Chrome 128 User-Agent Masquerade
Malware hardcodes a fake Google Chrome User-Agent string to masquerade its HTTP requests as legitimate browser traffic. The version number is often absurd or impossible (e.g., Chrome/7775543322.0.0.0 or Chrome/128.0.0.0), which makes the string trivial to detect but also serves as a family fingerprint.
Detection / Fingerprint
Look for WinInet or WinHTTP requests where the User-Agent header contains:
Chrome/followed by a version component that is clearly non-existent (7775543322,128with no sub-version, or other out-of-range numbers).- The full Phorpiex variant:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/7775543322.0.0.0 Safari/537.36
Implementation Patterns Observed
The UA string is passed as the lpszAgent parameter to InternetOpenW in WinInet-based downloaders. In the Phorpiex campaign the same UA string is reused across multiple compiled binaries, making it a high-signal network IOC.
Reproduce on Your Own VMs
Compile a minimal C/C++ program that calls:
HINTERNET hInternet = InternetOpenW(
L"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
L"AppleWebKit/537.36 (KHTML, like Gecko) "
L"Chrome/7775543322.0.0.0 Safari/537.36",
INTERNET_OPEN_TYPE_DIRECT,
NULL, NULL, 0);
Then fetch any URL via InternetOpenUrlW + InternetReadFile. Observe the outgoing User-Agent in a packet capture or proxy log.
Defensive Countermeasures
- Proxy / firewall rules blocking or alerting on
User-AgentcontainingChrome/7775543322or similar impossible version strings. - EDR network telemetry rules for processes that are not browsers but emit Chrome User-Agent strings.
Pages Where Observed
- phorpiex — campaign-level abuse of this masquerade across thin-downloaders and the business-app masquerade variant
9570038453. - Phorpiex thin-downloader siblings (
6b8527a7,2ffc3203,32f29422,f67e429d,025f5798).