typetechniqueconfidencehighcreated2026-09-01updated2026-09-01phorpiexloadermsvcinittermreflectiveanti-analysis

Phorpiex Loader — initterm Hijack

MSVC 9.0 (MSVCR90.dll) reflective loader technique observed in early Phorpiex samples. The malware hijacks the C runtime initialisation path (_initterm / _initterm_e) to execute its payload before main() is reached, evading simple API-tracing sandboxes that only monitor the main thread.

Mechanism

  1. The binary is a standard PE32 GUI linked against MSVCR90.dll.
  2. The .rdata section contains an encrypted payload.
  3. During CRT startup, _initterm calls a user-defined initialiser array.
  4. One of those initialisers decrypts and maps the payload reflectively.
  5. By the time main() is called, the payload is already running in a new thread.

Detection

  • Unusually large .rdata section (> 5 KB) in an 18–25 KB PE.
  • MSVCR90.dll import table with _initterm / _initterm_e but minimal other CRT usage.
  • Thread creation inside _initterm before main().

Observed In

  • phorpiex sample 755bed07 — 21 KB, masquerades as Microsoft Screen Saver.

References