typeanalysisfamilyphorpiexconfidencehighmalware-familyspamc2defense-evasionimpact
SHA-256: 724ec6b8cf5834d429ce360dc4427c8af4b1944cfe99020657f38ebb9b4b9d25

phorpiex: 724ec6b8 — mutex t10, fills t7–t11 gap in May 29 campaign burst

Executive Summary: MSVC 9.0 PE32 self-contained SMTP sextortion bot, 19 KB, compiled 12:39:58 UTC May 29 2026. Mutex t10 — the tenth confirmed sibling in the $800 sub-cluster, slotting between t7 (12:36:22) and t11 (12:40:35). Same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine via yahoo.com MX resolution. Static-only (CAPE skipped — no Windows guest).

What It Is

  • File: PE32 executable (GUI) Intel 80386, 5 sections, 18,944 bytes ^[file.txt]
  • Compiled: Fri May 29 12:39:58 2026 UTC (PE timestamp 0x6A19891E) ^[pefile.txt:34]
  • Toolchain: MSVC 9.0, MSVCR90.dll CRT, Windows GUI subsystem ^[rabin2-info.txt:11,17,32]
  • Linker version: 9.0 ^[pefile.txt:45]
  • Security: ASLR + NX enabled (DllCharacteristics: 0x8140), not signed ^[pefile.txt:67]
  • IAT surface: MSVCR90, WININET, SHLWAPI, WS2_32, DNSAPI, KERNEL32, USER32 — thin and honest ^[pefile.txt:229-390]

How It Works

Entry point follows standard MSVC C-runtime init (_initterm / _initterm_e) before reaching main at 0x00402740 ^[r2:entry0]. The bot is single-instance gated by mutex t10 (hardcoded at 0x00406020) ^[r2:str.t10]. If CreateMutexA returns ERROR_ALREADY_EXISTS (0xB7), the process exits immediately ^[r2:main@0x00402740].

On first launch:

  1. Sleeps 2,000 ms (Sleep(0x7d0)) — anti-emulation desync ^[r2:main@0x00402740]
  2. Deletes Zone.Identifier ADS from its own path via DeleteFileW with %s:Zone.Identifier format ^[r2:main@0x0040277e]
  3. Calls fcn.00401790 to resolve yahoo.com via DnsQuery_A (type DNS_TYPE_MX, value 0xf) and opens a TCP socket to port 25 ^[r2:fcn.00401790]
  4. If DNS fails, falls back to retrieving external IP via http://icanhazip.com/ using InternetOpenUrlA with Chrome/202.0.4664.110 UA ^[r2:fcn.00401800]
  5. Spawns the spam threadproc (fcn.004024e0) via CreateThread ^[r2:main@0x00402828]
  6. Main thread sleeps ~21,600,000 ms (0xcdfe600 = ~6 hours) and loops indefinitely ^[r2:main@0x00402831]

Threadproc (fcn.004024e0)

Seeds PRNG with GetTickCount, copies the email list path from a global buffer, expands %temp% to a wide path, and writes a numeric file %temp%\<n>.txt via InternetReadFile (the file appears to be a victim list fetched from a hardcoded URL, though the URL string is encrypted at rest). The threadproc then loops 100 times (outer), spawning 50 threads per iteration (inner) — 5,000 total SMTP workers. Each inner thread sleeps rand() % 50 + 50 ms between spawns. After each outer iteration, sleeps 20,000 ms (0x4e20). When complete, deletes the temp file and exits ^[r2:fcn.004024e0].

SMTP Engine (fcn.00401a10)

A state-machine driven SMTP client implementing the full mail transaction:

State Action
0 EHLO / HELO — probes for ESMTP in banner; falls back to HELO
2 MAIL FROM: <%s>
3 RCPT TO: <%s>
4 DATA
5 Message body assembly — full sextortion template with forged MailEnable/qmail Received headers, random alphanumeric Message-ID, Date, Subject
6 QUIT

The message body is constructed by concatenating static string blocks in fcn.00401a10 (case 5) ^[r2:fcn.00401a10]. Key elements:

  • Subject: YOU PERVERT! I RECORDED YOU! ^[strings.txt:146]
  • Body: Classic sextortion narrative — Trojan/RAT claims, camera recording threat, $800 USD BTC demand
  • BTC wallet: 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]
  • Exchange references: Coinbase, Binance, Bitrefill, Crypto.com, KuCoin, eToro, Kraken ^[strings.txt:49-56]
  • Fake UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/202.0.4664.110 ^[strings.txt:17]

String Decryption (fcn.00401030)

Same Tmlr XOR+NOT cipher observed across all $800 siblings. Key is 4 bytes at 0x4041c0 (Tmlr). Decoder iterates over input string via strlen, XORs each byte with key[i % 4], then applies bitwise NOT (~). The operation is its own inverse ^[r2:fcn.00401030].

C2 Infrastructure

  • MX resolution target: yahoo.com ^[strings.txt:16]
  • External IP check: http://icanhazip.com/ ^[strings.txt:18]
  • SMTP port: 25 (hardcoded, converted via htons) ^[r2:fcn.004010d0]
  • No direct C2 URL in the spam bot variant — it is self-contained, using victim lists from a file (likely fetched during downloader stage, not present in this binary)

Decompiled Behavior

Notable functions:

  • main (0x00402740) — entry logic, mutex gating, thread spawn, long sleep loop
  • fcn.00401790 — DNS MX query for yahoo.com, socket creation
  • fcn.00401800 — external IP fetch via WinInet (icanhazip.com)
  • fcn.004024e0 — threadproc: PRNG seed, temp-file staging, 5,000-thread dispatch
  • fcn.00401a10 — SMTP state machine: EHLO/HELO → MAIL FROM → RCPT TO → DATA → QUIT
  • fcn.00401030 — XOR+NOT string decoder with key Tmlr
  • fcn.004014c0 — RFC-2822 date formatter (Sun–Sat, Jan–Dec, timezone offset)
  • fcn.00401350 — random numeric string generator (used for Message-ID local-part)
  • fcn.004013c0 — random alphabetic string generator (used for Message-ID domain-part)
  • fcn.00401150 — send() wrapper with length validation
  • fcn.00401190 — recv() with select() timeout (30s)

Interesting Tidbits

  • Campaign burst sequencing: t10 at 12:39:58 fits squarely between t7 (12:36:22) and t11 (12:40:35), confirming continuous ~3–4 minute build intervals across the burst. The mutex naming (t1 through t13 plus 523535) is the only per-sample variable in an otherwise byte-identical stub.
  • Fake Chrome version: 202.0.4664.110 is impossible — Chrome major versions have never reached 202. This is a deliberate anti-signature choice or builder laziness.
  • No ZIP attachment: Unlike the earlier $1200 variant (150e4652), the $800 sub-cluster sends the extortion text inline as the email body, reducing SMTP complexity and avoiding attachment-based filtering.
  • MailEnable/qmail forgery: The Received header spoofs both MailEnable ESMTP and qmail, a dual-personality forgery that may help bypass simplistic SPF/DKIM checks.
  • Window title string: YOU PERVERT! I RECORDED YOU! appears in .data at 0x406000 and is referenced during email assembly, but no SetWindowText call is visible — it may be used by a downloader companion or simply left over from shared builder code.

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2008 (MSVC 9.0) or v90 platform toolset. Target: Win32 GUI.

Compiler flags: /O1 /GS- (size optimization, no buffer security check — the binary lacks stack cookies).

Working source snippet: See the reproduction notes in xor-not-string-decryption for the Tmlr cipher. To replicate the SMTP engine, use raw Winsock connect()/send()/recv() with a state machine loop and StrStrA banner parsing.

Verification: Compile a minimal SMTP client with the Tmlr decoder and compare section entropy, IAT shape, and string layout to this sample.

Deployable Signatures

YARA

rule phorpiex_sextortion_smtp_bot_800usd {
    meta:
        description = "Phorpiex campaign sextortion spam bot ($800 variant)"
        author = "PacketPursuit"
        date = "2026-09-04"
        sha256 = "724ec6b8cf5834d429ce360dc4427c8af4b1944cfe99020657f38ebb9b4b9d25"
    strings:
        $key = "Tmlr" ascii wide
        $ua = "Chrome/202.0.4664.110" ascii wide
        $btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
        $subj = "YOU PERVERT! I RECORDED YOU!" ascii
        $ehlo = "EHLO %s" ascii
        $mailfrom = "MAIL FROM: %s" ascii
        $rcptto = "RCPT TO: <%s>" ascii
        $yahoo = "yahoo.com" ascii
        $ipcheck = "http://icanhazip.com/" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.imports("MSVCR90.dll") and
        pe.imports("WS2_32.dll") and
        pe.imports("WININET.dll") and
        pe.imports("DNSAPI.dll") and
        4 of them
}

IOC List

Indicator Value Notes
SHA-256 724ec6b8cf5834d429ce360dc4427c8af4b1944cfe99020657f38ebb9b4b9d25 This sample
Mutex t10 Per-sample rotation (t1–t13, 523535)
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K Shared across all $800 siblings
Fake UA Mozilla/5.0 ... Chrome/202.0.4664.110 Impossible Chrome version
MX target yahoo.com Hardcoded DNS query
External IP icanhazip.com Fallback / reconnaissance
Temp file %temp%\<n>.txt Victim list staging
ADS deletion Zone.Identifier Evasion
Thread count 5,000 100 outer × 50 inner

Behavioral Fingerprint

This binary is a self-contained SMTP client that resolves yahoo.com MX records via DnsQuery_A, opens TCP/25 sockets, and implements a full EHLO/MAIL FROM/RCPT TO/DATA/QUIT transaction. The email body is an inline sextortion message demanding $800 in Bitcoin to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. It spawns 5,000 threads in a nested loop (100 × 50) with randomized 50–100 ms sleeps between spawns. Prior to network activity it sleeps 2 seconds, deletes its own Zone.Identifier ADS stream, and seeds PRNG with GetTickCount. No persistence mechanism is present in this stage; it is a pure spam-delivery payload likely dropped by a downloader companion.

Detection Signatures

Technique ID Evidence
User Execution: Malicious File T1204.002 Spam-distributed PE
Application Layer Protocol: DNS T1071.004 DnsQuery_A for yahoo.com MX
Ingress Tool Transfer T1105 Downloads victim list to %temp%
Exfiltration Over C2 T1041 SMTP data transmission
Anti-forensics: ADS deletion T1070.004 Zone.Identifier deletion
Scheduled Task/Job T1053 Inferred from campaign context

References

  • phorpiex — family entity
  • xor-not-string-decryption — build/RE technique page
  • /intel/analyses/724ec6b8cf5834d429ce360dc4427c8af4b1944cfe99020657f38ebb9b4b9d25.html — this analysis

Provenance

  • file.txt — file command output
  • pefile.txt — pefile.py dump
  • strings.txt — raw strings extraction
  • rabin2-info.txt — radare2 binary header
  • r2 decompile — radare2 pseudo-C (level-2 analysis, 78 functions)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)