Phorpiex Loader — initterm Hijack
MSVC 9.0 (MSVCR90.dll) reflective loader technique observed in early Phorpiex samples. The malware hijacks the C runtime initialisation path (_initterm / _initterm_e) to execute its payload before main() is reached, evading simple API-tracing sandboxes that only monitor the main thread.
Mechanism
- The binary is a standard PE32 GUI linked against
MSVCR90.dll. - The
.rdatasection contains an encrypted payload. - During CRT startup,
_inittermcalls a user-defined initialiser array. - One of those initialisers decrypts and maps the payload reflectively.
- By the time
main()is called, the payload is already running in a new thread.
Detection
- Unusually large
.rdatasection (> 5 KB) in an 18–25 KB PE. MSVCR90.dllimport table with_initterm/_initterm_ebut minimal other CRT usage.- Thread creation inside
_inittermbeforemain().
Observed In
- phorpiex sample
755bed07— 21 KB, masquerades asMicrosoft Screen Saver.