phorpiex (campaign umbrella)
  • Signing: Unsigned ^[pefile.txt:192]
  • Packing: None. Plain MSVC9 native code ^[pefile.txt:92]

Twin Verification

Check d69d4497 e0de4e3c Match
.text MD5 b50e5de817ef6e6aa6fb1f21c123658a b50e5de817ef6e6aa6fb1f21c123658a ✓
.rdata MD5 371ad74fd96153c1c566aecccf04c5a3 371ad74fd96153c1c566aecccf04c5a3 ✓
.data MD5 202a0f14ba4a024e6a35d5895669b769 202a0f14ba4a024e6a35d5895669b769 ✓
.rsrc MD5 58a3970c5ba6bee8bcaf23ee7343f378 58a3970c5ba6bee8bcaf23ee7343f378 ✓
.reloc MD5 460740661befd8c7613165ead3642d20 460740661befd8c7613165ead3642d20 ✓
strings.txt IDENTICAL IDENTICAL ✓
imports Same 5 DLLs, 53 imports Same 5 DLLs, 53 imports ✓
triage labels dropped-by-phorpiex, exe, malware-bazaar dropped-by-phorpiex, exe, malware-bazaar ✓

The only structural difference is the OpenCTI artifact ID and the SHA-256 itself, confirming this is the same binary ingested twice under distinct artifact records. ^[metadata.json], ^[triage.json]

Decompiled Behavior

Radare2 analysis (level 3, 73 functions) confirms the identical control-flow graph to d69d4497:

  • main @ 0x00401000 — sleeps 2 s, creates mutex TWIZTPEINF, checks GetLastError() == 0xB7 (ERROR_ALREADY_EXISTS), calls fcn.00402830 to create %appdata%\windrx.txt marker file, then spawns thread fcn.00403130 and sleeps ~36.2 h. ^[r2:main]
  • fcn.00402a70 — recursive directory walker with 21-name blacklist (windows, winsxs, cache, boot, microsoft, system, programdata, program files, appdata, application data, intel, default, config, perflogs, recovery, drivers, prefetch, recycle, extend, msocache, temp), case-insensitive via CharLowerW, matches *.exe via PathMatchSpecW. ^[r2:fcn.00402a70]
  • fcn.00402530 — PE infection engine. Memory-maps victim, validates MZ/PE, checks ImageBase != 0xdead (infection sentinel), appends .zero section, copies PI shellcode from fcn.004010f0 to fcn.00401ef0 (self-measured size), patches AddressOfEntryPoint, sets ImageBase = 0xdead, flushes, truncates. ^[r2:fcn.00402530]
  • fcn.004010f0 — payload shellcode. PEB-walking API hash resolution (fcn.00401bc0 with constants 0x526e0dcd, 0xc4b4a94d, 0x7a3a310, 0x165d9659, 0xeae447bb), loads urlmon.dll, resolves URLDownloadToFileW, downloads http://178.16.54.109/32.exe (stack-built URL), writes to %appdata%\windrx.txt, deletes Zone.Identifier ADS, then executes. ^[r2:fcn.004010f0]

For line-by-line decompilation of every function, hash constants, and sentinel-byte analysis, see the d69d4497 deep dive. ^[/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html]

C2 Infrastructure

Static C2 recovered from decompiled shellcode:

  • URL: http://178.16.54.109/32.exe ^[r2:fcn.004010f0]
  • Mutex: TWIZTPEINF ^[strings.txt:8]
  • Marker file: %appdata%\windrx.txt ^[strings.txt:10]
  • ADS deletion target: %s:Zone.Identifier ^[r2:fcn.004010f0]

Deploy / ATT&CK

  • T1027.002 — Obfuscated Files or Information: Software Packing — parasitic section append with 0xdead infection sentinel ^[r2:fcn.00402530]
  • T1055 — Process Injection — position-independent shellcode injected into victim PE via .zero section ^[r2:fcn.00402530]
  • T1497.001 — Virtualization/Sandbox Evasion: System Checks — NoDrives registry compliance to skip hidden drives ^[r2:fcn.004029b0]
  • T1564.001 — Hide Artifacts: Hidden Files and Directories — Zone.Identifier ADS deletion ^[r2:fcn.004010f0]
  • T1204.002 — User Execution: Malicious File — victim launches infected .exe
  • T1071.001 — Application Layer Protocol: Web Protocols — HTTP cleartext payload fetch ^[r2:fcn.004010f0]

Interesting Tidbits

  1. Duplicate artifact ID. OpenCTI assigned two distinct artifact records (dfd58feb... for d69d4497, 7c17f12e... for e0de4e3c) to the same 22,528-byte PE. This is a pipeline deduplication gap, not a variant. ^[metadata.json]
  2. Campaign timestamp clustering. Build time 2026-05-29 11:38:23 UTC falls 6 minutes after sibling d69d4497 (11:32:30 UTC) and on the same day as business-app masquerade downloader 0371fbbf (10:10:01 UTC). All three share the same C2 IP (178.16.54.109). This is a high-tempo build pipeline. ^[pefile.txt:34], ^[/intel/analyses/0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3.html]
  3. No network imports in host. The infector body imports zero networking APIs; all C2 logic lives inside the PI shellcode that gets appended to victims. Splits static detection surface between "clean" host and "dirty" payload. ^[pefile.txt:229]

Deployable Signatures

Reuse the YARA rules from the d69d4497 deep dive — they match this twin byte-for-byte. Key IOCs:

  • SHA-256: e0de4e3c9dee9877c78832ac9ebe3fbd2de45026896d6fc2a5ca12f6b588a29a
  • SHA-256 (twin): d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647
  • Mutex: TWIZTPEINF
  • Marker file: %appdata%\windrx.txt
  • C2 URL: http://178.16.54.109/32.exe
  • Infection sentinel: ImageBase == 0xdead in appended .zero section

Detection Signatures

See d69d4497 report for full YARA (infector + infected-file), Sigma, and behavioral hunt queries. ^[/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html]

References

  • Artifact ID: 7c17f12e-463d-4743-9672-124023c618ed (OpenCTI)
  • Twin artifact ID: dfd58feb-e7ca-49a9-a7c3-5b265ed0e794 (OpenCTI)
  • Related: phorpiex campaign entity page
  • Full analysis: /intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html

Provenance

Analysis derived from file.txt, exiftool.json, pefile.txt, strings.txt, triage.json, metadata.json, and radare2 decompilation (level 3, 73 functions) of <sample e0de4e3c9dee.bin>. Static-only; CAPE skipped because no Windows guest is available. Twin relationship confirmed by MD5-per-section comparison and cmp of strings.txt artifacts.