typeanalysisfamilyphorpiexconfidencehighcreated2026-09-02updated2026-09-02malware-familyphorpiexsextortionspamsmtp-exfiltrationmsvcanti-debugchrome-128-ua-masqueradedropped-by-phorpiex
SHA-256: 49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031

phorpiex: 49740d89 — sextortion spam bot $800 variant, mutex t7, compiled 12:36:22 UTC May 29

Executive Summary

A 19 KB MSVC 9.0 self-contained sextortion spam bot, compiled at 12:36:22 UTC on 2026-05-29 (22 minutes after the earliest confirmed $800 campaign build 67ae1ba4). Uses the same Tmlr XOR+NOT decrypt key, the same hardcoded BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, and the same 5,000-thread SMTP engine as the t1–t13 campaign burst. Delta: mutex t7, window title YOU PERVERT! I RECORDED YOU!.

What It Is

  • File type: PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
  • Size: 18,944 bytes (19 KB)
  • Compiler: MSVC 9.0 (LinkerVersion 9.0, MSVCR90.dll CRT, embedded VC90 CRT manifest) ^[pefile.txt:46],^[strings.txt:147]
  • Timestamp: 2026-05-29 12:36:22 UTC (0x6A198846) ^[pefile.txt:34]
  • Rich header: 5Fw^ byte pattern (matches campaign siblings) ^[strings.txt:2]
  • Packing / obfuscation: None. No UPX, no custom crypter. XOR+NOT string decryption using key Tmlr applied at runtime. ^[r2:fcn.00401030]
  • Anti-analysis: IsDebuggerPresent import present but not observed in main path; thin IAT (only WININET, WS2_32, DNSAPI, KERNEL32, USER32, SHLWAPI, MSVCR90). No VM checks. ^[strings.txt:141],^[pefile.txt:183]
  • Signing: Unsigned. No Authenticode. ^[rabin2-info.txt:27]
  • Mutex: t7 (hardcoded at 0x404058, pushed to CreateMutexA in main) ^[r2:main:0x402754]
  • Window title: YOU PERVERT! I RECORDED YOU! (hardcoded at 0x406000) ^[strings.txt:146]

How It Works

This sample is a self-contained sextortion spam bot — no external payload, no second-stage download. It resolves the MX for yahoo.com, opens raw TCP sockets to SMTP servers, and delivers the full ransom email using a hardcoded template. The $800 demand and the BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K are identical across the t1–t13 burst. ^[strings.txt:36],^[strings.txt:59]

Entry flow (main @ 0x402740):

  1. Sleeps 2,000 ms (Sleep(0x7d0)). ^[r2:main:0x402744]
  2. Creates mutex t7. If GetLastError() == 183 (ERROR_ALREADY_EXISTS), exits immediately. ^[r2:main:0x402754]
  3. Deletes %MODULEPATH%:Zone.Identifier ADS to strip MOTW. ^[r2:main:0x40277e]
  4. Calls WSAStartup(0x0202, ...) and checks external IP via http://icanhazip.com/ (WinInet). ^[r2:fcn.00401800],^[strings.txt:18]
  5. If IP check succeeds, spawns the SMTP spam thread (fcn.004024e0) and enters an infinite sleep loop (Sleep(0xcdfe600) ≈ 3.5 hours). ^[r2:main:0x402828]

SMTP spam thread (fcn.004024e0 @ 0x4024e0):

  1. Seeds srand with GetTickCount(). ^[r2:fcn.004024e0:0x4024e3]
  2. Copies a decoded string (likely the victim’s email or a sender name) to a buffer. ^[r2:fcn.004024e0:0x40250a]
  3. Expands %temp% to a wide path, writes n.txt there (victim list), then reads it back to count lines (atoi). ^[r2:fcn.004024e0:0x40252e],^[strings.txt:161]
  4. Outer loop: 100 iterations (0x64). Inner loop: 50 iterations (0x32). Each inner iteration spawns a new thread (fcn.00402340) = 5,000 total SMTP threads. ^[r2:fcn.004024e0:0x402680]
  5. Sleeps rand() % 50 + 50 ms between thread spawns. ^[r2:fcn.004024e0:0x4026b4]
  6. After 100 outer loops, sleeps 20,000 ms (0x4e20) and repeats. ^[r2:fcn.004024e0:0x4026d2]
  7. Self-cleanup: deletes a temp file at 0x406728 (.jpg staging path) before exiting. ^[r2:fcn.004024e0:0x4026df]

Per-thread SMTP client (fcn.00402340 @ 0x402340):

  1. Reads a line from the n.txt victim list (260-byte fgets buffer). ^[r2:fcn.00402340:0x402387]
  2. Uses rand() + probability gate (rand() / 50 + 1.0 comparison) to randomly select a victim line for this thread. ^[r2:fcn.00402340:0x4023a6]
  3. Splits the line on : and // to extract target domain / email parts. ^[r2:fcn.00402340:0x40242d]
  4. Calls fcn.00401a10 to open a TCP socket (port 25), perform the SMTP dialog, and send the full email body. ^[r2:fcn.00402340:0x402450]

SMTP state machine (fcn.00401a10 @ 0x401a10): A 7-case switch implementing the full SMTP transaction:

  • Case 0: StrStrA server banner for ESMTP.
  • Case 1: EHLO / HELO handshake.
  • Case 2: MAIL FROM: with spoofed sender address.
  • Case 3: RCPT TO: with victim email.
  • Case 4: DATA command.
  • Case 5: Full email body (headers + sextortion template + BTC instructions + exchange links). Uses rand() to generate fake Message-ID and Received timestamps. Masquerades as MailEnable and qmail in Received headers. ^[r2:fcn.00401a10:case 5]
  • Case 6: QUIT.

String decryption (fcn.00401030 @ 0x401030): XORs the input buffer with the repeating key Tmlr (0x4041c0), then applies a bitwise NOT to the result. ^[r2:fcn.00401030:0x40108d]

Decompiled Behavior

Entry point (entry0 @ 0x402bb7) is a standard MSVC 9.0 CRT bootstrap: sets SetUnhandledExceptionFilter, acquires the CRT lock via InterlockedCompareExchange, runs _initterm_e and _initterm, then calls main(0, 0, 0x400000). ^[r2:entry0]

main is the top-level orchestrator. The only child threads it creates are the SMTP spam thread and the infinite sleep guard. No file-write operations outside %temp%\n.txt and the Zone.Identifier deletion. No registry access. No network besides WinInet IP check and raw SMTP sockets.

Notable internal helper functions:

  • fcn.004018e0 — strstr wrapper (needle search).
  • fcn.00401430 — strips \r and \n from a string (line ending trim).
  • fcn.00401350 — rand() + sprintf("%s%d", ...) string generator (used for temp filenames and fake IDs).
  • fcn.00401150 — send() wrapper with length check.
  • fcn.00401190 — recv() wrapper (1024-byte buffer).

C2 Infrastructure

No traditional C2. The bot is self-contained — it does not beacon to an attacker server. All network activity is:

  • IP check: http://icanhazip.com/ (hardcoded) ^[strings.txt:18]
  • MX resolution: yahoo.com via DnsQuery_A (DNS type 15 = MX) ^[strings.txt:16],^[r2:fcn.00401790]
  • SMTP delivery: Direct TCP/25 to resolved MX hosts. No authentication. No TLS observed. ^[r2:fcn.00401a10]

Interesting Tidbits

  • Campaign timing: Compiled at 12:36:22 UTC, 22 minutes after the earliest $800 build (67ae1ba4, 12:13:57 UTC) and 8 minutes before t13 (04134145, 12:42:51 UTC). Fits the ~30-minute campaign burst. ^[pefile.txt:34],^[entities/phorpiex.md]
  • Same decrypt key: Tmlr is identical to t1, t2, t4, t5, and t13 siblings. Confirms shared builder. ^[r2:fcn.00401030],^[entities/phorpiex.md]
  • Same BTC wallet: 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K — no rotation across the burst. ^[strings.txt:59]
  • Same fake UA: Chrome/202.0.4664.110 (impossible version) used for the WinInet IP check. ^[strings.txt:17]
  • Temp staging: Generates %temp%\n.txt for the victim list and %temp%\%d%d%d.jpg for a sidecar file (possibly a screenshot lure, though no image data is embedded). ^[strings.txt:161],^[strings.txt:162]
  • No persistence: No registry, no scheduled task, no startup folder. Single execution, self-contained.

How To Mess With It (Homelab Replication)

Toolchain: MSVC 9.0 (Visual Studio 2008) or any compiler that links MSVCR90.dll and embeds the VC90 CRT manifest.

Goal: Reproduce a binary that hits the same capa / static fingerprint as this sample.

  1. Create a Win32 GUI project in VS2008.
  2. Link wininet.lib, ws2_32.lib, dnsapi.lib, shlwapi.lib, kernel32.lib, user32.lib.
  3. Implement a Tmlr XOR+NOT string decoder:
    void decrypt(char* buf, size_t len) {
        const char* key = "Tmlr";
        for (size_t i = 0; i < len; i++) {
            buf[i] = ~(buf[i] ^ key[i % 4]);
        }
    }
    
  4. Embed the sextortion email template as an encrypted .rdata blob, decrypt at runtime.
  5. Use GetTickCount → srand → rand() for temp filename entropy.
  6. Open raw TCP sockets to port 25 and speak plaintext SMTP.
  7. Compile with standard settings (no /O2 required; the original uses default CRT init).

Verification: Run capa on the reproducer. Expected hits: use network connection, send data, resolve DNS, create mutex, sleep, delete file, check external IP.

Deployable Signatures

YARA rule

rule phorpiex_sextortion_800_t_campaign {
    meta:
        description = "Phorpiex sextortion spam bot $800 variant (t-mutex campaign burst)"
        author = "PacketPursuit"
        date = "2026-09-02"
        sha256 = "49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031"
    strings:
        $decrypt_key = "Tmlr" ascii
        $btc_wallet = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
        $ua = "Chrome/202.0.4664.110" ascii
        $ip_check = "http://icanhazip.com/" ascii
        $mx_target = "yahoo.com" ascii
        $subject_title = "YOU PERVERT! I RECORDED YOU!" ascii
        $mailenable = "MailEnable ESMTP" ascii
        $qmail = "qmail" ascii
        $template_1 = "Unfortunately, there is some bad news for you." ascii
        $template_2 = "All you need is $800 USD in Bitcoin (BTC)" ascii
        $template_3 = "After the transaction is successful, I will proceed to delete everything." ascii
        $template_4 = "I keep my promises!" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize < 25KB and
        $decrypt_key and
        $btc_wallet and
        (2 of ($template_*)) and
        (1 of ($ua, $ip_check, $mx_target))
}

Sigma rule (process creation — network indicators)

title: Phorpiex Sextortion Spam Bot Network Activity
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Initiated: 'true'
        DestinationPort: 25
        Image|endswith:
            - '\file.exe'
            - '\file'
    selection_ua:
        CommandLine|contains:
            - 'Chrome/202.0.4664.110'
    selection_ip:
        CommandLine|contains:
            - 'http://icanhazip.com/'
    condition: selection and (selection_ua or selection_ip)
falsepositives:
    - Unknown
level: high

IOC list

Type Value Notes
SHA-256 49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031 This sample
Mutex t7 Campaign burst mutex
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K Shared across t1–t13
IP check URL http://icanhazip.com/ Hardcoded
MX target yahoo.com DNS MX resolution
Window title YOU PERVERT! I RECORDED YOU! Hardcoded at 0x406000
Decrypt key Tmlr XOR+NOT cipher key
Temp file %temp%\n.txt Victim list staging
Temp file %temp%\%d%d%d.jpg Sidecar staging

Behavioral fingerprint statement

This binary is a 19 KB MSVC 9.0 PE32 GUI executable with no packing, a minimal IAT (WININET, WS2_32, DNSAPI, KERNEL32, USER32, SHLWAPI, MSVCR90), and a hardcoded XOR+NOT string decryption key Tmlr. On launch it sleeps 2 seconds, creates a mutex (t7), strips the Zone.Identifier ADS, checks its external IP via http://icanhazip.com/ with a fake Chrome/202 UA, then spawns a 5,000-thread SMTP spam engine that resolves yahoo.com MX records and delivers a hardcoded $800 sextortion email demanding payment to BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. No persistence, no C2 beacon, no second stage. Self-contained spam bot.

Detection Signatures

  • MITRE ATT&CK: T1566.001 (Phishing: Spearphishing Attachment — delivery vector, inferred), T1046 (Network Service Discovery — MX resolution), T1021.001 (Remote Services: Remote Desktop — no, not applicable), T1491.001 (Defacement: Internal Defacement — no). The relevant mappings are: T1046 (MX DNS query), T1059.003 (Windows Command Shell — no, but CreateThread spam dispatch), T1071.003 (Application Layer Protocol: Mail Protocol — SMTP), T1496 (Resource Hijacking — 5,000 threads), T1027.002 (Obfuscated Files or Information: Software Packing — no packing, but XOR+NOT obfuscation qualifies as T1027). ^[capa.txt] (capa failed to install signatures, so mapping is manual from static analysis).

References

  • phorpiex — Family entity page with full campaign timeline and capability list.
  • chrome-128-ua-masquerade — Technique page for fake Chrome User-Agent strings.
  • xor-not-string-decryption — Technique page for the Tmlr XOR+NOT cipher.
  • [CAPE dynamic analysis] — Skipped (no Windows guest available). Static-only analysis.

Provenance

  • Static analysis performed via radare2 (level 3 analysis, 78 functions discovered) on 2026-09-02.
  • Triage artifacts: file.txt, pefile.txt, strings.txt, rabin2-info.txt, exiftool.json, binwalk.txt, yara.txt (generated 2026-05-29).
  • floss.txt — failed due to argument error (--no flag collision).
  • capa.txt — failed due to missing default signature path.
  • No CAPE detonation available (no Windows guest).
  • Decompilation: radare2 pdc backend (default).