Wraith
A Windows PE32 malware family characterized by a custom companion-file XOR decryption stub, system-information harvesting, and raw-socket C2 surface. The MalwareBazaar/OpenCTI label wraith co-occurs with the prometei botnet family in broader threat-intel feeds, but technical evidence linking the two is sparse — treat as separate families until cluster confirmation.
Build Stack
- PE32 GUI, x86, 6 sections
- MajorLinkerVersion 6.0 (retro toolchain) with forged or recent timestamps
- RWX section flags on
.stuband.text(self-modifying / encrypted payload) ^[sample 0ab9a570/pefile.txt] - Unsigned; no Authenticode certificate
- Heavy
.datasection inflation: ~24 MB virtual size, ~16 KB raw (encrypted payload staging)
Deploy / TTPs
| TTP | ID | Evidence |
|---|---|---|
| System Information Discovery | T1082 | systeminfo execution via CreateProcessA ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html] |
| Network Service Discovery | T1046 | ping 8.8.8.8 connectivity probe ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html] |
| Obfuscated Files or Information | T1027 | Rolling XOR decryption with external companion key ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html] |
| Access Token Manipulation | T1134.001 | OpenProcessToken → AdjustTokenPrivileges ^[sample 0ab9a570/pefile.txt] |
| Command and Control | T1071.001 | Full raw-socket WSOCK32 import surface (no hardcoded C2 strings recovered) ^[sample 0ab9a570/pefile.txt] |
Capabilities
companion-file-key-decryptionrolling-xor-section-decryptionsysteminfo-harvestingconnectivity-probe-pingraw-tcp-c2-sockettoken-privilege-escalationrwx-section-self-modifyingfilesystem-gate-anti-sandbox
Notable Analyses
0ab9a570— Custom XOR companion-key PE32 stub, systeminfo harvesting, raw-socket C2 surface. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]
Related
- prometei — Co-tagged
wraithin MalwareBazaar/OpenCTI feeds; distinct build stack. - companion-file-key-decryption — Technique page for filesystem-bound decryption gates.
- raw-tcp-c2-socket — Raw TCP socket C2 without application-layer framing.
Attribution
No clear actor attribution. The masquerade string PaiAuganMai does not map to known legitimate software. The retro linker version (v6.0) with a 2025 timestamp suggests either deliberate toolchain selection or timestamp forgery.