Phorpiex Spam Bot: Six Sextortion Builds, a Port-25 Kill Switch and One Bitcoin Wallet

0. Preface These samples were pulled from a Phorpiex drop server — a bare open directory on 178.16.54.109 serving numbered executables at /1.exe through /6.exe. A shell loop asked for 2.exe up to 13.exe; everything from 7.exe onward came back empty, so the live payload set at collection time was six files. 1.exe was retrieved separately. All six are the same program. The .text and .rdata sections are byte-identical across every build; the only differences are the PE timestamp, the PE checksum, and eleven bytes of ....

September 13, 2026 · 19 min

My Malware Analysis Journey

My Learning Process I’ll be documenting my journey as I learn malware analysis, sharing: Challenges I encounter and how I overcome them New techniques I discover and practice Tools I explore and my honest reviews Mistakes I make and lessons learned (because we all make them!) Hands-On Analysis This blog will feature: Step-by-step walkthroughs of malware samples Tool tutorials with practical examples Lab setup guides for safe analysis environments Real-world case studies from my analysis work Knowledge Sharing As I learn, I’ll share:...

September 11, 2026 · 1 min

RemusStealer: An OLEACC Sideloading Shim, Guard-Page Execution and an Ethereum Dead Drop

0. Preface This sample arrived in a folder named RemusStealer. Nothing in the chain calls itself that, and I found no internal marker that confirms the family — treat the name as a filing label, not an attribution. What the sample is, unambiguously, is a four-stage loader ending in an infostealer with screen-capture, hidden-desktop and browser-credential capability. Two things make it worth the writeup. First, the loader’s entry mechanism: it does not call anything from its own export table....

September 11, 2026 · 12 min

XHOMEM01: A CLR-Hosting Crypter and a Reactor-over-Reactor .NET Stealer

0. Preface This sample was pulled from https://abilityindisabilityindia.org/rock.exe, live and serving at the time of analysis. It arrived in a folder named purelogs-stealer. That label is plausible and, by the end, well supported — but still not proven. Nothing in any of the three stages contains the string “PureLogs”, a family mutex, or a version banner. What the final stage does provide is a behavioural profile that fits closely: a ....

September 11, 2026 · 30 min

SnappyClient: A Fake Cloudflare ClickFix Lure to a DLL-Sideloaded RAT

0. Preface This sample arrived in a folder named SnappyClient. Do not read too much into the name — nothing in the chain calls itself that, and the operator’s own build strings use two different markers, DidixResearch and GrelixDataset. Treat “SnappyClient” as a filing label, not a family attribution. The chain is a ClickFix delivery — a fake Cloudflare “verify you are human” page that plants a command on the victim’s clipboard — leading through a heavily-obfuscated PowerShell downloader to a DLL-sideloading kit built around a legitimately-signed application, and finally to a RAT that runs inside the memory of a Microsoft-signed Windows DLL via module stomping....

September 11, 2026 · 10 min

Brython Stager: A 25 KB rundll32 Downloader Filed Under Vidar

0. Preface This sample arrived in a folder named vidar-sample. It is not Vidar. It contains no credential access, no browser or wallet enumeration, no exfiltration protocol, and no configuration blob — none of the machinery that makes a stealer a stealer. It is a 25 KB downloader whose entire job is to fetch one DLL and hand it to rundll32.exe. The label is probably not wrong so much as one step early....

September 10, 2026 · 17 min