# ClockLauncher PHP Backdoor: php-win.exe LOLBin Abuse for Invisible Execution, LocalSystem Persistence, and EDR-Evasive RMM Deployment

> A PHP-based backdoor uncovered during a DFIR engagement abuses php-win.exe (the GUI-marked PHP interpreter) to run a malicious PHP script (5.php) completely invisibly. The implant beacons to a cutt.ly shortened URL with CURLOPT_NOBODY, extracts a payload from the utm_source value in the HTTP Location header, URL-decodes and double-Base64-decodes it, and executes it via eval(). It persists as a boot-triggered scheduled task (ClockLauncher) and a Windows service (ClockSystemService) running as LocalSystem, and was used to silently install remote-management agents (Atera, Bluetrait) while evading the tested EDR.

- **Published:** 2026-06-22T00:00:00Z
- **Last reviewed:** 2026-06-22T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0903
- **ID:** TL-2026-0903
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

During an incident-response engagement documented by Stephan Berger (dfir.ch), responders identified a stealthy PHP backdoor used for command-and-control and follow-on tool deployment on a compromised Windows host. The intrusion centered on a scheduled task (ClockLauncher) that executed a batch file (run-clock.bat) which in turn launched php-win.exe against a PHP backdoor script named 5.php, all staged under C:\Windows\Temp\{0B1281F3-C9BC-4B85-AD92-0803ED04208F}\php_2\.

The core evasion primitive is the choice of php-win.exe rather than php.exe. The two interpreters are functionally identical, but php-win.exe is compiled and marked as a 'GUI application' rather than a 'console' application in its PE subsystem, so it runs with no visible window and produces no console output. Combined with execution from a randomly-GUID-named Temp subfolder and a benign-sounding 'Clock' naming scheme for the task and service, this kept the activity low-visibility. In the responders' testing, one EDR raised only a single medium-severity alert for an attempted Atera installation and generated zero alerts for the PHP execution itself or for the Bluetrait agent installation.

The backdoor's C2 logic is a header-channel design. Using cURL, the script issues a request to a hardcoded cutt.ly shortened URL (https://cutt.ly/praXEwzs) with CURLOPT_NOBODY enabled (HEAD-style request, headers only) and CURLOPT_FOLLOWLOCATION enabled. It then scans the returned HTTP headers for a line containing 'utm_source=', extracts that value from the Location/redirect header, applies urldecode() followed by a double base64_decode(), and runs the resulting PHP via eval('?>' . $response). This effectively hides the operator's command/second-stage code inside what looks like an ordinary analytics tracking parameter on a redirect. Beaconing cadence is randomized with sleep(rand(10, 30)), introducing 10-30 second jitter between requests to blend with normal traffic and frustrate signature-based timing detection.

The operators used the implant as a delivery mechanism for legitimate remote-monitoring-and-management (RMM) software, a common tradecraft pattern for durable, EDR-tolerated remote access. An attempted Atera deployment was observed, and a Bluetrait MSP agent was downloaded from https://dfir.bluetrait.io/simple/msp_download_agent?os=windows&access_key=c236ddf4-a046-4b5f-ab80-868565498ca2 and installed silently (msiexec /i setup.msi /qn). A Pastebin raw URL (https://pastebin.com/raw/HZTqJLAs) was used as a test payload host during analysis. Bluetrait installation generated a Windows Security Event ID 7045 (service installation) artifact.

Persistence and privilege are anchored at the highest level: the ClockLauncher scheduled task (C:\Windows\System32\Tasks\ClockLauncher) runs at boot, at RunLevel HighestAvailable, as SYSTEM (S-1-5-18); task XML shows a start boundary of 2025-04-01 and a registration/creation timestamp of 2025-10-01 05:44:26 UTC by a COMPANY\ADM administrative account. The companion ClockSystemService Windows service is configured to run as LocalSystem (it was stopped at the time of investigation). The report attributes the campaign to no known threat actor and identifies no associated CVE; severity is assessed HIGH on the basis of confirmed LocalSystem persistence, defense evasion, and EDR-evasive remote-access tooling. Recommended hunting includes reviewing AutoRuns/scheduled-task inventories for suspicious boot tasks and watching for php-win.exe spawned by cmd.exe/batch files from non-standard paths.

## MITRE ATT&CK

- T1059 Command and Scripting Interpreter
- T1059.003 Windows Command Shell
- T1569.002 Service Execution
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1543.003 Windows Service
- T1053.005 Scheduled Task
- T1543.003 Windows Service
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1564 Hide Artifacts
- T1071.001 Web Protocols
- T1102 Web Service
- T1132.001 Standard Encoding
- T1105 Ingress Tool Transfer
- T1219 Remote Access Tools

## Sources

- [Dissection of a PHP Backdoor leveraging php-win.exe](https://dfir.ch/posts/dissection_php_backdoor/)
- [Dissection of a PHP Backdoor leveraging PHP-win.exe (Hacker News discussion)](https://news.ycombinator.com/item?id=45951730)
- [MITRE ATT&CK T1053.005 Scheduled Task](https://attack.mitre.org/techniques/T1053/005/)
- [MITRE ATT&CK T1543.003 Create or Modify System Process: Windows Service](https://attack.mitre.org/techniques/T1543/003/)
- [MITRE ATT&CK T1219 Remote Access Software](https://attack.mitre.org/techniques/T1219/)
- [MITRE ATT&CK T1140 Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140/)
- [PHP command line: php-win.exe (GUI subsystem interpreter)](https://www.php.net/manual/en/features.commandline.usage.php)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0903
