49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031phorpiex: 49740d89 — sextortion spam bot $800 variant, mutex t7, compiled 12:36:22 UTC May 29
Executive Summary
A 19 KB MSVC 9.0 self-contained sextortion spam bot, compiled at 12:36:22 UTC on 2026-05-29 (22 minutes after the earliest confirmed $800 campaign build 67ae1ba4). Uses the same Tmlr XOR+NOT decrypt key, the same hardcoded BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, and the same 5,000-thread SMTP engine as the t1–t13 campaign burst. Delta: mutex t7, window title YOU PERVERT! I RECORDED YOU!.
What It Is
- File type: PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
- Size: 18,944 bytes (19 KB)
- Compiler: MSVC 9.0 (LinkerVersion 9.0,
MSVCR90.dllCRT, embedded VC90 CRT manifest) ^[pefile.txt:46],^[strings.txt:147] - Timestamp: 2026-05-29 12:36:22 UTC (
0x6A198846) ^[pefile.txt:34] - Rich header: 5Fw^ byte pattern (matches campaign siblings) ^[strings.txt:2]
- Packing / obfuscation: None. No UPX, no custom crypter. XOR+NOT string decryption using key
Tmlrapplied at runtime. ^[r2:fcn.00401030] - Anti-analysis:
IsDebuggerPresentimport present but not observed in main path; thin IAT (onlyWININET,WS2_32,DNSAPI,KERNEL32,USER32,SHLWAPI,MSVCR90). No VM checks. ^[strings.txt:141],^[pefile.txt:183] - Signing: Unsigned. No Authenticode. ^[rabin2-info.txt:27]
- Mutex:
t7(hardcoded at 0x404058, pushed toCreateMutexAinmain) ^[r2:main:0x402754] - Window title:
YOU PERVERT! I RECORDED YOU!(hardcoded at 0x406000) ^[strings.txt:146]
How It Works
This sample is a self-contained sextortion spam bot — no external payload, no second-stage download. It resolves the MX for yahoo.com, opens raw TCP sockets to SMTP servers, and delivers the full ransom email using a hardcoded template. The $800 demand and the BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K are identical across the t1–t13 burst. ^[strings.txt:36],^[strings.txt:59]
Entry flow (main @ 0x402740):
- Sleeps 2,000 ms (
Sleep(0x7d0)). ^[r2:main:0x402744] - Creates mutex
t7. IfGetLastError() == 183(ERROR_ALREADY_EXISTS), exits immediately. ^[r2:main:0x402754] - Deletes
%MODULEPATH%:Zone.IdentifierADS to strip MOTW. ^[r2:main:0x40277e] - Calls
WSAStartup(0x0202, ...)and checks external IP viahttp://icanhazip.com/(WinInet). ^[r2:fcn.00401800],^[strings.txt:18] - If IP check succeeds, spawns the SMTP spam thread (
fcn.004024e0) and enters an infinite sleep loop (Sleep(0xcdfe600)≈ 3.5 hours). ^[r2:main:0x402828]
SMTP spam thread (fcn.004024e0 @ 0x4024e0):
- Seeds
srandwithGetTickCount(). ^[r2:fcn.004024e0:0x4024e3] - Copies a decoded string (likely the victim’s email or a sender name) to a buffer. ^[r2:fcn.004024e0:0x40250a]
- Expands
%temp%to a wide path, writesn.txtthere (victim list), then reads it back to count lines (atoi). ^[r2:fcn.004024e0:0x40252e],^[strings.txt:161] - Outer loop: 100 iterations (
0x64). Inner loop: 50 iterations (0x32). Each inner iteration spawns a new thread (fcn.00402340) = 5,000 total SMTP threads. ^[r2:fcn.004024e0:0x402680] - Sleeps
rand() % 50 + 50ms between thread spawns. ^[r2:fcn.004024e0:0x4026b4] - After 100 outer loops, sleeps 20,000 ms (
0x4e20) and repeats. ^[r2:fcn.004024e0:0x4026d2] - Self-cleanup: deletes a temp file at 0x406728 (
.jpgstaging path) before exiting. ^[r2:fcn.004024e0:0x4026df]
Per-thread SMTP client (fcn.00402340 @ 0x402340):
- Reads a line from the
n.txtvictim list (260-bytefgetsbuffer). ^[r2:fcn.00402340:0x402387] - Uses
rand()+ probability gate (rand() / 50 + 1.0comparison) to randomly select a victim line for this thread. ^[r2:fcn.00402340:0x4023a6] - Splits the line on
:and//to extract target domain / email parts. ^[r2:fcn.00402340:0x40242d] - Calls
fcn.00401a10to open a TCP socket (port 25), perform the SMTP dialog, and send the full email body. ^[r2:fcn.00402340:0x402450]
SMTP state machine (fcn.00401a10 @ 0x401a10):
A 7-case switch implementing the full SMTP transaction:
- Case 0:
StrStrAserver banner forESMTP. - Case 1:
EHLO/HELOhandshake. - Case 2:
MAIL FROM:with spoofed sender address. - Case 3:
RCPT TO:with victim email. - Case 4:
DATAcommand. - Case 5: Full email body (headers + sextortion template + BTC instructions + exchange links). Uses
rand()to generate fakeMessage-IDandReceivedtimestamps. Masquerades asMailEnableandqmailin Received headers. ^[r2:fcn.00401a10:case 5] - Case 6:
QUIT.
String decryption (fcn.00401030 @ 0x401030):
XORs the input buffer with the repeating key Tmlr (0x4041c0), then applies a bitwise NOT to the result. ^[r2:fcn.00401030:0x40108d]
Decompiled Behavior
Entry point (entry0 @ 0x402bb7) is a standard MSVC 9.0 CRT bootstrap: sets SetUnhandledExceptionFilter, acquires the CRT lock via InterlockedCompareExchange, runs _initterm_e and _initterm, then calls main(0, 0, 0x400000). ^[r2:entry0]
main is the top-level orchestrator. The only child threads it creates are the SMTP spam thread and the infinite sleep guard. No file-write operations outside %temp%\n.txt and the Zone.Identifier deletion. No registry access. No network besides WinInet IP check and raw SMTP sockets.
Notable internal helper functions:
fcn.004018e0—strstrwrapper (needle search).fcn.00401430— strips\rand\nfrom a string (line ending trim).fcn.00401350—rand()+sprintf("%s%d", ...)string generator (used for temp filenames and fake IDs).fcn.00401150—send()wrapper with length check.fcn.00401190—recv()wrapper (1024-byte buffer).
C2 Infrastructure
No traditional C2. The bot is self-contained — it does not beacon to an attacker server. All network activity is:
- IP check:
http://icanhazip.com/(hardcoded) ^[strings.txt:18] - MX resolution:
yahoo.comviaDnsQuery_A(DNS type 15 = MX) ^[strings.txt:16],^[r2:fcn.00401790] - SMTP delivery: Direct TCP/25 to resolved MX hosts. No authentication. No TLS observed. ^[r2:fcn.00401a10]
Interesting Tidbits
- Campaign timing: Compiled at 12:36:22 UTC, 22 minutes after the earliest $800 build (
67ae1ba4, 12:13:57 UTC) and 8 minutes beforet13(04134145, 12:42:51 UTC). Fits the ~30-minute campaign burst. ^[pefile.txt:34],^[entities/phorpiex.md] - Same decrypt key:
Tmlris identical tot1,t2,t4,t5, andt13siblings. Confirms shared builder. ^[r2:fcn.00401030],^[entities/phorpiex.md] - Same BTC wallet:
1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K— no rotation across the burst. ^[strings.txt:59] - Same fake UA:
Chrome/202.0.4664.110(impossible version) used for the WinInet IP check. ^[strings.txt:17] - Temp staging: Generates
%temp%\n.txtfor the victim list and%temp%\%d%d%d.jpgfor a sidecar file (possibly a screenshot lure, though no image data is embedded). ^[strings.txt:161],^[strings.txt:162] - No persistence: No registry, no scheduled task, no startup folder. Single execution, self-contained.
How To Mess With It (Homelab Replication)
Toolchain: MSVC 9.0 (Visual Studio 2008) or any compiler that links MSVCR90.dll and embeds the VC90 CRT manifest.
Goal: Reproduce a binary that hits the same capa / static fingerprint as this sample.
- Create a Win32 GUI project in VS2008.
- Link
wininet.lib,ws2_32.lib,dnsapi.lib,shlwapi.lib,kernel32.lib,user32.lib. - Implement a
TmlrXOR+NOT string decoder:void decrypt(char* buf, size_t len) { const char* key = "Tmlr"; for (size_t i = 0; i < len; i++) { buf[i] = ~(buf[i] ^ key[i % 4]); } } - Embed the sextortion email template as an encrypted
.rdatablob, decrypt at runtime. - Use
GetTickCount→srand→rand()for temp filename entropy. - Open raw TCP sockets to port 25 and speak plaintext SMTP.
- Compile with standard settings (no
/O2required; the original uses default CRT init).
Verification: Run capa on the reproducer. Expected hits: use network connection, send data, resolve DNS, create mutex, sleep, delete file, check external IP.
Deployable Signatures
YARA rule
rule phorpiex_sextortion_800_t_campaign {
meta:
description = "Phorpiex sextortion spam bot $800 variant (t-mutex campaign burst)"
author = "PacketPursuit"
date = "2026-09-02"
sha256 = "49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031"
strings:
$decrypt_key = "Tmlr" ascii
$btc_wallet = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
$ua = "Chrome/202.0.4664.110" ascii
$ip_check = "http://icanhazip.com/" ascii
$mx_target = "yahoo.com" ascii
$subject_title = "YOU PERVERT! I RECORDED YOU!" ascii
$mailenable = "MailEnable ESMTP" ascii
$qmail = "qmail" ascii
$template_1 = "Unfortunately, there is some bad news for you." ascii
$template_2 = "All you need is $800 USD in Bitcoin (BTC)" ascii
$template_3 = "After the transaction is successful, I will proceed to delete everything." ascii
$template_4 = "I keep my promises!" ascii
condition:
uint16(0) == 0x5A4D and
filesize < 25KB and
$decrypt_key and
$btc_wallet and
(2 of ($template_*)) and
(1 of ($ua, $ip_check, $mx_target))
}
Sigma rule (process creation — network indicators)
title: Phorpiex Sextortion Spam Bot Network Activity
logsource:
category: network_connection
product: windows
detection:
selection:
Initiated: 'true'
DestinationPort: 25
Image|endswith:
- '\file.exe'
- '\file'
selection_ua:
CommandLine|contains:
- 'Chrome/202.0.4664.110'
selection_ip:
CommandLine|contains:
- 'http://icanhazip.com/'
condition: selection and (selection_ua or selection_ip)
falsepositives:
- Unknown
level: high
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031 |
This sample |
| Mutex | t7 |
Campaign burst mutex |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
Shared across t1–t13 |
| IP check URL | http://icanhazip.com/ |
Hardcoded |
| MX target | yahoo.com |
DNS MX resolution |
| Window title | YOU PERVERT! I RECORDED YOU! |
Hardcoded at 0x406000 |
| Decrypt key | Tmlr |
XOR+NOT cipher key |
| Temp file | %temp%\n.txt |
Victim list staging |
| Temp file | %temp%\%d%d%d.jpg |
Sidecar staging |
Behavioral fingerprint statement
This binary is a 19 KB MSVC 9.0 PE32 GUI executable with no packing, a minimal IAT (WININET, WS2_32, DNSAPI, KERNEL32, USER32, SHLWAPI, MSVCR90), and a hardcoded XOR+NOT string decryption key Tmlr. On launch it sleeps 2 seconds, creates a mutex (t7), strips the Zone.Identifier ADS, checks its external IP via http://icanhazip.com/ with a fake Chrome/202 UA, then spawns a 5,000-thread SMTP spam engine that resolves yahoo.com MX records and delivers a hardcoded $800 sextortion email demanding payment to BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. No persistence, no C2 beacon, no second stage. Self-contained spam bot.
Detection Signatures
- MITRE ATT&CK: T1566.001 (Phishing: Spearphishing Attachment — delivery vector, inferred), T1046 (Network Service Discovery — MX resolution), T1021.001 (Remote Services: Remote Desktop — no, not applicable), T1491.001 (Defacement: Internal Defacement — no). The relevant mappings are: T1046 (MX DNS query), T1059.003 (Windows Command Shell — no, but
CreateThreadspam dispatch), T1071.003 (Application Layer Protocol: Mail Protocol — SMTP), T1496 (Resource Hijacking — 5,000 threads), T1027.002 (Obfuscated Files or Information: Software Packing — no packing, but XOR+NOT obfuscation qualifies as T1027). ^[capa.txt] (capa failed to install signatures, so mapping is manual from static analysis).
References
- phorpiex — Family entity page with full campaign timeline and capability list.
- chrome-128-ua-masquerade — Technique page for fake Chrome User-Agent strings.
- xor-not-string-decryption — Technique page for the
TmlrXOR+NOT cipher. - [CAPE dynamic analysis] — Skipped (no Windows guest available). Static-only analysis.
Provenance
- Static analysis performed via radare2 (level 3 analysis, 78 functions discovered) on 2026-09-02.
- Triage artifacts:
file.txt,pefile.txt,strings.txt,rabin2-info.txt,exiftool.json,binwalk.txt,yara.txt(generated 2026-05-29). floss.txt— failed due to argument error (--noflag collision).capa.txt— failed due to missing default signature path.- No CAPE detonation available (no Windows guest).
- Decompilation: radare2
pdcbackend (default).