MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 24c134595a2e38206674b3e4be0f57e00a29477c51103785dc18e937eebb6e57. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Phorpiex


Vendor detections: 16


Intelligence 16 IOCs YARA 1 File information Comments

SHA256 hash: 24c134595a2e38206674b3e4be0f57e00a29477c51103785dc18e937eebb6e57
SHA3-384 hash: 303482534eead0efeafaba905edc14d0fa7e61ef9f27e5c293c8bdfd3f5726246746a7845396104b537b54d61e67c96d
SHA1 hash: 3a5e4683d6ba64238b0ea14d1062e3ab4e18cf07
MD5 hash: 4e8b770def5fa68ac9fdad816a5b50fc
humanhash: two-fifteen-venus-lamp
File name:file
Download: download sample
Signature Phorpiex
File size:11'776 bytes
First seen:2026-03-09 09:39:29 UTC
Last seen:2026-03-09 10:30:51 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 27080eab3ded4a4cce0697f22f2df921 (4 x Phorpiex)
ssdeep 192:yBdeU99M0CnUrfR6fBee2Hz3bJxTNerBthIjOu:UdT9MqR6fArzrBerBsO
Threatray 1 similar samples on MalwareBazaar
TLSH T14B32190A684A5831F3E204B2277F829786BD1AA337D5B9DBF380764D0E753D1C17866E
TrID 39.7% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
21.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
8.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
8.3% (.EXE) Win64 Executable (generic) (6522/11/2)
6.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
Reporter Bitsight
Tags:dropped-by-phorpiex exe Phorpiex


Avatar
Bitsight
url: http://178.16.54.109/32.exe

Intelligence


File Origin
# of uploads :
7
# of downloads :
164
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
phorpiex
ID:
1
File name:
file
Verdict:
Malicious activity
Analysis date:
2026-03-09 09:39:42 UTC
Tags:
evasion loader auto-reg stealer botnet phorpiex golang

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.9%
Tags:
downloader dropper hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm microsoft_visual_cc phorpiex
Verdict:
Malicious
File Type:
exe x32
Detections:
HEUR:Worm.Win32.Generic HEUR:Trojan-Downloader.Win32.Agent.gen HEUR:Trojan-Banker.Win32.Phorpiex.gen HEUR:Trojan.Win32.Agent.gen Trojan.Agent.HTTP.C&C Trojan-Downloader.Win32.Gomal.sb Trojan-Banker.Win32.ClipBanker.sb Trojan.Win32.Injuke.pmkn Trojan.Win32.Agent.sb Backdoor.Agent.HTTP.C&C PDM:Trojan.Win32.Generic HEUR:Virus.Win32.Zeropi.gen HEUR:Trojan-Banker.Win32.ClipBanker.gen Trojan-PSW.PureLogs.TCP.C&C Trojan-Dropper.Win32.Dorifel.sbc Trojan.Win32.Zonidel.sb Trojan.Agentb.UDP.C&C RiskTool.BitCoinMiner.TCP.C&C
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Worm.Phorpiex
Status:
Malicious
First seen:
2026-03-09 09:40:26 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
18 of 23 (78.26%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:phorphiex family:xmrig discovery loader miner persistence spyware stealer trojan worm
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Looks up external IP address via web service
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Downloads MZ/PE file
Phorphiex family
Phorphiex, Phorpiex
XMRig Miner payload
Xmrig family
xmrig
Malware Config
C2 Extraction:
http://178.16.54.109
178.16.54.109
Unpacked files
SH256 hash:
24c134595a2e38206674b3e4be0f57e00a29477c51103785dc18e937eebb6e57
MD5 hash:
4e8b770def5fa68ac9fdad816a5b50fc
SHA1 hash:
3a5e4683d6ba64238b0ea14d1062e3ab4e18cf07
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Phorpiex

Executable exe 24c134595a2e38206674b3e4be0f57e00a29477c51103785dc18e937eebb6e57

(this sample)

  
Dropped by
Phorpiex
  
Delivery method
Distributed via web download

Comments