Nine files, two payloads: a Silver Fox sideloader in an open directory
An HTTP File Server (HFS) on 156.238.123[.]182, port 7294, was serving a complete Chinese-language DLL-sideloading kit with no authentication and directory listing enabled. The kit pairs a genuine Microsoft-signed program with a malicious DLL that starts a two-stage chain: a downloader, then an implant that imports keylogging and clipboard functions. The listing showed eleven files: the signed host program, the sideloaded loader, and nine payload files that reduce to two payloads.
MalwareHunterTeam (@malwrhunterteam on X) first flagged the open directory publicly on September 28, 2026. The analysis of the kit, its payloads and its infrastructure is Tuxxin's.
The malicious samples are on MalwareBazaar and VirusTotal, and the indicators are in an AlienVault OTX pulse.
The open directory
The directory is hxxp://156.238.123[.]182:7294/.
| File | Size (bytes) | Contents |
|---|---|---|
1.1x1 | 252,768 | Signed Microsoft console program, the sideload host |
1.d00 | 172,032 | Unsigned DLL, the loader |
mqpbl.xm, nqxzer.xm, qlnxro.xm, xmlakt.xm | 344,064 each | Stage 1 downloader, four copies |
gdtqka.fyx, mqucpe.yjl, nlehkyc.yxr, qbupve.btk, xfzwinq.krx | 363,520 each | Stage 2 implant, five copies |
The signed host program
1.1x1 is the Microsoft SPD Dump Utility, SPDDUMP.EXE, from Visual Studio 14.51.36244.0. Its signature validates and the file is unmodified. VirusTotal scores it 0 of 70. The operators ship it because it is clean and signed. Treat it as the host half of a sideload pair and keep it out of malicious-file lists.
SPDDUMP.EXE imports two functions from mspdb140.dll: PDBOpen2W and PDBClose.
1.d00 is an unsigned DLL compiled on September 23, 2026. Among a long list of decoy Cygwin exports, it exports those two names. Renamed to spddump.exe and mspdb140.dll and placed in the same folder, the pair makes a signed Microsoft program load the attacker's code.
The loader finds its payload by wildcard
1.d00 contains no URLs and imports no network functions. When it loads, it:
- calls
FreeConsole(), which hides the console window ofSPDDUMP.EXE; - gets its own path with
GetModuleFileNameAand trims it to the directory; - builds a wildcard from the string
"*."plus an extension and searches its own folder withFindFirstFileAandFindNextFileA; - opens the match with mode
"rb", reads it into memory fromVirtualAlloc, and runs it throughQueueUserAPC.
The loader runs any file in its folder with the matching extension, so the operator can rename the payload for every victim.
Nine files, two payloads
Within each size group, XOR-ing any two files against each other returns zero for the first several hundred kilobytes. A full byte comparison shows that the copies differ by three or four bytes:
mqucpe.yjl vs gdtqka.fyx ndiff=3 @0x54280 b3 cb 47 -> 33 ca 4d
qbupve.btk vs gdtqka.fyx ndiff=3 @0x54280 b3 cb 47 -> 5f e5 51
In the stage 2 group, the changed bytes sit in .data padding directly after a hardcoded command-and-control (C2) IP address string. They leave execution unchanged and give each copy a different SHA-256, a technique called hash-busting.
In the stage 1 group, the changed bytes are ASCII text. Each copy carries the filename of the stage 2 file it downloads:
| Stage 1 file | Stage 2 file it fetches |
|---|---|
mqpbl.xm | mqucpe.yjl |
nqxzer.xm | nlehkyc.yxr |
qlnxro.xm | qbupve.btk |
xmlakt.xm | xfzwinq.krx |
A shared 2 KB loader stub
Both payload types start with position-independent code. The first bytes, 40 55 53 56 57 41 54 41 55 41 56 41 57, are the prologue push rbp, push rbx, push rsi, push rdi, push r12 and onward.
At offset 0x800, 2,048 bytes in, each file holds a complete PE32+ image. Carving at that offset produces valid, analyzable executables. The 2,048-byte stub in front is byte-identical in stage 1 and stage 2:
5f7c25d4f1e5ce47674986d1f39fff1200a395646ccc516dbbdff55e39af7702
VirusTotal and MalwareBazaar had no record of the stub hash at the time of writing.
Stage 1: downloader and decoy
The carved stage 1 executable was compiled on July 11, 2026, and imports WinHTTP. It contains:
hxxp://156.238.123[.]182:7294/, the open directory it came from;- the filename of its paired stage 2 file;
https://www.baidu.com, used as a connectivity check;- process enumeration through
CreateToolhelp32Snapshot; - a
MessageBoxWcall and this string:
您的电脑不支持此版本,请到官网下载最新版以继续安装。
In English: "Your computer does not support this version. Please go to the official website to download the latest version to continue installation."
The victim sees this installer error in Chinese while stage 1 fetches stage 2 in the background.
Stage 2: the implant
The carved stage 2 executable was compiled on August 12, 2026. Its import table shows almost no networking, because the names ws2_32.dll and winmm.dll are XOR-obfuscated inline and resolved at runtime. Its imports include these functions, grouped by capability:
| Capability | Imports |
|---|---|
| Keylogging | GetAsyncKeyState, GetKeyboardState, MapVirtualKeyA, ToAscii, GetForegroundWindow, GetWindowTextW |
| Clipboard theft | OpenClipboard, IsClipboardFormatAvailable, GetClipboardData |
| Persistence | RegCreateKeyExW, RegSetValueExW, RegisterApplicationRestart |
| Injection | VirtualAlloc, VirtualProtect, GetThreadContext, SetThreadContext, CreateProcessW |
| Integrity-level check | OpenProcessToken, GetTokenInformation, GetSidSubAuthority |
Host artifacts to hunt for:
- a mutex matching
Local\Mutex_%08X; - a relaunch command line of the form
"<path>" --restart-after-pid <pid>.
The C2 address is a plain string in .data: 137.220.156[.]70 in four of the five copies and 137.220.156[.]69 in the fifth. The implant writes the port into a global variable at runtime, so the files alone do not reveal it.
Attribution
This report makes no independent attribution. VirusTotal labels a 41 MB archive on the same staging host, a fake LetsVPN installer package, as trojan.silverfox/wylw.
Silver Fox (银狐) is a documented cluster that targets Chinese-speaking users with trojanized installers of popular software. The kit matches that pattern: a Chinese-language decoy, a Baidu connectivity check and a VPN lure.
LetsVPN lookalike domains
LetsVPN is a legitimate product and the impersonated brand in this operation. The service is blocked in mainland China, so its operators run a large, rotating set of mirror domains with numbered names in the pattern a1-letsvpn, a2-letsvpn.
We enumerated 576 LetsVPN lookalike domains and checked each one against the attacker's hosting ranges. None resolved into attacker infrastructure. They are excluded from the indicators below, because listing them would flag a large number of innocent domains. Resolve lookalike domains against known attacker infrastructure before adding them to a blocklist.
A sibling staging host, April to August 2026
Public URL-scan history returns 44 scans of a second HFS server that served the filename 1.d00:
Path on hxxp://154.198.50[.]76:8080/ | Relation to this kit |
|---|---|
1.1x1, 1.d00 | Same sideload filenames |
dlters.xm | Same .xm stage 1 extension |
dusbng.res | No counterpart on the current host |
/upload | HFS upload endpoint |
Both servers use the HFS page title HFS - 文件列表 ("HFS - file list"). The older host was active from April 2026 to at least August 12, 2026, on a different provider and a different continent. It pivots to the same malware cluster, including KunBang.dll, QQHong_* and Update.dll, reaching the same C2 at 137.220.156[.]69. The two staging hosts belong to one operation.
Detection
- The 2,048-byte loader stub is the strongest single signal. It is shared across stages and unaffected by the hash-busting.
- Alert on the pair: a signed
SPDDUMP.EXEnext to an unsignedmspdb140.dlloutside a Visual Studio install directory. QueueUserAPCrunning memory that was read from a wildcard match in the process's own directory is a narrow behavioral signature.- Payload filenames and payload hashes change per copy by design. Detections built on either alone will miss the next copy.
Indicators of compromise
| Indicator | Role | Hosting |
|---|---|---|
156.238.123[.]182:7294 | HFS staging host and open directory | AS54801 Zillion Network (PH) |
154.198.50[.]76:8080 | Sibling staging host, April to August 2026 | AS138995 Antbox Networks (SC) |
137.220.156[.]69 | Stage 2 C2 | AS4907 BGPNET (JP) |
137.220.156[.]70 | Stage 2 C2 | AS4907 BGPNET (JP) |
SHA-256, malicious:
401c5e167f6f17b2b8362c2056f22d8843d1fa52195e89ba4e88d9346d179496 1.d00 (malicious mspdb140.dll)
5f7c25d4f1e5ce47674986d1f39fff1200a395646ccc516dbbdff55e39af7702 shared 2,048-byte loader stub
64ae3a7092ddbd80289a4a0cc1f846f8ef7353d062983d6dd33cef9fbe22f5e6 mqpbl.xm stage 1
288333007ef4dc1d037a9fd4a738de6880f913685d249665c73ee67091a0a092 nqxzer.xm stage 1
46de9a3cc65df078d8fa20f0c7bd098e136c030df1053df530a8aca739145301 qlnxro.xm stage 1
740b1aeab51e61de17f6bc82e02f9335b02bb24133fb73bd96a6870006d4ee1c xmlakt.xm stage 1
3f1af26ff035374ae1c4d44a4a581444aa9f92d4baf2f03c3db2221129537473 stage 1, carved PE
7218bc172e68a3c651ba68c7ea4d28e28fc282f871c557b7fbc88624b6621789 gdtqka.fyx stage 2
7584e6296a476069a2e7b3f41a08903a4a3b2754f10e607317678056744cc4fe mqucpe.yjl stage 2
461793559fa43ebc74cb885558ded8a79c32255b3d8cd7b6341478e7dc806168 nlehkyc.yxr stage 2
bbd64f281d249bfe328b072c0db87b6226c7f4208a8b36edec78bed7b611a24a qbupve.btk stage 2
4ea8b2a2438b9d1fd76e110b944ba9156459e4ff0a81aff8aa668d0a4e731f5f xfzwinq.krx stage 2
bd520a958988f14e471b09b8c6e8f201ba045bdff647d9110a9aa09b7286e8b2 stage 2, carved PE
c2f0a3e9913a8a36befaa07e67a16df6ce966f10662e6663493f8603673fc76a fake LetsVPN .zip delivery package
SHA-256, clean. Do not block:
9a09faa9fa833f1810094c1a71e43217ff82e4861e3c63cea7670434b8d8229d 1.1x1 = Microsoft SPDDUMP.EXE (0/70)
Disclosure
On September 29, 2026, Tuxxin LLC contributed the samples to MalwareBazaar and VirusTotal and published the indicators to AlienVault OTX. The legitimate Microsoft binary was excluded from all submissions.
For coordinated disclosure: [email protected].
whack