← whack.sh News

Nine files, two payloads: a Silver Fox sideloader in an open directory

2026-09-29 · Threat Research

An HTTP File Server (HFS) on 156.238.123[.]182, port 7294, was serving a complete Chinese-language DLL-sideloading kit with no authentication and directory listing enabled. The kit pairs a genuine Microsoft-signed program with a malicious DLL that starts a two-stage chain: a downloader, then an implant that imports keylogging and clipboard functions. The listing showed eleven files: the signed host program, the sideloaded loader, and nine payload files that reduce to two payloads.

MalwareHunterTeam (@malwrhunterteam on X) first flagged the open directory publicly on September 28, 2026. The analysis of the kit, its payloads and its infrastructure is Tuxxin's.

The malicious samples are on MalwareBazaar and VirusTotal, and the indicators are in an AlienVault OTX pulse.

The open directory

The directory is hxxp://156.238.123[.]182:7294/.

FileSize (bytes)Contents
1.1x1252,768Signed Microsoft console program, the sideload host
1.d00172,032Unsigned DLL, the loader
mqpbl.xm, nqxzer.xm, qlnxro.xm, xmlakt.xm344,064 eachStage 1 downloader, four copies
gdtqka.fyx, mqucpe.yjl, nlehkyc.yxr, qbupve.btk, xfzwinq.krx363,520 eachStage 2 implant, five copies

The signed host program

1.1x1 is the Microsoft SPD Dump Utility, SPDDUMP.EXE, from Visual Studio 14.51.36244.0. Its signature validates and the file is unmodified. VirusTotal scores it 0 of 70. The operators ship it because it is clean and signed. Treat it as the host half of a sideload pair and keep it out of malicious-file lists.

SPDDUMP.EXE imports two functions from mspdb140.dll: PDBOpen2W and PDBClose.

1.d00 is an unsigned DLL compiled on September 23, 2026. Among a long list of decoy Cygwin exports, it exports those two names. Renamed to spddump.exe and mspdb140.dll and placed in the same folder, the pair makes a signed Microsoft program load the attacker's code.

The loader finds its payload by wildcard

1.d00 contains no URLs and imports no network functions. When it loads, it:

  1. calls FreeConsole(), which hides the console window of SPDDUMP.EXE;
  2. gets its own path with GetModuleFileNameA and trims it to the directory;
  3. builds a wildcard from the string "*." plus an extension and searches its own folder with FindFirstFileA and FindNextFileA;
  4. opens the match with mode "rb", reads it into memory from VirtualAlloc, and runs it through QueueUserAPC.

The loader runs any file in its folder with the matching extension, so the operator can rename the payload for every victim.

Nine files, two payloads

Within each size group, XOR-ing any two files against each other returns zero for the first several hundred kilobytes. A full byte comparison shows that the copies differ by three or four bytes:

mqucpe.yjl vs gdtqka.fyx   ndiff=3    @0x54280  b3 cb 47  ->  33 ca 4d
qbupve.btk vs gdtqka.fyx   ndiff=3    @0x54280  b3 cb 47  ->  5f e5 51

In the stage 2 group, the changed bytes sit in .data padding directly after a hardcoded command-and-control (C2) IP address string. They leave execution unchanged and give each copy a different SHA-256, a technique called hash-busting.

In the stage 1 group, the changed bytes are ASCII text. Each copy carries the filename of the stage 2 file it downloads:

Stage 1 fileStage 2 file it fetches
mqpbl.xmmqucpe.yjl
nqxzer.xmnlehkyc.yxr
qlnxro.xmqbupve.btk
xmlakt.xmxfzwinq.krx

A shared 2 KB loader stub

Both payload types start with position-independent code. The first bytes, 40 55 53 56 57 41 54 41 55 41 56 41 57, are the prologue push rbp, push rbx, push rsi, push rdi, push r12 and onward.

At offset 0x800, 2,048 bytes in, each file holds a complete PE32+ image. Carving at that offset produces valid, analyzable executables. The 2,048-byte stub in front is byte-identical in stage 1 and stage 2:

5f7c25d4f1e5ce47674986d1f39fff1200a395646ccc516dbbdff55e39af7702

VirusTotal and MalwareBazaar had no record of the stub hash at the time of writing.

Stage 1: downloader and decoy

The carved stage 1 executable was compiled on July 11, 2026, and imports WinHTTP. It contains:

  • hxxp://156.238.123[.]182:7294/, the open directory it came from;
  • the filename of its paired stage 2 file;
  • https://www.baidu.com, used as a connectivity check;
  • process enumeration through CreateToolhelp32Snapshot;
  • a MessageBoxW call and this string:
您的电脑不支持此版本,请到官网下载最新版以继续安装。

In English: "Your computer does not support this version. Please go to the official website to download the latest version to continue installation."

The victim sees this installer error in Chinese while stage 1 fetches stage 2 in the background.

Stage 2: the implant

The carved stage 2 executable was compiled on August 12, 2026. Its import table shows almost no networking, because the names ws2_32.dll and winmm.dll are XOR-obfuscated inline and resolved at runtime. Its imports include these functions, grouped by capability:

CapabilityImports
KeyloggingGetAsyncKeyState, GetKeyboardState, MapVirtualKeyA, ToAscii, GetForegroundWindow, GetWindowTextW
Clipboard theftOpenClipboard, IsClipboardFormatAvailable, GetClipboardData
PersistenceRegCreateKeyExW, RegSetValueExW, RegisterApplicationRestart
InjectionVirtualAlloc, VirtualProtect, GetThreadContext, SetThreadContext, CreateProcessW
Integrity-level checkOpenProcessToken, GetTokenInformation, GetSidSubAuthority

Host artifacts to hunt for:

  • a mutex matching Local\Mutex_%08X;
  • a relaunch command line of the form "<path>" --restart-after-pid <pid>.

The C2 address is a plain string in .data: 137.220.156[.]70 in four of the five copies and 137.220.156[.]69 in the fifth. The implant writes the port into a global variable at runtime, so the files alone do not reveal it.

Attribution

This report makes no independent attribution. VirusTotal labels a 41 MB archive on the same staging host, a fake LetsVPN installer package, as trojan.silverfox/wylw.

Silver Fox (银狐) is a documented cluster that targets Chinese-speaking users with trojanized installers of popular software. The kit matches that pattern: a Chinese-language decoy, a Baidu connectivity check and a VPN lure.

LetsVPN lookalike domains

LetsVPN is a legitimate product and the impersonated brand in this operation. The service is blocked in mainland China, so its operators run a large, rotating set of mirror domains with numbered names in the pattern a1-letsvpn, a2-letsvpn.

We enumerated 576 LetsVPN lookalike domains and checked each one against the attacker's hosting ranges. None resolved into attacker infrastructure. They are excluded from the indicators below, because listing them would flag a large number of innocent domains. Resolve lookalike domains against known attacker infrastructure before adding them to a blocklist.

A sibling staging host, April to August 2026

Public URL-scan history returns 44 scans of a second HFS server that served the filename 1.d00:

Path on hxxp://154.198.50[.]76:8080/Relation to this kit
1.1x1, 1.d00Same sideload filenames
dlters.xmSame .xm stage 1 extension
dusbng.resNo counterpart on the current host
/uploadHFS upload endpoint

Both servers use the HFS page title HFS - 文件列表 ("HFS - file list"). The older host was active from April 2026 to at least August 12, 2026, on a different provider and a different continent. It pivots to the same malware cluster, including KunBang.dll, QQHong_* and Update.dll, reaching the same C2 at 137.220.156[.]69. The two staging hosts belong to one operation.

Detection

  • The 2,048-byte loader stub is the strongest single signal. It is shared across stages and unaffected by the hash-busting.
  • Alert on the pair: a signed SPDDUMP.EXE next to an unsigned mspdb140.dll outside a Visual Studio install directory.
  • QueueUserAPC running memory that was read from a wildcard match in the process's own directory is a narrow behavioral signature.
  • Payload filenames and payload hashes change per copy by design. Detections built on either alone will miss the next copy.

Indicators of compromise

IndicatorRoleHosting
156.238.123[.]182:7294HFS staging host and open directoryAS54801 Zillion Network (PH)
154.198.50[.]76:8080Sibling staging host, April to August 2026AS138995 Antbox Networks (SC)
137.220.156[.]69Stage 2 C2AS4907 BGPNET (JP)
137.220.156[.]70Stage 2 C2AS4907 BGPNET (JP)

SHA-256, malicious:

401c5e167f6f17b2b8362c2056f22d8843d1fa52195e89ba4e88d9346d179496  1.d00 (malicious mspdb140.dll)
5f7c25d4f1e5ce47674986d1f39fff1200a395646ccc516dbbdff55e39af7702  shared 2,048-byte loader stub
64ae3a7092ddbd80289a4a0cc1f846f8ef7353d062983d6dd33cef9fbe22f5e6  mqpbl.xm     stage 1
288333007ef4dc1d037a9fd4a738de6880f913685d249665c73ee67091a0a092  nqxzer.xm    stage 1
46de9a3cc65df078d8fa20f0c7bd098e136c030df1053df530a8aca739145301  qlnxro.xm    stage 1
740b1aeab51e61de17f6bc82e02f9335b02bb24133fb73bd96a6870006d4ee1c  xmlakt.xm    stage 1
3f1af26ff035374ae1c4d44a4a581444aa9f92d4baf2f03c3db2221129537473  stage 1, carved PE
7218bc172e68a3c651ba68c7ea4d28e28fc282f871c557b7fbc88624b6621789  gdtqka.fyx   stage 2
7584e6296a476069a2e7b3f41a08903a4a3b2754f10e607317678056744cc4fe  mqucpe.yjl   stage 2
461793559fa43ebc74cb885558ded8a79c32255b3d8cd7b6341478e7dc806168  nlehkyc.yxr  stage 2
bbd64f281d249bfe328b072c0db87b6226c7f4208a8b36edec78bed7b611a24a  qbupve.btk   stage 2
4ea8b2a2438b9d1fd76e110b944ba9156459e4ff0a81aff8aa668d0a4e731f5f  xfzwinq.krx  stage 2
bd520a958988f14e471b09b8c6e8f201ba045bdff647d9110a9aa09b7286e8b2  stage 2, carved PE
c2f0a3e9913a8a36befaa07e67a16df6ce966f10662e6663493f8603673fc76a  fake LetsVPN .zip delivery package

SHA-256, clean. Do not block:

9a09faa9fa833f1810094c1a71e43217ff82e4861e3c63cea7670434b8d8229d  1.1x1 = Microsoft SPDDUMP.EXE (0/70)

Disclosure

On September 29, 2026, Tuxxin LLC contributed the samples to MalwareBazaar and VirusTotal and published the indicators to AlienVault OTX. The legitimate Microsoft binary was excluded from all submissions.


For coordinated disclosure: [email protected].