This is Siemens...

More in Malware
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- .exe .docm .xlsm
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256:
e014dadf6d93b312b93e2fc857791c241692da4015da7a24a4d42a946551add2
Our attention was drawn to a message from the account that uploaded this sample:

Hmm, ICS malware, and it already has a ready-made name — S7Flip (so we don’t even need to strain our imagination to name it)? Sounds interesting! Let’s take a look at what’s inside.
After establishing persistence in autorun under the name aphp.exe, the sample begins collecting addresses of devices on the local network — these are addresses 192.168.*.*, 10.*.*.*, and 172.*.*.* — after which it checks them for the presence of certain open ports that are widely used by industrial devices:
- 102 — mainly used by Siemens controllers for communication via the S7Comm or S7Comm+ protocol.
- 502 — the standard port for the Modbus TCP protocol; it can be used by devices from any manufacturer.
- 44818 — mainly used by Allen-Bradley (Rockwell) controllers for communication via the EtherNet/IP (CIP) protocol.
Connecting to Allen-Bradley (Rockwell) devices effectively does not work. There is no implementation of a client for EtherNet/IP (CIP): the branch reuses the Siemens client and attempts to connect via port 102 as if to a Siemens controller. A connection to a real Allen-Bradley will not be established — no impact is exerted at all on devices that have only opened port 44818.
Having identified the required devices, S7Flip connects to them and begins applying one of the destructive mechanisms (or both at once).
Mechanism 1: “randomize” of values
Via S7Comm (port 102): it iterates through DB blocks 1–10 one by one; for each, it selects a random offset 0–99, reads a 4-byte integer from there, adds a random integer from −10 to +10, and writes it back.
Via Modbus TCP (port 502): it selects a 16-bit holding register at a random address 0–99, reads the current value, adds a random integer from −10 to +10, and writes it back.
Mechanism 2: bit inversion (findAndModifyInputs)
Via S7Comm (port 102): it sequentially goes through the first 100 bytes in DB blocks 1–10: reads a byte, flips its least significant bit to the opposite value, and writes it back.
Via Modbus TCP (port 502): it sequentially goes through single-bit write cells (coils — discrete outputs, commands, flags) in the range 0–255: reads a bit, flips it to the opposite value, and writes it back.
Each change is written to logs.csv next to the executable file and contains five columns — time, tag, vendor, old value, and new value.

In addition to this binary, we also found another one:
88717716e54b35682a28d673764975d439a31ee194c85dfc619a15ea93ab1280
In terms of its operating logic, it is no different from the sample examined earlier. The main difference is that the libmodbus library, which implements the Modbus protocol, is dynamically linked in e014dadf6d93b312b93e2fc857791c241692da4015da7a24a4d42a946551add2, while in 88717716e54b35682a28d673764975d439a31ee194c85dfc619a15ea93ab1280 it is statically linked.
On the same day, from the same account jeans, in addition to e014dadf6d93b312b93e2fc857791c241692da4015da7a24a4d42a946551add2 (file name — Edge.exe), another binary was uploaded:
2c57c1a39933514c63b5a7b585f5948ead04b65e4df96fb595ccda84208c4aa0
On closer inspection, it turned out to be a wiper. When launched, it gentlemanly asks whether you would like to install Microsoft Edge:

And if you decline, the wiper stops its work 😅
But if you agree… then be prepared for “unforeseen circumstances.” Here is the list:
- recursive deletion of all contents of the
%USERPROFILE%\Desktopfolder; - a file
compiled-desktopwill also be created there, containing exactly1 048 576random bytes; - and, of course, a
README.txtfile with a polite request to transfer bitcoins in the amount of 100 dollars.
After all this, the malware adds itself to autorun.
File decryption is not provided for: the contents of the desktop are not saved anywhere. This is a pseudo-ransomware wiper.
The most interesting thing is that README.txt specifies a wallet to which the attackers propose to send the money: bc1qp6ejw8ptj9l9pkscmlf8fhhkrrjeawgpyjvtq8 — this is the official donation wallet for the Bitcoin.org project. That is, the scammers don’t actually want a ransom? Hmm, interesting… 🤑
A little later, jeans uploaded another variant of this tool — f47502628708300840efe2771a3c5e7e9a631205512f0a2ee6382a00a92056e2, and this time the file is named not Edge.exe but Edgev5.exe.
Does v5 signify some kind of development or further improvement of the malware? Yes, in the new version the author added symmetric file encryption using AES-256-GCM, and also expanded the number of folders for encryption: now, in addition to Desktop, Downloads and Documents are also subject to encryption. True, there is one nuance… the key for decrypting the data is located in the master_key.dat file, and the bitcoin wallet is the same as in the earlier version of the wiper.
Apparently, the author of the malware is actively developing and testing their tool. It is possible that in the future they will begin actively using it in a “combat” form.
So what is the connection between S7Flip and the wipers? 🧐
While reading this post, you may have wondered: “how are S7Flip and the wiper connected to each other?” And in fact, there are certain coincidences:
- all binaries were compiled using the GCC 16.2.0 toolchain;
- the build timestamp of the PE files
88717716e54b35682a28d673769475d439a31ee194c85dfc619a15ea93ab1280(S7Flip) and2c57c1a39933514c63b5a7b585f5948ead04b65e4df96fb595ccda84208c4aa0(Edge.exe) matches to within a day — 2026-09-13; - the shared account from which the files were uploaded to MalwareBazaar is
jeans.
Is this data sufficient to assert that S7Flip and the wipers were developed by the same author? No, certain doubts still remain, but there is nonetheless some connection.
IoCs
| SHA-256 | Name | PT Fusion |
|---|---|---|
88717716e54b35682a28d673769475d439a31ee194c85dfc619a15ea93ab1280 |
S7Flip | Open ↗ |
e014dadf6d93b312b93e2fc857791c241692da4015da7a24a4d42a946551add2 |
S7Flip | Open ↗ |
2c57c1a39933514c63b5a7b585f5948ead04b65e4df96fb595ccda84208c4aa0 |
Edge.exe (ver 1) | Open ↗ |
f47502628708300840efe2771a3c5e7e9a631205512f0a2ee6382a00a92056e2 |
Edgev5.exe | Open ↗ |
#malware #win #ioc
@ptescalator
More in Malware
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- .exe .docm .xlsm
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…





