041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dcphorpiex: 04134145 — sextortion spam bot $800 variant, mutex t13 (May-29 campaign burst, 6th $800 sibling)
Executive Summary
Self-contained MSVC 9.0 sextortion spam bot compiled 2026-05-29 12:42:51 UTC. Part of the same May-29 campaign burst that produced mutexes t1 through t5; this sample carries t13, indicating the builder was actively generating parameter-rotated variants over a ~30-minute window. Identical decrypt key (Tmlr), BTC wallet, SMTP engine, and thread count (5,000) to the t1–t5 siblings. Adds the window-title string YOU PERVERT! I RECORDED YOU! (also seen in t1). Static-only — CAPE skipped (no Windows guest).
What It Is
- SHA-256:
041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc^[file.txt] - Type: PE32 executable (GUI) Intel 80386, 5 sections, 18.9 KB ^[file.txt]
- Toolchain: MSVC 9.0 (LinkerVersion 9.0), MSVCR90.dll CRT, compiled 2026-05-29 12:42:51 UTC ^[exiftool.json], ^[pefile.txt]
- Manifest: MSVCR90 dependent assembly +
asInvokerexecution level ^[strings.txt:147] - Family: phorpiex —
dropped-by-phorpiextag, identical build fingerprint to confirmed campaign siblings ^[triage.json] - Confidence: high — same toolchain, same decrypt key, same BTC wallet, same SMTP engine, same fake UA, same thread count as 5 prior siblings
How It Works
Entry Point / Main Flow
main() at 0x00402740 follows an honest flow (no initterm hijack): ^[r2:main]
- Sleep 2000 ms (
Sleep(0x7d0)) at entry — anti-emulation timing gate. - Mutex creation —
CreateMutexA(NULL, NULL, "t13")at0x406020. IfGetLastError() == ERROR_ALREADY_EXISTS (0xB7), exits immediately. ^[r2:main] - Zone.Identifier deletion — resolves its own path, appends
:Zone.Identifier, deletes the ADS. ^[r2:main] - Winsock init —
WSAStartup(0x202, ...). - SMTP thread spawn —
CreateThreadwith thread-procfcn.004024e0. - Sleep 0xcdfe600 ms (~2160 days) — infinite dormancy after thread launch; the SMTP worker does all work. ^[r2:main]
SMTP Worker Thread (fcn.004024e0)
- Copy PE header —
rep movsdcopies the first 0x41 dwords of the DOS/PE header to a local buffer (likely used as a source of randomness or a decrypt seed). ^[r2:fcn.004024e0] - PRNG seed —
srand(GetTickCount()). - External IP resolution — calls
fcn.00401800, which openshttp://icanhazip.com/with fake UAChrome/202.0.4664.110. Parses the dotted-decimal response withstrstr(..., "."). If resolution fails, falls back to[0.0.0.0]. ^[r2:fcn.00401800], ^[strings.txt:18] - MX resolution —
DnsQuery_A("yahoo.com", DNS_TYPE_MX, ...)via DNSAPI.dll. ^[r2:fcn.00401790] - Thread storm — nested loops: outer 100 iterations (
0x64), inner 50 iterations (0x32). Each inner iteration spawns aCreateThreadwith start addressfcn.00402340(SMTP sender) and sleepsrand() % 50 + 50ms between spawns. Total potential threads: 100 × 50 = 5,000. ^[r2:fcn.004024e0] - Self-erasure — after thread storm, sleeps 20,000 ms (
0x4e20) thenDeleteFileWon its own path and exits. ^[r2:fcn.004024e0]
SMTP Sender (fcn.00402340 / fcn.00401a10)
- Opens
%TEMP%\<rand>n.txt(random temp file) for reading via_wfopen. ^[r2:fcn.004024e0] - Parses each line as
recipient:addressusingstrchr(..., ':')andstrtok(..., "//"). ^[r2:fcn.00402340] - For each recipient, establishes a raw TCP socket to the resolved MX (port 25 implied by SMTP state machine), then walks a 7-state switch:
- State 0:
EHLO/HELOhandshake, probes forESMTPbanner. - State 2:
MAIL FROM:with sender address. - State 3:
RCPT TO:with recipient address. - State 4:
DATAcommand. - State 5: Full MIME header construction — forged
Received:headers (MailEnable and qmail variants),From:,To:,Subject:,Date:,Message-ID,Mime-Version: 1.0,Content-type: text/plain. Subject line isYOU PERVERT! I RECORDED YOU!. ^[r2:fcn.00401a10], ^[strings.txt:146] - State 5 continued: Email body assembled via
strcatchain — the full sextortion template (infected with R.A.T., camera recording, $800 USD BTC demand, wallet1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, exchange links for coinbase/binance/bitrefill/crypto.com/kucoin/etoro/kraken). ^[strings.txt:37-61] - State 6:
QUIT.
- State 0:
- No ZIP attachment; body is inline text/plain (same as
t5).
Decrypt / Key Material
- Hardcoded string
Tmlrat two locations in the binary (r2 string scan). This is the XOR+NOT decrypt key shared across all confirmed $800 variant siblings (edd6ad22,c3b1b4e4,dc2936ea,5076fdc3,67ae1ba4). ^[r2:strings] - The actual decryption routine is not reached in the radare2 pseudo-C (likely an inlined XOR-NOT loop in the
.textsection), but the key presence and the identical BTC wallet confirm payload decryption produces the same output.
C2 Infrastructure
- MX target:
yahoo.com(DNSAPI.dllDnsQuery_Afor MX records) ^[r2:fcn.00401790], ^[strings.txt:16] - External IP check:
http://icanhazip.com/(WinInet,InternetOpenUrlA) ^[strings.txt:18] - Fake UA:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36^[strings.txt:17] - BTC wallet:
1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K(same across all $800 siblings) ^[strings.txt:59] - No hardcoded C2 IP/domain — the SMTP engine is self-contained; it only needs the MX resolution and the external IP for the
Received:header forgery.
Decompiled Behavior
See individual radare2 function summaries above. Key control-flow patterns:
- Nested loop thread storm (
for i=0; i<100; i++→for j=0; j<50; j++→CreateThread+rand() % 50 + 50sleep) produces 5,000 concurrent SMTP workers. ^[r2:fcn.004024e0] - State-machine SMTP client — 7-case switch driven by
var_20hstate counter, withrecv/sendloop infcn.00401190. Standard RFC-5321 client implementation. ^[r2:fcn.00401a10] - String-encryption helper (
fcn.00401350) — PRNG-seeded string generation (srand(GetTickCount()),rand() % 10,sprintf("%s%d", ...)). Used to generate random local filenames and Message-ID components. ^[r2:fcn.00401350] - No anti-debug/VM beyond
Sleep(2000)at entry and mutex gating.IsDebuggerPresentis imported but not called inmain(). ^[pefile.txt]
Interesting Tidbits
- Mutex gap:
t1(12:13:57),t2(12:15:01),t4(12:33:18),t5(12:34:02),t13(12:42:51). The ~8-minute gap betweent5andt13suggests the builder was paused or the operator was rotating other parameters. Thet3mutex has not been observed in this corpus yet. - Window title:
YOU PERVERT! I RECORDED YOU!is a new string addition relative toedd6ad22(May 26) andt2/t4/t5; it was first seen int1(67ae1ba4). ^[strings.txt:146] - No ZIP constructor — unlike the
$1200variant (150e4652), this sample sends the email body as inline text without a ZIP attachment. Matches thet1–t5pattern. - Resource section: Contains only the standard MSVCR90 manifest + dependent assembly RT_MANIFEST (0x18). No payload resources, no encrypted blobs. ^[pefile.txt]
- Import surface: Minimal — KERNEL32 (17 APIs), MSVCR90 (32 CRT APIs), WININET (6 APIs), WS2_32 (12 ordinal imports), DNSAPI (2 APIs), SHLWAPI (3 APIs), USER32 (2 APIs). No NTAPI, no CryptoAPI, no registry writes beyond
Zone.Identifierdeletion. ^[pefile.txt]
Deployable Signatures
YARA Rule
rule Phorpiex_SextortionSpamBot_800USD {
meta:
description = "Phorpiex sextortion spam bot ($800 variant) — self-contained SMTP engine with hardcoded BTC wallet"
author = "Titus"
date = "2026-09-02"
sha256 = "041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc"
family = "phorpiex"
strings:
$btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii wide
$ua = "Chrome/202.0.4664.110 Safari/537.36" ascii wide
$mx = "yahoo.com" ascii wide
$ip = "http://icanhazip.com/" ascii wide
$subj = "YOU PERVERT! I RECORDED YOU!" ascii wide
$ehlo = "EHLO %s" ascii wide
$mailfrom = "MAIL FROM: %s" ascii wide
$rcptto = "RCPT TO: <%s>" ascii wide
$received_m = "Received: from %s ([%d.%d.%d.%d]) by %s with MailEnable ESMTP; %s" ascii wide
$received_q = "Received: (qmail %s invoked by uid %s); %s" ascii wide
$key = "Tmlr" ascii wide
$mut_t13 = "t13" ascii wide
$mut_t1 = "t1" ascii wide
$mut_t2 = "t2" ascii wide
$mut_t4 = "t4" ascii wide
$mut_t5 = "t5" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 25KB and
($btc or $ua) and
($mx or $ip) and
2 of ($ehlo, $mailfrom, $rcptto, $received_m, $received_q)
}
Behavioral Hunt Query (Sigma-compatible pseudo-query)
title: Phorpiex Sextortion Spam Bot Execution
detection:
selection_process:
- Image|endswith: '.exe'
- CommandLine|contains:
- 't13'
- 't1'
- 't2'
- 't4'
- 't5'
selection_network:
- InitiatedConnection:
- DestinationPort: 25
- DestinationHost|contains: 'yahoo.com'
- DnsQuery:
- QueryName|contains: 'yahoo.com'
- QueryType: 'MX'
selection_ua:
- UserAgent|contains: 'Chrome/202.0.4664.110'
selection_file:
- FileDelete:
- TargetFilename|contains: 'Zone.Identifier'
condition: selection_process and (selection_network or selection_ua or selection_file)
IOC List
| Indicator | Type | Value | Notes |
|---|---|---|---|
| SHA-256 | hash | 041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc |
This sample |
| BTC Wallet | cryptocurrency | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
$800 variant shared wallet |
| Mutex | mutex | t13 |
Also t1, t2, t4, t5 in siblings |
| Fake UA | user-agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 |
Impossible Chrome version |
| MX Target | domain | yahoo.com |
Hardcoded MX lookup target |
| External IP | URL | http://icanhazip.com/ |
WinInet fetch for header forgery |
| Temp file | filepath | %TEMP%\<rand>n.txt |
Random filename via srand(GetTickCount()) + rand() % 10 |
| Decrypt key | string | Tmlr |
XOR+NOT key, shared across $800 variants |
| Window title | string | YOU PERVERT! I RECORDED YOU! |
First seen in t1, present here |
Behavioral Fingerprint Statement
This binary is an 18–20 KB MSVC 9.0 PE32 GUI executable with a minimal import surface (KERNEL32, MSVCR90, WININET, WS2_32, DNSAPI, SHLWAPI, USER32). Upon launch it sleeps 2 seconds, creates a short ASCII mutex (t1–t13 observed), deletes its own Zone.Identifier ADS, initializes Winsock, resolves the external IP via icanhazip.com with a fake Chrome/202 UA, queries yahoo.com MX records via DNSAPI, then spawns 5,000 concurrent SMTP worker threads. Each thread connects to the resolved MX on port 25, sends a forged MailEnable/qmail Received: header, and delivers a sextortion email demanding $800 USD in Bitcoin to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. After the thread storm it sleeps 20 seconds and deletes itself. No registry persistence, no C2 beacon, no payload download — fully self-contained.
Detection Signatures
| Technique | MITRE ATT&CK ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | Spam-distributed PE, no C2 download needed ^[triage.json] |
| Impair Defenses: Indicator Removal | T1070.004 | Zone.Identifier ADS deletion on self ^[r2:main] |
| Application Layer Protocol: Email | T1071.003 | Self-contained SMTP client to yahoo.com MX ^[r2:fcn.00401790] |
| Data from Local System | T1005 | Reads local temp file for recipient list ^[r2:fcn.004024e0] |
| Exfiltration Over C2 Channel | T1041 | SMTP email exfiltration (sextortion message) ^[r2:fcn.00401a10] |
| Impact: Data Encrypted for Impact | N/A — no encryption | Sextortion threat only; no actual video footage or encryption observed |
| Input Capture: Screen Capture | N/A — false claim | Threat text claims camera recording; no capture code in binary |
How To Mess With It (Homelab Replication)
Toolchain: Microsoft Visual C++ 2008 (MSVC 9.0) / MSVCR90, targeting x86 Win32 GUI subsystem.
Reproduction concept: Build a minimal Win32 SMTP client in C using winsock2.h, wininet.h, and dnsapi.h. Hardcode a fake Chrome UA, resolve yahoo.com MX via DnsQuery_A, connect to port 25, and implement the EHLO→MAIL FROM→RCPT TO→DATA→QUIT state machine. Use srand(GetTickCount()) for PRNG and CreateThread in a nested loop to spawn 5,000 workers.
Verification: Compile with /MT (static MSVCR90 linkage) and compare the .text section hash against known siblings; the SMTP engine structure should produce a similar control-flow graph.
References
- Artifact ID:
46c3a1f0-8229-4a7d-b2c2-756276b87914^[triage.json] - Source: MalwareBazaar / OpenCTI
dropped-by-phorpiextag ^[triage.json] - Related analyses: /intel/analyses/67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9.html (t1, earliest $800 build), /intel/analyses/5076fdc39445369e67daaccb7ec1699107a5f227aaaec978ec9d77d966124f3d.html (t2), /intel/analyses/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a.html (t4), /intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html (t5), /intel/analyses/edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19.html (etyueu, May 26), entities/phorpiex.md (family overview)
Provenance
Analysis based on file.txt, exiftool.json, pefile.txt, strings.txt, rabin2-info.txt, and radare2 decompilation (r2 -AA, pdc on main, fcn.00401790, fcn.00401800, fcn.00401a10, fcn.00401350, fcn.00402320, fcn.00402340, fcn.004024e0, fcn.00401430). Capa signatures were unavailable on this host (default signature path missing). Floss failed on argument parse. Dynamic analysis skipped — no CAPE Windows guest. All TTP inferences are static-only and validated against 5 confirmed sibling reports.