Skip to main content

Worm:W32/Phorpiex

Classification

Category:

Malware

Type:

Worm

Aliases:

  • TR/AD.Phorpiex.sdjto

Summary

Phorpiex is a worm which spreads via removable drives and network drives. Some Phorpiex variants will also download additional malware such as cryptominer and execute them.

Removal

Technical Details

Infection Vector

Phorpiex typically propagates or spreads via an infected removable or shared drive. It can also spread via drive-by downloads if it infects a web server.

Behavior

Upon execution, Phorpiex checks for the presence of a virtual or debugging environment; if found, it will terminate itself.

If it does not find a debugging environment, it will proceed to add a registry key so that it can persistance on the machine. It will also added a mutex to ensure that only one instance of itself is running. Different variants will have different mutexes, but all use a hardcoded 13-digit numerical value.

Next, Phorpiex starts infecting removable and shared drives. Subsequently, it also tries to connects to malicious command and control (C&C) servers to download additonal malware to be executed.

The worm is also capable of compromising system security by disabling security features.

Propagation

Once it is present on a computer, the worm can propagate or spread copies of its malicious file by infecting any accessible network drives or inserted removable storage devices. Some variants also propagate by compromising web servers, which could expose site visitors to drive-by downloads.

To propagate, Phorpiex performs the following actions:

Files created

Depending on the execution privilege, Phorpiex creates a copy of itself at:

  • %windir%\5060077904302040\winsvcs.exe
  • %userprofile%\5060077904302040\winsvcs.exe
  • %appdata%\5060077904302040\winsvcs.exe or
  • %temp%\5060077904302040\winsvcs.exe

Phorpiex will also drop these file on the infected system:

  • %temp%\5060077904302040\Windows Archive Manager.exe
  • %appdata%\winsvcs_.txt

Registry Changes

Phorpiex adds the following registry key so that it can automatically run at startup:

Depending on the execution privilage:

  • "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ : [path of the newly copied file of itself]\5060077904302040\winsvcs.exe"
  • "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ : [path of the newly copied file of itself]\5060077904302040\winsvcs.exe"

Network activity

It connects to one of the following servers, with URLs that are defined by a list of provided top-level domains (TLDs) and parameters:

  • hxxp://92.63[.]197.48/
  • hxxp://afeifieuuufufufuf.[TLD]
  • hxxp://aiiaiafrzrueuedur.[TLD]
  • hxxp://eiifngjfksisiufjf.[TLD]
  • hxxp://eofihsishihiursgu.[TLD]
  • hxxp://eoroooskfogihisrg.[TLD]
  • hxxp://fifiehsueuufidhfi.[TLD]
  • hxxp://fiiauediehduefuge.[TLD]
  • hxxp://fuaiuebndieufeufu.[TLD]
  • hxxp://iuirshriuisruruuf.[TLD]
  • hxxp://nnososoosjfeuhueu.[TLD]
  • hxxp://noeuaoenriusfiruu.[TLD]
  • hxxp://nousiieiffgogogoo.[TLD]
  • hxxp://slpsrgpsrhojifdij.[TLD]
  • hxxp://srndndubsbsifurfd.[TLD]
  • hxxp://ssofhoseuegsgrfnu.[TLD]

The [TLD] for the server URLs may be:

  • .biz, .com, .in, .info, .net, .su, .ru

The URL parameters may be:

  • /m.exe, /o.exe, /p.exe, /s.exe, /t.exe, /tldr.php?new=1, /tldr.php?on=1

The User-Agent is:

  • Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0

Other Behavior

The worm also has the capability to:

Analysis on file: b6ce47cc2a6dbf7309957cdfd3faf8a0ba3c2c8d

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.