e0de4e3c9dee9877c78832ac9ebe3fbd2de45026896d6fc2a5ca12f6b588a29aphorpiex: e0de4e3c — TWIZTPEINF parasitic infector (byte-identical twin of d69d4497)
Executive Summary. This sample is a byte-identical twin of the Phorpiex parasitic infector d69d4497 — same binary, different OpenCTI artifact ID. It carries the dropped-by-phorpiex tag and the TWIZTPEINF infection marker. All static artifacts (section hashes, strings, imports, build fingerprint) match the sibling exactly. For full decompiled behavior, payload shellcode analysis, and deployable signatures, see the deep-dive report on d69d4497. ^[/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html]
What It Is
- File:
e0de4e3c9dee9877c78832ac9ebe3fbd2de45026896d6fc2a5ca12f6b588a29a.bin(22,528 bytes) - Type: PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
- Toolchain: MSVC 9.0 (Visual Studio 2008), linker 9.0, MSVCR90.dll CRT ^[exiftool.json], ^[pefile.txt:44]
- Timestamp: 2026-05-29 11:38:23 UTC (same build day as sibling
d69d4497at 11:32:30 UTC) ^[pefile.txt:34] - Family: Phorpiex (campaign umbrella)
- Signing: Unsigned ^[pefile.txt:192]
- Packing: None. Plain MSVC9 native code ^[pefile.txt:92]
Twin Verification
| Check | d69d4497 | e0de4e3c | Match |
|---|---|---|---|
| .text MD5 | b50e5de817ef6e6aa6fb1f21c123658a | b50e5de817ef6e6aa6fb1f21c123658a | ✓ |
| .rdata MD5 | 371ad74fd96153c1c566aecccf04c5a3 | 371ad74fd96153c1c566aecccf04c5a3 | ✓ |
| .data MD5 | 202a0f14ba4a024e6a35d5895669b769 | 202a0f14ba4a024e6a35d5895669b769 | ✓ |
| .rsrc MD5 | 58a3970c5ba6bee8bcaf23ee7343f378 | 58a3970c5ba6bee8bcaf23ee7343f378 | ✓ |
| .reloc MD5 | 460740661befd8c7613165ead3642d20 | 460740661befd8c7613165ead3642d20 | ✓ |
| strings.txt | IDENTICAL | IDENTICAL | ✓ |
| imports | Same 5 DLLs, 53 imports | Same 5 DLLs, 53 imports | ✓ |
| triage labels | dropped-by-phorpiex, exe, malware-bazaar |
dropped-by-phorpiex, exe, malware-bazaar |
✓ |
The only structural difference is the OpenCTI artifact ID and the SHA-256 itself, confirming this is the same binary ingested twice under distinct artifact records. ^[metadata.json], ^[triage.json]
Decompiled Behavior
Radare2 analysis (level 3, 73 functions) confirms the identical control-flow graph to d69d4497:
main @ 0x00401000— sleeps 2 s, creates mutexTWIZTPEINF, checksGetLastError() == 0xB7(ERROR_ALREADY_EXISTS), callsfcn.00402830to create%appdata%\windrx.txtmarker file, then spawns threadfcn.00403130and sleeps ~36.2 h. ^[r2:main]fcn.00402a70— recursive directory walker with 21-name blacklist (windows,winsxs,cache,boot,microsoft,system,programdata,program files,appdata,application data,intel,default,config,perflogs,recovery,drivers,prefetch,recycle,extend,msocache,temp), case-insensitive viaCharLowerW, matches*.exeviaPathMatchSpecW. ^[r2:fcn.00402a70]fcn.00402530— PE infection engine. Memory-maps victim, validates MZ/PE, checksImageBase != 0xdead(infection sentinel), appends.zerosection, copies PI shellcode fromfcn.004010f0tofcn.00401ef0(self-measured size), patchesAddressOfEntryPoint, setsImageBase = 0xdead, flushes, truncates. ^[r2:fcn.00402530]fcn.004010f0— payload shellcode. PEB-walking API hash resolution (fcn.00401bc0with constants0x526e0dcd,0xc4b4a94d,0x7a3a310,0x165d9659,0xeae447bb), loadsurlmon.dll, resolvesURLDownloadToFileW, downloadshttp://178.16.54.109/32.exe(stack-built URL), writes to%appdata%\windrx.txt, deletesZone.IdentifierADS, then executes. ^[r2:fcn.004010f0]
For line-by-line decompilation of every function, hash constants, and sentinel-byte analysis, see the d69d4497 deep dive. ^[/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html]
C2 Infrastructure
Static C2 recovered from decompiled shellcode:
- URL:
http://178.16.54.109/32.exe^[r2:fcn.004010f0] - Mutex:
TWIZTPEINF^[strings.txt:8] - Marker file:
%appdata%\windrx.txt^[strings.txt:10] - ADS deletion target:
%s:Zone.Identifier^[r2:fcn.004010f0]
Deploy / ATT&CK
- T1027.002 — Obfuscated Files or Information: Software Packing — parasitic section append with
0xdeadinfection sentinel ^[r2:fcn.00402530] - T1055 — Process Injection — position-independent shellcode injected into victim PE via
.zerosection ^[r2:fcn.00402530] - T1497.001 — Virtualization/Sandbox Evasion: System Checks —
NoDrivesregistry compliance to skip hidden drives ^[r2:fcn.004029b0] - T1564.001 — Hide Artifacts: Hidden Files and Directories —
Zone.IdentifierADS deletion ^[r2:fcn.004010f0] - T1204.002 — User Execution: Malicious File — victim launches infected
.exe - T1071.001 — Application Layer Protocol: Web Protocols — HTTP cleartext payload fetch ^[r2:fcn.004010f0]
Interesting Tidbits
- Duplicate artifact ID. OpenCTI assigned two distinct artifact records (
dfd58feb...ford69d4497,7c17f12e...fore0de4e3c) to the same 22,528-byte PE. This is a pipeline deduplication gap, not a variant. ^[metadata.json] - Campaign timestamp clustering. Build time 2026-05-29 11:38:23 UTC falls 6 minutes after sibling
d69d4497(11:32:30 UTC) and on the same day as business-app masquerade downloader0371fbbf(10:10:01 UTC). All three share the same C2 IP (178.16.54.109). This is a high-tempo build pipeline. ^[pefile.txt:34], ^[/intel/analyses/0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3.html] - No network imports in host. The infector body imports zero networking APIs; all C2 logic lives inside the PI shellcode that gets appended to victims. Splits static detection surface between "clean" host and "dirty" payload. ^[pefile.txt:229]
Deployable Signatures
Reuse the YARA rules from the d69d4497 deep dive — they match this twin byte-for-byte. Key IOCs:
- SHA-256:
e0de4e3c9dee9877c78832ac9ebe3fbd2de45026896d6fc2a5ca12f6b588a29a - SHA-256 (twin):
d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647 - Mutex:
TWIZTPEINF - Marker file:
%appdata%\windrx.txt - C2 URL:
http://178.16.54.109/32.exe - Infection sentinel:
ImageBase == 0xdeadin appended.zerosection
Detection Signatures
See d69d4497 report for full YARA (infector + infected-file), Sigma, and behavioral hunt queries. ^[/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html]
References
- Artifact ID:
7c17f12e-463d-4743-9672-124023c618ed(OpenCTI) - Twin artifact ID:
dfd58feb-e7ca-49a9-a7c3-5b265ed0e794(OpenCTI) - Related: phorpiex campaign entity page
- Full analysis:
/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html
Provenance
Analysis derived from file.txt, exiftool.json, pefile.txt, strings.txt, triage.json, metadata.json, and radare2 decompilation (level 3, 73 functions) of <sample e0de4e3c9dee.bin>. Static-only; CAPE skipped because no Windows guest is available. Twin relationship confirmed by MD5-per-section comparison and cmp of strings.txt artifacts.