typeanalysisfamilyphorpiexconfidencehighcreated2026-09-02updated2026-09-02pemalware-familyloadermalware-bazaarc2exfiltrationimpactsextortionspamsmtp
SHA-256: 041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc

phorpiex: 04134145 — sextortion spam bot $800 variant, mutex t13 (May-29 campaign burst, 6th $800 sibling)

Executive Summary

Self-contained MSVC 9.0 sextortion spam bot compiled 2026-05-29 12:42:51 UTC. Part of the same May-29 campaign burst that produced mutexes t1 through t5; this sample carries t13, indicating the builder was actively generating parameter-rotated variants over a ~30-minute window. Identical decrypt key (Tmlr), BTC wallet, SMTP engine, and thread count (5,000) to the t1–t5 siblings. Adds the window-title string YOU PERVERT! I RECORDED YOU! (also seen in t1). Static-only — CAPE skipped (no Windows guest).

What It Is

  • SHA-256: 041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc ^[file.txt]
  • Type: PE32 executable (GUI) Intel 80386, 5 sections, 18.9 KB ^[file.txt]
  • Toolchain: MSVC 9.0 (LinkerVersion 9.0), MSVCR90.dll CRT, compiled 2026-05-29 12:42:51 UTC ^[exiftool.json], ^[pefile.txt]
  • Manifest: MSVCR90 dependent assembly + asInvoker execution level ^[strings.txt:147]
  • Family: phorpiex — dropped-by-phorpiex tag, identical build fingerprint to confirmed campaign siblings ^[triage.json]
  • Confidence: high — same toolchain, same decrypt key, same BTC wallet, same SMTP engine, same fake UA, same thread count as 5 prior siblings

How It Works

Entry Point / Main Flow

main() at 0x00402740 follows an honest flow (no initterm hijack): ^[r2:main]

  1. Sleep 2000 ms (Sleep(0x7d0)) at entry — anti-emulation timing gate.
  2. Mutex creation — CreateMutexA(NULL, NULL, "t13") at 0x406020. If GetLastError() == ERROR_ALREADY_EXISTS (0xB7), exits immediately. ^[r2:main]
  3. Zone.Identifier deletion — resolves its own path, appends :Zone.Identifier, deletes the ADS. ^[r2:main]
  4. Winsock init — WSAStartup(0x202, ...).
  5. SMTP thread spawn — CreateThread with thread-proc fcn.004024e0.
  6. Sleep 0xcdfe600 ms (~2160 days) — infinite dormancy after thread launch; the SMTP worker does all work. ^[r2:main]

SMTP Worker Thread (fcn.004024e0)

  1. Copy PE header — rep movsd copies the first 0x41 dwords of the DOS/PE header to a local buffer (likely used as a source of randomness or a decrypt seed). ^[r2:fcn.004024e0]
  2. PRNG seed — srand(GetTickCount()).
  3. External IP resolution — calls fcn.00401800, which opens http://icanhazip.com/ with fake UA Chrome/202.0.4664.110. Parses the dotted-decimal response with strstr(..., "."). If resolution fails, falls back to [0.0.0.0]. ^[r2:fcn.00401800], ^[strings.txt:18]
  4. MX resolution — DnsQuery_A("yahoo.com", DNS_TYPE_MX, ...) via DNSAPI.dll. ^[r2:fcn.00401790]
  5. Thread storm — nested loops: outer 100 iterations (0x64), inner 50 iterations (0x32). Each inner iteration spawns a CreateThread with start address fcn.00402340 (SMTP sender) and sleeps rand() % 50 + 50 ms between spawns. Total potential threads: 100 × 50 = 5,000. ^[r2:fcn.004024e0]
  6. Self-erasure — after thread storm, sleeps 20,000 ms (0x4e20) then DeleteFileW on its own path and exits. ^[r2:fcn.004024e0]

SMTP Sender (fcn.00402340 / fcn.00401a10)

  • Opens %TEMP%\<rand>n.txt (random temp file) for reading via _wfopen. ^[r2:fcn.004024e0]
  • Parses each line as recipient:address using strchr(..., ':') and strtok(..., "//"). ^[r2:fcn.00402340]
  • For each recipient, establishes a raw TCP socket to the resolved MX (port 25 implied by SMTP state machine), then walks a 7-state switch:
    • State 0: EHLO / HELO handshake, probes for ESMTP banner.
    • State 2: MAIL FROM: with sender address.
    • State 3: RCPT TO: with recipient address.
    • State 4: DATA command.
    • State 5: Full MIME header construction — forged Received: headers (MailEnable and qmail variants), From:, To:, Subject:, Date:, Message-ID, Mime-Version: 1.0, Content-type: text/plain. Subject line is YOU PERVERT! I RECORDED YOU!. ^[r2:fcn.00401a10], ^[strings.txt:146]
    • State 5 continued: Email body assembled via strcat chain — the full sextortion template (infected with R.A.T., camera recording, $800 USD BTC demand, wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, exchange links for coinbase/binance/bitrefill/crypto.com/kucoin/etoro/kraken). ^[strings.txt:37-61]
    • State 6: QUIT.
  • No ZIP attachment; body is inline text/plain (same as t5).

Decrypt / Key Material

  • Hardcoded string Tmlr at two locations in the binary (r2 string scan). This is the XOR+NOT decrypt key shared across all confirmed $800 variant siblings (edd6ad22, c3b1b4e4, dc2936ea, 5076fdc3, 67ae1ba4). ^[r2:strings]
  • The actual decryption routine is not reached in the radare2 pseudo-C (likely an inlined XOR-NOT loop in the .text section), but the key presence and the identical BTC wallet confirm payload decryption produces the same output.

C2 Infrastructure

  • MX target: yahoo.com (DNSAPI.dll DnsQuery_A for MX records) ^[r2:fcn.00401790], ^[strings.txt:16]
  • External IP check: http://icanhazip.com/ (WinInet, InternetOpenUrlA) ^[strings.txt:18]
  • Fake UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 ^[strings.txt:17]
  • BTC wallet: 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K (same across all $800 siblings) ^[strings.txt:59]
  • No hardcoded C2 IP/domain — the SMTP engine is self-contained; it only needs the MX resolution and the external IP for the Received: header forgery.

Decompiled Behavior

See individual radare2 function summaries above. Key control-flow patterns:

  • Nested loop thread storm (for i=0; i<100; i++ → for j=0; j<50; j++ → CreateThread + rand() % 50 + 50 sleep) produces 5,000 concurrent SMTP workers. ^[r2:fcn.004024e0]
  • State-machine SMTP client — 7-case switch driven by var_20h state counter, with recv/send loop in fcn.00401190. Standard RFC-5321 client implementation. ^[r2:fcn.00401a10]
  • String-encryption helper (fcn.00401350) — PRNG-seeded string generation (srand(GetTickCount()), rand() % 10, sprintf("%s%d", ...)). Used to generate random local filenames and Message-ID components. ^[r2:fcn.00401350]
  • No anti-debug/VM beyond Sleep(2000) at entry and mutex gating. IsDebuggerPresent is imported but not called in main(). ^[pefile.txt]

Interesting Tidbits

  • Mutex gap: t1 (12:13:57), t2 (12:15:01), t4 (12:33:18), t5 (12:34:02), t13 (12:42:51). The ~8-minute gap between t5 and t13 suggests the builder was paused or the operator was rotating other parameters. The t3 mutex has not been observed in this corpus yet.
  • Window title: YOU PERVERT! I RECORDED YOU! is a new string addition relative to edd6ad22 (May 26) and t2/t4/t5; it was first seen in t1 (67ae1ba4). ^[strings.txt:146]
  • No ZIP constructor — unlike the $1200 variant (150e4652), this sample sends the email body as inline text without a ZIP attachment. Matches the t1–t5 pattern.
  • Resource section: Contains only the standard MSVCR90 manifest + dependent assembly RT_MANIFEST (0x18). No payload resources, no encrypted blobs. ^[pefile.txt]
  • Import surface: Minimal — KERNEL32 (17 APIs), MSVCR90 (32 CRT APIs), WININET (6 APIs), WS2_32 (12 ordinal imports), DNSAPI (2 APIs), SHLWAPI (3 APIs), USER32 (2 APIs). No NTAPI, no CryptoAPI, no registry writes beyond Zone.Identifier deletion. ^[pefile.txt]

Deployable Signatures

YARA Rule

rule Phorpiex_SextortionSpamBot_800USD {
    meta:
        description = "Phorpiex sextortion spam bot ($800 variant) — self-contained SMTP engine with hardcoded BTC wallet"
        author = "Titus"
        date = "2026-09-02"
        sha256 = "041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc"
        family = "phorpiex"
    strings:
        $btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii wide
        $ua = "Chrome/202.0.4664.110 Safari/537.36" ascii wide
        $mx = "yahoo.com" ascii wide
        $ip = "http://icanhazip.com/" ascii wide
        $subj = "YOU PERVERT! I RECORDED YOU!" ascii wide
        $ehlo = "EHLO %s" ascii wide
        $mailfrom = "MAIL FROM: %s" ascii wide
        $rcptto = "RCPT TO: <%s>" ascii wide
        $received_m = "Received: from %s ([%d.%d.%d.%d]) by %s with MailEnable ESMTP; %s" ascii wide
        $received_q = "Received: (qmail %s invoked by uid %s); %s" ascii wide
        $key = "Tmlr" ascii wide
        $mut_t13 = "t13" ascii wide
        $mut_t1 = "t1" ascii wide
        $mut_t2 = "t2" ascii wide
        $mut_t4 = "t4" ascii wide
        $mut_t5 = "t5" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 25KB and
        ($btc or $ua) and
        ($mx or $ip) and
        2 of ($ehlo, $mailfrom, $rcptto, $received_m, $received_q)
}

Behavioral Hunt Query (Sigma-compatible pseudo-query)

title: Phorpiex Sextortion Spam Bot Execution
detection:
    selection_process:
        - Image|endswith: '.exe'
        - CommandLine|contains:
            - 't13'
            - 't1'
            - 't2'
            - 't4'
            - 't5'
    selection_network:
        - InitiatedConnection:
            - DestinationPort: 25
            - DestinationHost|contains: 'yahoo.com'
        - DnsQuery:
            - QueryName|contains: 'yahoo.com'
            - QueryType: 'MX'
    selection_ua:
        - UserAgent|contains: 'Chrome/202.0.4664.110'
    selection_file:
        - FileDelete:
            - TargetFilename|contains: 'Zone.Identifier'
    condition: selection_process and (selection_network or selection_ua or selection_file)

IOC List

Indicator Type Value Notes
SHA-256 hash 041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc This sample
BTC Wallet cryptocurrency 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K $800 variant shared wallet
Mutex mutex t13 Also t1, t2, t4, t5 in siblings
Fake UA user-agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 Impossible Chrome version
MX Target domain yahoo.com Hardcoded MX lookup target
External IP URL http://icanhazip.com/ WinInet fetch for header forgery
Temp file filepath %TEMP%\<rand>n.txt Random filename via srand(GetTickCount()) + rand() % 10
Decrypt key string Tmlr XOR+NOT key, shared across $800 variants
Window title string YOU PERVERT! I RECORDED YOU! First seen in t1, present here

Behavioral Fingerprint Statement

This binary is an 18–20 KB MSVC 9.0 PE32 GUI executable with a minimal import surface (KERNEL32, MSVCR90, WININET, WS2_32, DNSAPI, SHLWAPI, USER32). Upon launch it sleeps 2 seconds, creates a short ASCII mutex (t1–t13 observed), deletes its own Zone.Identifier ADS, initializes Winsock, resolves the external IP via icanhazip.com with a fake Chrome/202 UA, queries yahoo.com MX records via DNSAPI, then spawns 5,000 concurrent SMTP worker threads. Each thread connects to the resolved MX on port 25, sends a forged MailEnable/qmail Received: header, and delivers a sextortion email demanding $800 USD in Bitcoin to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. After the thread storm it sleeps 20 seconds and deletes itself. No registry persistence, no C2 beacon, no payload download — fully self-contained.

Detection Signatures

Technique MITRE ATT&CK ID Evidence
User Execution: Malicious File T1204.002 Spam-distributed PE, no C2 download needed ^[triage.json]
Impair Defenses: Indicator Removal T1070.004 Zone.Identifier ADS deletion on self ^[r2:main]
Application Layer Protocol: Email T1071.003 Self-contained SMTP client to yahoo.com MX ^[r2:fcn.00401790]
Data from Local System T1005 Reads local temp file for recipient list ^[r2:fcn.004024e0]
Exfiltration Over C2 Channel T1041 SMTP email exfiltration (sextortion message) ^[r2:fcn.00401a10]
Impact: Data Encrypted for Impact N/A — no encryption Sextortion threat only; no actual video footage or encryption observed
Input Capture: Screen Capture N/A — false claim Threat text claims camera recording; no capture code in binary

How To Mess With It (Homelab Replication)

Toolchain: Microsoft Visual C++ 2008 (MSVC 9.0) / MSVCR90, targeting x86 Win32 GUI subsystem.

Reproduction concept: Build a minimal Win32 SMTP client in C using winsock2.h, wininet.h, and dnsapi.h. Hardcode a fake Chrome UA, resolve yahoo.com MX via DnsQuery_A, connect to port 25, and implement the EHLO→MAIL FROM→RCPT TO→DATA→QUIT state machine. Use srand(GetTickCount()) for PRNG and CreateThread in a nested loop to spawn 5,000 workers.

Verification: Compile with /MT (static MSVCR90 linkage) and compare the .text section hash against known siblings; the SMTP engine structure should produce a similar control-flow graph.

References

  • Artifact ID: 46c3a1f0-8229-4a7d-b2c2-756276b87914 ^[triage.json]
  • Source: MalwareBazaar / OpenCTI dropped-by-phorpiex tag ^[triage.json]
  • Related analyses: /intel/analyses/67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9.html (t1, earliest $800 build), /intel/analyses/5076fdc39445369e67daaccb7ec1699107a5f227aaaec978ec9d77d966124f3d.html (t2), /intel/analyses/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a.html (t4), /intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html (t5), /intel/analyses/edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19.html (etyueu, May 26), entities/phorpiex.md (family overview)

Provenance

Analysis based on file.txt, exiftool.json, pefile.txt, strings.txt, rabin2-info.txt, and radare2 decompilation (r2 -AA, pdc on main, fcn.00401790, fcn.00401800, fcn.00401a10, fcn.00401350, fcn.00402320, fcn.00402340, fcn.004024e0, fcn.00401430). Capa signatures were unavailable on this host (default signature path missing). Floss failed on argument parse. Dynamic analysis skipped — no CAPE Windows guest. All TTP inferences are static-only and validated against 5 confirmed sibling reports.