Phorpiex
A crimeware botnet/dropper family active since at least 2016. Known to distribute ransomware, cryptocurrency miners, and other commodity payloads via spam campaigns. The label originates from MalwareBazaar/OpenCTI where multiple samples are tagged dropped-by-phorpiex. The family label itself is an umbrella: samples vary widely in size (10–300 KB), build toolchain, and payload (static-only analysis shows this is not a single-codebase cluster).
Observed Build Patterns
- MSVC C++ x32 stubs linked statically against MSVCR90.dll, mimicking
Microsoft Screen Saverbinaries ^[/intel/analyses/755bed077773b6cc7bea81ff624ded0554784accd5745d734742dafb73833b6b.html] - Go droppers with packed UPX overlays (observed in sibling
dropped-by-phorpiexsamples) - Minimal IAT — only a handful of KERNEL32 and MSVCR90 imports; actual payload imported via runtime resolution or reflective injection
Observed Deploy / ATT&CK
- T1204.002 — User Execution: Malicious File — spam-distributed PEs with social-engineered names
- T1053 — Scheduled Task/Job (inferred from historical reporting for Phorpiex)
- Payload delivery mechanism: runtime-decoded shellcode or PE via phorpiex-loader-initterm-hijack ^[/intel/analyses/755bed077773b6cc7bea81ff624ded0554784accd5745d734742dafb73833b6b.html]
- New variant: cplapplet-png-payload-dropper — x64 CPlApplet that expects a
payload.pngcompanion file, decrypts/decompresses a second-stage DLL, self-erases, and executes. May 2026 build.
Capabilities
parasitic-pe-section-append(new —.zerosection, entry-point patch,ImageBase=0xdeadsentinel)peb-walking-api-hash-resolution(new — custom hash constants, export-name iteration)shellcode-ntdll-scratchpad-copy(new — intermediate RX copy before victim write)twiztpeinf-mutex-gatingwindrx-marker-filenodrives-registry-evasiondrive-blacklist-skipinitterm-hijack-payload-decoderthin-msvc9-downloaderdual-fetch-wininet-urlmonzone-identifier-ads-deletionrtlgversion-build-gatingmarker-file-mutex-gatingtemp-random-filename-stagingx64-progfiles-checkchrome-128-ua-masqueradepeinf-xmr-xmrget-grab-payload-chainhttp-cleartext-c2anti-debug-isdebuggerpresentiat-minimization-runtime-api-resolutionscreensaver-masquerademsvcr90-static-crtzip-header-manual-assemblysmtp-self-spoofinghttp-chrome-ua-downloadersexttortion-email-templatebitcoin-wallet-hardcodedthread-storm-spam-deliveryxor-not-string-decryptiondns-mx-resolutionmime-multipart-zip-attachmentexternal-ip-http-checktemp-file-spam-stagingzone-identifier-deletionmutex-single-instancecplapplet-png-payload-dropper(new x64 variant, May 2026)api-name-xor-decryptioncustom-byte-pair-decompressionself-text-erasuregettickcount-anti-emulation-loopmarker-file-mutex-gatingwininet-urlmon-dual-downloadcreateprocessw-create_no_windowrtlgversion-build-gatingx64-arch-check-progfiles-x86sextortion-500-usd-variant(May 2026; earliest cluster build)sextortion-1200-usd-variant(May 2026; standard cluster build)sextortion-800-usd-variant(May 2026; sibling of 1200 variant, updated Chrome UA, mutexetyueu)gettickcount-anti-emulation-loop13-14-peinf-xmr-xmrget-payload-chain(earliest campaign build, May 2026)business-app-masquerade-execution(new May 2026 variant: Slack, Teams, Zoom, SAP GUI, Power BI, Tableau)ip-api-geolocation-gatingcountry-code-cn-exclusionzone-identifier-ads-deletionchrome-7775543322-ua-masqueradedual-ua-rotation-chrome-plausible-fallback(new —e50d0e5aadds Chrome/93.0.4577.82 alongside the impossible-version UA)business-app-masquerade-expanded-url-list(new —e50d0e5acarries 31 payload URLs vs 11 in0371fbbf)sextortion-800-usd-variant-mutex-t4(new —dc2936ea, twin build ofc3b1b4e4, mutext4, compiled 44 seconds earlier, same campaign burst)sextortion-800-usd-variant-mutex-t5(new —c3b1b4e4, mutext5, identical SMTP engine and decrypt keyTmlr, 5,000-thread dispatch,yahoo.comMX query, self-contained WinInet+WS2_32 spam bot)sextortion-800-usd-variant-mutex-t6(new —3bfbfb35, mutext6, compiled 12:34:48 UTC May 29, betweent5(12:34:02) andt7(12:36:22), sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window titleYOU PERVERT! I RECORDED YOU!. Fills the ~1m46s gap, confirming sub-minute builder rotation.)sextortion-800-usd-variant-mutex-t13(new —04134145, mutext13, compiled 12:42:51 UTC, ~8 minutes aftert5; adds window-title stringYOU PERVERT! I RECORDED YOU!, sameTmlrkey, same BTC wallet, same 5,000-thread SMTP engine. Confirms active builder parameter rotation acrosst1–t13in a ~30-minute campaign burst.)sextortion-800-usd-variant-mutex-t2(new —5076fdc3, mutext2, earliest confirmed build in $800 sub-cluster at 12:15:01 UTC, predatest4/t5twins by ~18 minutes, identical decrypt key and BTC wallet)sextortion-800-usd-variant-mutex-t1(new —67ae1ba4, mutext1, earliest build in the $800 campaign burst at 12:13:57 UTC, predatest2by ~1 minute; adds window title stringYOU PERVERT! I RECORDED YOU!)sextortion-800-usd-variant-mutex-t7(new —49740d89, mutext7, compiled 12:36:22 UTC, ~22 minutes aftert1build, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window titleYOU PERVERT! I RECORDED YOU!)sextortion-800-usd-variant-mutex-t12(new —b221a625, mutext12, compiled 12:41:46 UTC May 29, fills gap betweent7andt13, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window titleYOU PERVERT! I RECORDED YOU!)sextortion-800-usd-variant-mutex-t11(new —cbc59001, mutext11, compiled 12:40:35 UTC May 29, betweent7(12:36:22) andt12(12:41:46), sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window titleYOU PERVERT! I RECORDED YOU!)sextortion-800-usd-variant-mutex-t10(new —724ec6b8, mutext10, compiled 12:39:58 UTC May 29, betweent7(12:36:22) andt11(12:40:35), sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window titleYOU PERVERT! I RECORDED YOU!. Fills the ~3.5-minute gap in the campaign burst, confirming continuous builder rotation.)sextortion-800-usd-variant-mutex-t9(new —8f257c0e, mutext9, compiled 12:37:51 UTC May 29, betweent7(12:36:22) andt10(12:39:58), sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window titleYOU PERVERT! I RECORDED YOU!. Fills the ~1.5-minute gap betweent7andt10, confirming continuous builder rotation.)sextortion-800-usd-variant-mutex-523535(new —bb0a8440, mutex523535, compiled 12:02:34 UTC May 29, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window titleYOU PERVERT! I RECORDED YOU!. Delta: new Chrome/202.0.4664.110 UA (prior siblings used Chrome/128 or Chrome/7775543322), numeric mutex breaks thet*naming pattern observed int1–t13sub-cluster)sequential-1-12-payload-naming(new —ee83f1e8, thin downloader with1.exe–12.exesequential naming, replacinglb*convention)rtlgetversion-windows11-build-gate(new —ee83f1e8, gatesxmrget.exeon build >= 22000, first thin-downloader sibling with this gate)thin-downloader-15-payload(confirmed —ee83f1e8, 15 URLs: 1.exe–12.exe, xmr.exe, xmrget.exe, grab.exe)
Notable Analyses
-
x32 MSVC9 stub / MSVCR90 dropper (e.g.
755bed07) — 21 KB, pre-main payload throughinitterm, masquerades asMicrosoft Screen Saver -
Go/UPX droppers (siblings in corpus) — much larger, UPX-packed
-
Sextortion spam bot — $500 variant (
bb77ef06) — 19 KB, earliest May-22 campaign build (13:05 UTC), mutexefaefaef, hardcoded BTC1NXeVuYtcVwJ1do2EUS6qJS8FQSPFabxeE, Chrome/202 UA, $500 ransom demand. Precedes the $1200 builds by ~4 hours. ^[/intel/analyses/bb77ef06de83dc5e450572c04f69224c44786bda5eadc9e7a698dc4ef1445edf.html] -
Sextortion spam bot — $1200 variant (e.g.
150e4652) — 23 KB, self-contained SMTP engine + ZIP constructor + hardcoded BTC wallet -
Sextortion spam bot sibling (e.g.
17960bcb) — 24 KB, same build day, identical payload architecture, mutexww88ww8w8 -
Sextortion spam bot — $800 variant (
edd6ad22) — 18.9 KB, compiled 2026-05-26 06:02:43 UTC, same SMTP engine and BTC wallet as150e4652. Delta: $800 demand (vs $1200), Chrome/202 UA, mutexetyueu. Confirms campaign-parameter rotation across builds. ^[/intel/analyses/edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19.html] -
Thin HTTP downloader (
6b8527a7) — 10 KB, MSVC9, dual WinInet+URLMon fetch, marker-file gating,Zone.Identifierdeletion, x64+build gating forxmr.exe/xmrget.exe. Noinittermhijack; honestmain()flow. 2026-05-22 16:56 UTC -
Thin HTTP downloader sibling (
025f5798) — 10 KB, confirmed campaign sibling compiled 3h51m earlier (2026-05-22 13:06 UTC). Same C2 (178.16.54.109), same gating, same dual-fetch. Delta: omits15.exepayload present in later build. -
Thin HTTP downloader sibling — peinf/xmr/xmrget chain (
2ffc3203) — 10 KB, compiled 2026-05-22 07:45:34 UTC. Same C2, same gating, same dual-fetch. Delta: payload name rotation —peinf.exereplaces15.exe; adds third-stagexmrget.exe. Confirms active C2 payload rotation within the same campaign window. -
Earliest thin HTTP downloader sibling (
32f29422) — 10 KB, compiled 2026-05-22 06:19:01 UTC. Same C2, same gating, same dual-fetch. Delta: earliest build; addsgrab.exeas fallback payload when the primary peinf/xmr/xmrget chain fails. Honestmain()flow; noinittermhijack. -
Ultra-early thin HTTP downloader sibling — 13/14 chain (
f67e429d) — 10 KB, compiled 2026-05-21 23:03:35 UTC. Earliest known build in the campaign window, predating32f29422by ~7 hours. Same C2, same toolchain. Deltas: five payload URLs (13.exe, 14.exe, peinf.exe, xmr.exe, xmrget.exe); dual filesystem marker gates (d333...txtandf3f3...txt); both RtlGetVersion and x64 Program-Files checks present. -
Thin HTTP downloader sibling — 15-payload variant (
5549d978e2e0) — 11.8 KB, compiled 2026-05-26 10:32:54 UTC. Same C2 (178.16.54.109), same MSVC9 toolchain, same dual-fetch gating. Delta: largest payload list in campaign (15 URLs: 1.exe–14.exe, peinf.exe, xmr.exe, xmrget.exe, grab.exe); no15.exeobserved. Confirms active payload rotation within the campaign window. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/5549d978e2e00768fc99d95bd7644dfebacc261284e3b19a79e6e4c1f320fa3a.html] -
Business-app masquerade downloader (
9570038453) — 113 KB, compiled 2026-05-26 07:35:20 UTC. Largest downloader in the campaign (~10× the thin stubs). C++ STL bloat, WinInet-only (no URLMon fallback observed),ip-api.com/jsongeolocation gating with explicit CN exclusion,%TEMP%\w4f4wffwf.txtmarker-file gate, random-numeric filename staging (%d%d.exe),Zone.IdentifierADS deletion, and six hardcoded masquerade names (slack.exe,Teams.exe,Zoom.exe,sapgui.exe,PBIDesktop.exe,tableau.exe) passed toShellExecuteW. Fake UA:Chrome/7775543322.0.0.0. Same C2 (178.16.54.109) as thin-downloader cluster. ^[/intel/analyses/9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f.html] -
Business-app masquerade downloader sibling (
0371fbbf) — 113 KB, compiled 2026-05-29 10:10:01 UTC. Confirmed third business-app masquerade sibling (same size, same toolchain, same six masquerade names, samew4f4wffwf.txtgate, same CN geolocation exclusion). Deltas: addslkdomain.exeas a primary payload URL and ten sequentially-named payloads (lb1.exe–lb10.exe), blending the business-app masquerade pattern with the thin-downloaderlb*payload-naming convention. Same fake UA (Chrome/7775543322.0.0.0). Same C2 (178.16.54.109). Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3.html] -
Parasitic file infector — TWIZTPEINF variant (
d69d4497) — 22 KB, compiled 2026-05-29 11:32:30 UTC. First parasitic infector observed in the campaign. Appends a.zerosection to every*.exeon visible drives, patches entry point, setsImageBase=0xdeadinfection sentinel. Payload shellcode uses PEB-walking API hash resolution (fcn.00401bc0) and downloads stage-2 viaURLDownloadToFileW. MutexTWIZTPEINF, marker file%appdata%\windrx.txt, registryNoDrivesgating. Siblinge0de4e3c...is a byte-identical twin (same binary, different OpenCTI artifact ID). Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html] -
Parasitic file infector twin (
e0de4e3c) — byte-identical tod69d4497; sameTWIZTPEINFmarker, same C2 (178.16.54.109/32.exe), same build fingerprint. Confirms OpenCTI pipeline ingested the same sample twice under distinct artifact records. Static-only. ^[/intel/analyses/e0de4e3c9dee9877c78832ac9ebe3fbd2de45026896d6fc2a5ca12f6b588a29a.html] -
Business-app masquerade downloader — expanded payload list (
e50d0e5a) — 114 KB, compiled 2026-05-29 11:37:19 UTC. Fourth confirmed business-app masquerade sibling. Same six masquerade names, samew4f4wffwf.txtgate, same CN geolocation exclusion, same fake UA (Chrome/7775543322.0.0.0). Deltas: expands payload URL list from 11 to 31 (lkdomain.exe+lb1.exe–lb30.exe); adds a second fake UA (Chrome/93.0.4577.82); dropsf3f3g3df.txt/NoDrives/OUTLOOKFOUNDindicators seen in0371fbbf. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/e50d0e5abf23d4cdb1021c0db51572a785150f0a797fbe57b203b54c26c086e1.html] -
Sextortion spam bot — $800 variant, mutex
t5(c3b1b4e4) — 18.9 KB, compiled 2026-05-29 12:34:02 UTC. Fifth confirmed sextortion sibling in the $800 sub-cluster (preceded byedd6ad22). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine + ZIP-less email body, sameTmlrXOR+NOT decrypt key. Deltas: mutext5(new), BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, thread count 5,000 (highest in cluster), no ZIP attachment. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html] -
Sextortion spam bot — $800 variant, mutex
t4(twin oft5) (dc2936ea) — 18.9 KB, compiled 2026-05-29 12:33:18 UTC. Twin build ofc3b1b4e4, compiled 44 seconds earlier in the same campaign burst. Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine + ZIP-less email body, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutext4(vst5). Confirms campaign-level parameter rotation, not code change. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a.html] -
Sextortion spam bot — $800 variant, mutex
t2(earliest confirmed build) (5076fdc3) — 18.9 KB, compiled 2026-05-29 12:15:01 UTC. Earliest confirmed build in the $800 sub-cluster, predatingt4/t5twins by ~18 minutes. Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutext2(new). Confirms the builder was generating mutex-rotated variants in a continuous campaign burst. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/5076fdc39445369e67daaccb7ec1699107a5f227aaaec978ec9d77d966124f3d.html] -
Sextortion spam bot — $800 variant, mutex
t1(earliest build in burst) (67ae1ba4) — 18.9 KB, compiled 2026-05-29 12:13:57 UTC. Predates thet2build by ~1 minute, making it the earliest confirmed build in the $800 campaign burst. Same MSVC9/MSVCR90 toolchain, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine. Delta: mutext1(new); adds window title stringYOU PERVERT! I RECORDED YOU!not seen in prior siblings. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9.html] -
Thin HTTP downloader — 15-payload sequential naming variant (
ee83f1e8) — 11 KB, compiled 2026-05-29 12:16:54 UTC. New thin-downloader morph: sequential1.exe–12.exepayload naming (replacinglb*andpeinfconventions); same dual WinInet+URLMon fetch, samed333...txt/f3f3...txtmarker-file gating, sameZone.IdentifierADS deletion, sameChrome/128.0.0.0fake UA. Delta: addsRtlGetVersionWindows 11 build gate (build >= 22000) forxmrget.exefetch — first thin-downloader sibling with this gate. Same C2 (178.16.54.109). Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/ee83f1e835ae321ac303708151a85bdf35ff64b09eb706458e901bc77d40c83c.html] -
Sextortion spam bot — $800 variant, mutex
t13(sixth confirmed $800 sibling) (04134145) — 18.9 KB, compiled 2026-05-29 12:42:51 UTC. Sixth confirmed sibling in the $800 sub-cluster (preceded byt1–t5). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine + ZIP-less email body, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Deltas: mutext13(new); adds window title stringYOU PERVERT! I RECORDED YOU!(also seen int1); compiled ~8 minutes aftert5, confirming active builder parameter rotation across a ~30-minute campaign burst. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc.html] -
Sextortion spam bot — $800 variant, mutex
t7(seventh confirmed $800 sibling) (49740d89) — 18.9 KB, compiled 2026-05-29 12:36:22 UTC. Seventh confirmed sibling in the $800 sub-cluster (betweent5andt13). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutext7(new); window titleYOU PERVERT! I RECORDED YOU!. Compiled ~22 minutes after thet1earliest build, fitting the continuous campaign burst timeline. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031.html] -
Sextortion spam bot — $800 variant, mutex
t12(eighth confirmed $800 sibling) (b221a625) — 18.9 KB, compiled 2026-05-29 12:41:46 UTC. Eighth confirmed sibling in the $800 sub-cluster, betweent7(12:36:22) andt13(12:42:51). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutext12(new); fills the ~7-minute gap betweent7andt13, confirming continuous builder rotation. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95.html] -
Sextortion spam bot — $800 variant, mutex
t11(ninth confirmed $800 sibling) (cbc59001) — 18.9 KB, compiled 2026-05-29 12:40:35 UTC. Ninth confirmed sibling in the $800 sub-cluster, betweent7(12:36:22) andt12(12:41:46). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutext11(new); compiled ~4 minutes aftert7, confirming continuous builder rotation. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000.html] -
Sextortion spam bot — $800 variant, mutex
t9(tenth confirmed $800 sibling) (8f257c0e) — 18.9 KB, compiled 2026-05-29 12:37:51 UTC. Tenth confirmed sibling in the $800 sub-cluster, betweent7(12:36:22) andt10(12:39:58). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutext9(new); fills the ~1.5-minute gap betweent7andt10, confirming continuous builder rotation. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c.html] -
Sextortion spam bot — $800 variant, mutex
t8(eleventh confirmed $800 sibling) (cff535e6) — 18.9 KB, compiled 2026-05-29 12:37:13 UTC. Eleventh confirmed sibling in the $800 sub-cluster, betweent7(12:36:22) andt9(12:37:51). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, sameTmlrXOR+NOT decrypt key, same BTC wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutext8(new); fills the ~51-second gap betweent7andt9, confirming continuous builder rotation at sub-minute granularity. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556.html]
Notes
No deep-analysis report existed for any dropped-by-phorpiex sample in the corpus prior to this one. The label aggregates disparate builders under a single campaign umbrella. Individual samples should be characterized by their actual build/behavior rather than by the umbrella label alone.
Related Analyses
- /intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html — sextortion spam bot $800 variant, mutex
t5, 5,000 threads - /intel/analyses/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a.html — sextortion spam bot $800 variant, mutex
t4(twin build, 44 seconds earlier), 5,000 threads - /intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html — sextortion spam bot with SMTP engine, ZIP constructor, and hardcoded BTC wallet
- /intel/analyses/755bed077773b6cc7bea81ff624ded0554784accd5745d734742dafb73833b6b.html — screensaver masquerade stub with
.rsrcpayload staging - /intel/analyses/17960bcb0d7fe57fac3a286fe7e8ba9b53783fdd53a2ef1132ae4d302d2c18f3.html — sextortion spam bot sibling (same build timestamp)
- /intel/analyses/edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19.html — sextortion spam bot $800 variant (mutex
etyueu) - /intel/analyses/49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031.html — sextortion spam bot $800 variant, mutex
t7, 12:36:22 UTC - /intel/analyses/b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95.html — sextortion spam bot $800 variant, mutex
t12, 12:41:46 UTC - /intel/analyses/bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49.html — sextortion spam bot $800 variant, mutex
523535, numeric mutex breakingt*pattern - /intel/analyses/cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000.html — sextortion spam bot $800 variant, mutex
t11, 12:40:35 UTC - /intel/analyses/8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c.html — sextortion spam bot $800 variant, mutex
t9, 12:37:51 UTC - /intel/analyses/cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556.html — sextortion spam bot $800 variant, mutex
t8, 12:37:13 UTC - /intel/analyses/724ec6b8d24acad8b84cc87b7f77a8d2cf25e3a6d1d1dcadbd0b94b5ef9d8a8f.html — sextortion spam bot $800 variant, mutex
t10, 12:39:58 UTC - /intel/analyses/ee83f1e835ae321ac303708151a85bdf35ff64b09eb706458e901bc77d40c83c.html — thin downloader, sequential payload naming, RtlGetVersion Windows 11 gate