
A Five-Year-Old Phorpiex Dropper Still Wears a Windows Disguise
A Phorpiex/ClipBanker dropper compiled in October 2020 is still being flagged by security engines today, masquerading as svchost.exe and DriveMgr.exe while pointing to two live C2 domains. Neither the sample nor its infrastructure needed innovation to stay viable — just cheap TLS cover and a CPU-timer sandbox check.
A Phorpiex dropper compiled on 31 October 2020 is still being flagged by anti-malware engines today, and it hasn't needed a rewrite to stay useful. The sample (tracked internally as 5d9b6c49a8c8…) presents itself under the names DriveMgr.exe and C:\2994616913505\svchost.exe — masquerading as ordinary Windows plumbing [T1036] rather than anything a user would think twice about.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read