724ec6b8cf5834d429ce360dc4427c8af4b1944cfe99020657f38ebb9b4b9d25phorpiex: 724ec6b8 — mutex t10, fills t7–t11 gap in May 29 campaign burst
Executive Summary: MSVC 9.0 PE32 self-contained SMTP sextortion bot, 19 KB, compiled 12:39:58 UTC May 29 2026. Mutex t10 — the tenth confirmed sibling in the $800 sub-cluster, slotting between t7 (12:36:22) and t11 (12:40:35). Same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine via yahoo.com MX resolution. Static-only (CAPE skipped — no Windows guest).
What It Is
- File: PE32 executable (GUI) Intel 80386, 5 sections, 18,944 bytes ^[file.txt]
- Compiled: Fri May 29 12:39:58 2026 UTC (PE timestamp
0x6A19891E) ^[pefile.txt:34] - Toolchain: MSVC 9.0, MSVCR90.dll CRT, Windows GUI subsystem ^[rabin2-info.txt:11,17,32]
- Linker version: 9.0 ^[pefile.txt:45]
- Security: ASLR + NX enabled (
DllCharacteristics: 0x8140), not signed ^[pefile.txt:67] - IAT surface: MSVCR90, WININET, SHLWAPI, WS2_32, DNSAPI, KERNEL32, USER32 — thin and honest ^[pefile.txt:229-390]
How It Works
Entry point follows standard MSVC C-runtime init (_initterm / _initterm_e) before reaching main at 0x00402740 ^[r2:entry0]. The bot is single-instance gated by mutex t10 (hardcoded at 0x00406020) ^[r2:str.t10]. If CreateMutexA returns ERROR_ALREADY_EXISTS (0xB7), the process exits immediately ^[r2:main@0x00402740].
On first launch:
- Sleeps 2,000 ms (
Sleep(0x7d0)) — anti-emulation desync ^[r2:main@0x00402740] - Deletes
Zone.IdentifierADS from its own path viaDeleteFileWwith%s:Zone.Identifierformat ^[r2:main@0x0040277e] - Calls
fcn.00401790to resolveyahoo.comviaDnsQuery_A(typeDNS_TYPE_MX, value0xf) and opens a TCP socket to port 25 ^[r2:fcn.00401790] - If DNS fails, falls back to retrieving external IP via
http://icanhazip.com/usingInternetOpenUrlAwith Chrome/202.0.4664.110 UA ^[r2:fcn.00401800] - Spawns the spam threadproc (
fcn.004024e0) viaCreateThread^[r2:main@0x00402828] - Main thread sleeps ~21,600,000 ms (
0xcdfe600= ~6 hours) and loops indefinitely ^[r2:main@0x00402831]
Threadproc (fcn.004024e0)
Seeds PRNG with GetTickCount, copies the email list path from a global buffer, expands %temp% to a wide path, and writes a numeric file %temp%\<n>.txt via InternetReadFile (the file appears to be a victim list fetched from a hardcoded URL, though the URL string is encrypted at rest). The threadproc then loops 100 times (outer), spawning 50 threads per iteration (inner) — 5,000 total SMTP workers. Each inner thread sleeps rand() % 50 + 50 ms between spawns. After each outer iteration, sleeps 20,000 ms (0x4e20). When complete, deletes the temp file and exits ^[r2:fcn.004024e0].
SMTP Engine (fcn.00401a10)
A state-machine driven SMTP client implementing the full mail transaction:
| State | Action |
|---|---|
| 0 | EHLO / HELO — probes for ESMTP in banner; falls back to HELO |
| 2 | MAIL FROM: <%s> |
| 3 | RCPT TO: <%s> |
| 4 | DATA |
| 5 | Message body assembly — full sextortion template with forged MailEnable/qmail Received headers, random alphanumeric Message-ID, Date, Subject |
| 6 | QUIT |
The message body is constructed by concatenating static string blocks in fcn.00401a10 (case 5) ^[r2:fcn.00401a10]. Key elements:
- Subject:
YOU PERVERT! I RECORDED YOU!^[strings.txt:146] - Body: Classic sextortion narrative — Trojan/RAT claims, camera recording threat, $800 USD BTC demand
- BTC wallet:
1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K^[strings.txt:59] - Exchange references: Coinbase, Binance, Bitrefill, Crypto.com, KuCoin, eToro, Kraken ^[strings.txt:49-56]
- Fake UA:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/202.0.4664.110^[strings.txt:17]
String Decryption (fcn.00401030)
Same Tmlr XOR+NOT cipher observed across all $800 siblings. Key is 4 bytes at 0x4041c0 (Tmlr). Decoder iterates over input string via strlen, XORs each byte with key[i % 4], then applies bitwise NOT (~). The operation is its own inverse ^[r2:fcn.00401030].
C2 Infrastructure
- MX resolution target:
yahoo.com^[strings.txt:16] - External IP check:
http://icanhazip.com/^[strings.txt:18] - SMTP port: 25 (hardcoded, converted via
htons) ^[r2:fcn.004010d0] - No direct C2 URL in the spam bot variant — it is self-contained, using victim lists from a file (likely fetched during downloader stage, not present in this binary)
Decompiled Behavior
Notable functions:
main(0x00402740) — entry logic, mutex gating, thread spawn, long sleep loopfcn.00401790— DNS MX query foryahoo.com, socket creationfcn.00401800— external IP fetch via WinInet (icanhazip.com)fcn.004024e0— threadproc: PRNG seed, temp-file staging, 5,000-thread dispatchfcn.00401a10— SMTP state machine: EHLO/HELO → MAIL FROM → RCPT TO → DATA → QUITfcn.00401030— XOR+NOT string decoder with keyTmlrfcn.004014c0— RFC-2822 date formatter (Sun–Sat, Jan–Dec, timezone offset)fcn.00401350— random numeric string generator (used for Message-ID local-part)fcn.004013c0— random alphabetic string generator (used for Message-ID domain-part)fcn.00401150—send()wrapper with length validationfcn.00401190—recv()withselect()timeout (30s)
Interesting Tidbits
- Campaign burst sequencing:
t10at 12:39:58 fits squarely betweent7(12:36:22) andt11(12:40:35), confirming continuous ~3–4 minute build intervals across the burst. The mutex naming (t1throught13plus523535) is the only per-sample variable in an otherwise byte-identical stub. - Fake Chrome version:
202.0.4664.110is impossible — Chrome major versions have never reached 202. This is a deliberate anti-signature choice or builder laziness. - No ZIP attachment: Unlike the earlier $1200 variant (
150e4652), the $800 sub-cluster sends the extortion text inline as the email body, reducing SMTP complexity and avoiding attachment-based filtering. - MailEnable/qmail forgery: The Received header spoofs both MailEnable ESMTP and qmail, a dual-personality forgery that may help bypass simplistic SPF/DKIM checks.
- Window title string:
YOU PERVERT! I RECORDED YOU!appears in.dataat0x406000and is referenced during email assembly, but noSetWindowTextcall is visible — it may be used by a downloader companion or simply left over from shared builder code.
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2008 (MSVC 9.0) or v90 platform toolset. Target: Win32 GUI.
Compiler flags: /O1 /GS- (size optimization, no buffer security check — the binary lacks stack cookies).
Working source snippet: See the reproduction notes in xor-not-string-decryption for the Tmlr cipher. To replicate the SMTP engine, use raw Winsock connect()/send()/recv() with a state machine loop and StrStrA banner parsing.
Verification: Compile a minimal SMTP client with the Tmlr decoder and compare section entropy, IAT shape, and string layout to this sample.
Deployable Signatures
YARA
rule phorpiex_sextortion_smtp_bot_800usd {
meta:
description = "Phorpiex campaign sextortion spam bot ($800 variant)"
author = "PacketPursuit"
date = "2026-09-04"
sha256 = "724ec6b8cf5834d429ce360dc4427c8af4b1944cfe99020657f38ebb9b4b9d25"
strings:
$key = "Tmlr" ascii wide
$ua = "Chrome/202.0.4664.110" ascii wide
$btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
$subj = "YOU PERVERT! I RECORDED YOU!" ascii
$ehlo = "EHLO %s" ascii
$mailfrom = "MAIL FROM: %s" ascii
$rcptto = "RCPT TO: <%s>" ascii
$yahoo = "yahoo.com" ascii
$ipcheck = "http://icanhazip.com/" ascii
condition:
uint16(0) == 0x5A4D and
pe.imports("MSVCR90.dll") and
pe.imports("WS2_32.dll") and
pe.imports("WININET.dll") and
pe.imports("DNSAPI.dll") and
4 of them
}
IOC List
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | 724ec6b8cf5834d429ce360dc4427c8af4b1944cfe99020657f38ebb9b4b9d25 |
This sample |
| Mutex | t10 |
Per-sample rotation (t1–t13, 523535) |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
Shared across all $800 siblings |
| Fake UA | Mozilla/5.0 ... Chrome/202.0.4664.110 |
Impossible Chrome version |
| MX target | yahoo.com |
Hardcoded DNS query |
| External IP | icanhazip.com |
Fallback / reconnaissance |
| Temp file | %temp%\<n>.txt |
Victim list staging |
| ADS deletion | Zone.Identifier |
Evasion |
| Thread count | 5,000 | 100 outer × 50 inner |
Behavioral Fingerprint
This binary is a self-contained SMTP client that resolves yahoo.com MX records via DnsQuery_A, opens TCP/25 sockets, and implements a full EHLO/MAIL FROM/RCPT TO/DATA/QUIT transaction. The email body is an inline sextortion message demanding $800 in Bitcoin to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. It spawns 5,000 threads in a nested loop (100 × 50) with randomized 50–100 ms sleeps between spawns. Prior to network activity it sleeps 2 seconds, deletes its own Zone.Identifier ADS stream, and seeds PRNG with GetTickCount. No persistence mechanism is present in this stage; it is a pure spam-delivery payload likely dropped by a downloader companion.
Detection Signatures
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | Spam-distributed PE |
| Application Layer Protocol: DNS | T1071.004 | DnsQuery_A for yahoo.com MX |
| Ingress Tool Transfer | T1105 | Downloads victim list to %temp% |
| Exfiltration Over C2 | T1041 | SMTP data transmission |
| Anti-forensics: ADS deletion | T1070.004 | Zone.Identifier deletion |
| Scheduled Task/Job | T1053 | Inferred from campaign context |
References
- phorpiex — family entity
- xor-not-string-decryption — build/RE technique page
/intel/analyses/724ec6b8cf5834d429ce360dc4427c8af4b1944cfe99020657f38ebb9b4b9d25.html— this analysis
Provenance
file.txt—filecommand outputpefile.txt— pefile.py dumpstrings.txt— raw strings extractionrabin2-info.txt— radare2 binary headerr2 decompile— radare2 pseudo-C (level-2 analysis, 78 functions)dynamic-analysis.md— CAPE skipped (no Windows guest)