typeanalysisfamilyphorpiexconfidencehighmalware-familyloaderc2persistencedefense-evasionc2-protocolmitre-attck
SHA-256: 3bfbfb354bcb470401421a22b7bce071d0ec77f9d6be1d5241fe49b69a169678

phorpiex: 3bfbfb35 — $800 sextortion spam bot, mutex t6, compiled 12:34:48 UTC (fills t5→t7 gap)

Executive Summary

Phorpiex campaign sextortion spam bot, $800 variant, mutex t6. 19 KB MSVC 9.0 PE32 with self-contained SMTP engine, WinInet external-IP fetch, and 5,000-thread dispatch. Compiled 12:34:48 UTC May 29 2026 — fills the ~1m46s gap between siblings t5 (12:34:02) and t7 (12:36:22), confirming continuous sub-minute builder rotation. Static-only; CAPE skipped.

What It Is

PE32 GUI, 18,944 bytes, MSVC 9.0 / MSVCR90 CRT, LinkerVersion 9.0 ^[exiftool.json:18] ^[rabin2-info.txt]. Timestamp 0x6A1987E8 = 2026-05-29 12:34:48 UTC ^[pefile.txt:34]. ASLR+NX enabled, no signature, no PDB, manifest-only .rsrc ^[pefile.txt:393-430]. Family: Phorpiex (dropped-by-phorpiex tag, shared Tmlr XOR+NOT decrypt key, identical BTC wallet and SMTP engine to 12 prior $800 siblings). See phorpiex for full campaign context.

How It Works

Mutex-gated single instance (t6) ^[r2:main]; sleeps 2s on startup ^[r2:main]; deletes Zone.Identifier ADS ^[r2:main]; resolves victim external IP via icanhazip.com ^[r2:fcn.00401800]; queries yahoo.com MX via DNSAPI.DnsQuery_A ^[r2:fcn.00401790]; spawns 5,000 SMTP worker threads (100 outer × 50 inner nested loop) ^[r2:fcn.004024e0] delivering a sextortion template with hardcoded BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]. The SMTP dialog spoofs MailEnable ESMTP and qmail Received headers ^[strings.txt:27-28]. See xor-not-string-decryption for the decrypt-key technique.

Decompiled Behavior

Entry point main (0x402740) calls Sleep(2000), creates mutex t6 via CreateMutexA, then deletes the Zone.Identifier ADS stream on its own executable path. It calls fcn.00401790 which queries yahoo.com via DnsQuery_A and opens a test TCP socket. On success, main spawns thread fcn.004024e0.

Thread fcn.004024e0 seeds srand with GetTickCount, calls fcn.00401800 to fetch the external IP via WinInet (InternetOpenA → InternetOpenUrlA → InternetReadFile on http://icanhazip.com/), writes the result to %TEMP%\n.txt via CreateFileW/WriteFile, then reads it back with _wfopen/fgets. The IP string is tokenized with strtok on : and // delimiters ^[r2:fcn.00402340], and each extracted address is passed to fcn.00401a10.

fcn.00401a10 is a full SMTP state machine implementing EHLO/HELO, MAIL FROM, RCPT TO, DATA, and QUIT over raw WS2_32 sockets. It assembles spoofed Received: headers mimicking MailEnable ESMTP and qmail, then constructs the email body by repeated strcat of hardcoded paragraph strings (the sextortion text). Subject is YOU PERVERT! I RECORDED YOU! ^[strings.txt:146]. The body includes the hardcoded BTC wallet and a list of exchange URLs ^[strings.txt:49-56].

C2 Infrastructure

No traditional C2. Self-contained spam bot. Infrastructure indicators:

Indicator Value Source
External IP resolution http://icanhazip.com/ ^[strings.txt:18]
MX resolution target yahoo.com ^[strings.txt:16]
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]
Mutex t6 ^[r2:main]
Window title YOU PERVERT! I RECORDED YOU! ^[strings.txt:146]
Fake UA Chrome/202.0.4664.110 ^[strings.txt:17]
SMTP spoof MailEnable ESMTP, qmail ^[strings.txt:27-28]
Decrypt key Tmlr ^[r2:strings]

Interesting Tidbits

  • Compile time 12:34:48 UTC sits exactly between t5 (12:34:02) and t7 (12:36:22), confirming the builder was rotating mutex values continuously with ~1m46s granularity ^[pefile.txt:34].
  • Same Tmlr XOR+NOT decrypt key as all prior $800 siblings — key reuse across the entire campaign burst ^[r2:strings].
  • Fake Chrome UA uses an impossible version Chrome/202.0.4664.110 — same as prior siblings, distinguishing from the 523535 numeric-mutex variant which also used this UA ^[strings.txt:17].
  • MailEnable ESMTP and qmail spoofed Received headers suggest awareness of spam-filter heuristics ^[strings.txt:27-28].
  • No ZIP attachment construction observed in this variant (unlike earlier $1200 siblings); the body is delivered inline as plain text.

How To Mess With It (Homelab Replication)

Not applicable — this is a pure spam-delivery binary with no novel build technique beyond the standard MSVC 9.0 + XOR+NOT obfuscation already documented at xor-not-string-decryption. For reproduction notes see that technique page.

Deployable Signatures

YARA

rule phorpiex_sextortion_800_t6 {
    meta:
        description = "Phorpiex $800 sextortion spam bot, mutex t6 variant"
        author = "pp-hermes"
        date = "2026-09-05"
        sha256 = "3bfbfb354bcb470401421a22b7bce071d0ec77f9d6be1d5241fe49b69a169678"
    strings:
        $mutex_t6 = "t6" ascii wide
        $btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K"
        $ua = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36"
        $ip_check = "http://icanhazip.com/"
        $yahoo = "yahoo.com"
        $title = "YOU PERVERT! I RECORDED YOU!"
        $mailenable = "MailEnable ESMTP"
        $qmail = "qmail"
        $key = "Tmlr"
    condition:
        uint16(0) == 0x5A4D and
        5 of them and
        filesize < 25KB
}

Sigma

Not applicable — this binary's behavior is network-socket shaped, not process-event shaped. Use the YARA rule for static detection and the behavioral hunt query below for runtime.

Behavioral hunt query (KQL/SPL/EQL)

# Hunt: process creates mutex "t6" AND performs DNS query for "yahoo.com" 
# AND makes HTTP GET to "icanhazip.com" within 60s of launch
(process_create where command_line like "*%" and 
   (mutex_access where mutex_name == "t6") and
   (dns_query where query_name == "yahoo.com") and
   (network_http where url == "http://icanhazip.com/"))

IOC list

Type Value
SHA-256 3bfbfb354bcb470401421a22b7bce071d0ec77f9d6be1d5241fe49b69a169678
ssdeep 192:tIISCngTBvblVPT0Y76fIkq2NleQY9T4KUSvu9zw+ggSmOiMbO5Ot1EdkF39TGJ4:vIblVP4Y/2N0bLu9JgPL7Nyav8U9co
Mutex t6
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K
IP check URL http://icanhazip.com/
MX target yahoo.com
Window title YOU PERVERT! I RECORDED YOU!
Fake UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36

Behavioral fingerprint

This binary loads kernel32, msvcr90, wininet, ws2_32, dnsapi, shlwapi, and user32. Within 2 seconds of launch it creates a mutex t6, deletes its own Zone.Identifier ADS, queries yahoo.com via DnsQuery_A, fetches http://icanhazip.com/ via WinInet, and spawns 5,000 threads over ~20 seconds. Each thread opens a TCP socket to the resolved MX, sends an SMTP dialog with spoofed MailEnable/qmail Received headers, and delivers a plain-text sextortion body demanding $800 BTC to 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K.

Detection Signatures

  • YARA: PE_File_Generic, Suspicious_Wininet_Imports ^[yara.txt]
  • capa: unavailable (signatures not installed) ^[capa.txt]

References

Provenance

  • file.txt — file type
  • pefile.txt — PE headers, compile timestamp, imports, resources
  • strings.txt — plaintext strings
  • rabin2-info.txt — radare2 binary summary
  • exiftool.json — metadata
  • r2-decompile — functions main (0x402740), fcn.00401790, fcn.00401800, fcn.00401900, fcn.00401a10, fcn.004024e0, fcn.00402340 via radare2-MCP
  • Tool versions: radare2 5.x (MCP), pefile (Python), ExifTool 12.76