typeanalysisfamilyphorpiexconfidencehighcreated2026-09-05updated2026-09-05pemalware-familyc2persistenceimpactmitre-attck
SHA-256: 8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c

phorpiex: 8f257c0e — sextortion spam bot $800 variant, mutex t9

Executive Summary: MSVC 9.0 PE32 GUI sextortion spam bot, 18.9 KB, compiled 2026-05-29 12:37:51 UTC. Mutex t9; eleventh confirmed sibling in the $800 sub-cluster. Same Tmlr XOR+NOT string-decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP dispatch engine via yahoo.com MX resolution. Window title string YOU PERVERT! I RECORDED YOU! present (also in t1, t7, t10–t13). Static-only — CAPE skipped (no Windows guest).

What It Is

  • File: PE32 executable (GUI) Intel 80386, 5 sections, 18,944 bytes ^[file.txt]
  • Toolchain: MSVC 9.0 / MSVCR90.dll static CRT, LinkerVersion 9.0, compiled Fri May 29 12:37:51 2026 UTC ^[pefile.txt:34] ^[exiftool.json:15]
  • Entry point: 0x2bb7 (CRT main after initterm boilerplate) ^[rabin2-info.txt:5]
  • No packing, no signing, no anti-debug/VM beyond IsDebuggerPresent import (unreached in static view) ^[rabin2-info.txt:27] ^[rabin2-info.txt:21]
  • IAT surface: MSVCR90, WININET, SHLWAPI, WS2_32, DNSAPI, KERNEL32, USER32 ^[rabin2-info.txt — import list]
  • YARA: PE_File_Generic, Suspicious_Wininet_Imports ^[yara.txt]
  • OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]

How It Works

Entry Flow (main @ 0x00402740)

  1. Sleep 2,000 ms — anti-emulation gate before any meaningful work. ^[r2:main]
  2. Mutex gating — CreateMutexA("t9"); if GetLastError() == ERROR_ALREADY_EXISTS (0xB7), exits. ^[r2:main]
  3. Zone.Identifier deletion — builds %s:Zone.Identifier path from own module filename and deletes the ADS. ^[r2:main]
  4. Winsock init — WSAStartup(0x202, &wsadata). ^[r2:main]
  5. External IP fetch — calls fcn.00401800 which fetches http://icanhazip.com/ via WinInet (InternetOpenA with fake Chrome/202 UA) and wraps the result in [<ip>]. Falls back to [0.0.0.0]. ^[r2:fcn.00401800]
  6. Thread storm — decrypts the SMTP server string then launches 50 inner threads (fcn.00402340) in an outer loop of 100 iterations (5,000 total threads), each thread sleeps rand() % 50 + 50 ms between spawns. ^[r2:fcn.004024e0]
  7. Main thread sleeps — Sleep(0xcdfe600) (~216 million ms ≈ 60 hours), then exits. ^[r2:main]

String Decryption (fcn.00401030)

  • Key: Tmlr\x00 (4 bytes + null) ^[r2:fcn.00401030] ^[strings.txt:147]
  • Algorithm: XOR each byte of ciphertext with corresponding key byte, cycling through key length. After XOR, apply bitwise NOT (~). Confirmed identical to siblings edd6ad22, 150e4652, c3b1b4e4, etc. ^[r2:fcn.00401030]

SMTP Spam Engine (fcn.00402340 → fcn.00401a10)

  • Target domain: yahoo.com (hardcoded, resolved via DnsQuery_A for MX records) ^[r2:fcn.00401790]
  • Recipients: read from %TEMP%\<rand>n.txt — a file generated earlier containing email addresses (format: one per line, : delimited with local-part and domain). ^[r2:fcn.004024e0]
  • SMTP state machine (7 states via switch/jump table in fcn.00401a10): 0. Parse ESMTP banner via StrStrA
    1. EHLO <domain> or HELO <domain>
    2. MAIL FROM: <%s>
    3. RCPT TO: <%s>
    4. DATA
    5. Message body assembly — full sextortion template with forged headers (MailEnable/qmail Received lines, randomized Message-ID, Date, Subject)
    6. QUIT
  • Email body: Standard Phorpiex sextortion template — $800 BTC demand, hardcoded wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, six exchange URLs (coinbase, binance, bitrefill, crypto.com, kucoin, etoro, kraken). ^[strings.txt:37-60]
  • Subject line: YOU PERVERT! I RECORDED YOU! ^[strings.txt:146] ^[r2:fcn.00401a10]
  • Fake User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 ^[strings.txt:17]

Network IOCs

Indicator Value Provenance
SMTP target domain yahoo.com ^[strings.txt:16]
External IP check http://icanhazip.com/ ^[strings.txt:18]
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]
Mutex t9 ^[r2:main]
Staging file %TEMP%\%sn.txt ^[strings.txt:162]
Fake UA Chrome/202.0.4664.110 ^[strings.txt:17]

Decompiled Behavior

See phorpiex entity page for shared cluster analysis. Per-sample deltas:

  • Mutex t9 — new in this sample; no prior t9 observed in the $800 sub-cluster. Sits between t7 (12:36:22) and t10 (12:39:58) chronologically, confirming the campaign burst rotated mutex names on ~3-minute intervals. ^[r2:main]
  • Window title YOU PERVERT! I RECORDED YOU! — present (also in t1, t7, t10–t13, 523535). This is a builder toggle, not a code delta. ^[strings.txt:146]
  • Decrypt key Tmlr — identical to all $800 siblings. ^[r2:fcn.00401030]
  • Thread count 5,000 (50 × 100) — same as t5, t7, t10–t13. ^[r2:fcn.004024e0]
  • No ZIP attachment — email body is inline text/plain, consistent with post-t5 builds. ^[r2:fcn.00401a10]

Interesting Tidbits

  • Timestamp precision: compiled at 12:37:51 UTC, exactly 1 minute 29 seconds after t7 (12:36:22) and 2 minutes 7 seconds before t10 (12:39:58). The builder is clearly parameter-rotating in a tight loop. ^[pefile.txt:34]
  • PE Checksum: 0x14106 — unique to this sample (not shared with any sibling). ^[pefile.txt:65]
  • Floss failure: floss.txt contains only CLI error output (invalid --no argument parse), meaning decoded strings were not recovered by the automated pipeline. The decrypt key Tmlr was recovered from raw strings and confirmed via static decompilation. ^[floss.txt]
  • Capa failure: signatures path missing; no capability report generated. ^[capa.txt]
  • No .rsrc payload: .rsrc section is only 688 bytes (manifest + version info padding), confirming this is a self-contained spam bot, not a dropper. ^[pefile.txt]

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2008 (MSVC 9.0) with /MT static CRT, 32-bit Release.

Source sketch (simplified decrypt loop):

void decrypt(char *buf, size_t len) {
    const char key[] = "Tmlr";
    for (size_t i = 0; i < len; i++) {
        buf[i] ^= key[i % 4];
        buf[i] = ~buf[i];
    }
}

Verification: XOR the ciphertext bytes at 0x40602c (SMTP server string) with Tmlr then NOT; result should be yahoo.com.

Deployable Signatures

YARA

rule phorpiex_sextortion_800_t9 {
    meta:
        description = "Phorpiex sextortion spam bot $800 variant, mutex t9"
        author = "titus"
        date = "2026-09-05"
        sha256 = "8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c"
    strings:
        $mut = "t9" ascii wide
        $ua = "Chrome/202.0.4664.110 Safari/537.36" ascii
        $btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
        $subj = "YOU PERVERT! I RECORDED YOU!" ascii
        $key = "Tmlr" ascii
        $ehlo = "EHLO %s\r\n" ascii
        $rcpt = "RCPT TO: <%s>\r\n" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize < 25KB and
        all of ($mut, $ua, $btc, $subj, $key) and
        2 of ($ehlo, $rcpt)
}

IOCs

Type Value
SHA-256 8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c
Mutex t9
BTC 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K
Domain yahoo.com (MX resolution target)
URL http://icanhazip.com/ (external IP check)
Fake UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36
Staging file %TEMP%\<rand>n.txt

Behavioral Fingerprint

On launch, this binary sleeps 2 seconds, creates mutex t9, deletes its own Zone.Identifier ADS, initializes Winsock, fetches external IP from icanhazip.com via WinInet with a fake Chrome/202 UA, then spawns 5,000 threads over ~100 iterations. Each thread reads email addresses from %TEMP%\<rand>n.txt and delivers sextortion emails via direct SMTP to yahoo.com MX servers using a hardcoded template with $800 BTC demand and subject YOU PERVERT! I RECORDED YOU!. The main thread then sleeps ~60 hours before exiting.

Detection Signatures (ATT&CK)

Technique ID Evidence
User Execution: Malicious File T1204.002 Spam-distributed PE ^[file.txt]
Application Layer Protocol: Email T1071.003 Self-contained SMTP client ^[r2:fcn.00401a10]
Data from Local System T1005 Reads %TEMP%\*.txt for recipient list ^[r2:fcn.004024e0]
Ingress Tool Transfer T1105 None observed (self-contained, no downloader)
Impact: Extortion T1491 Sextortion email with BTC wallet ^[strings.txt:37-60]
Defense Evasion: Delete Indicator T1070.004 Deletes Zone.Identifier ADS ^[r2:main]
Discovery: System Network Config T1016 Queries yahoo.com MX via DnsQuery_A ^[r2:fcn.00401790]
Command and Control T1071 SMTP C2 to public mail servers ^[r2:fcn.00401a10]

References

  • phorpiex — Cluster entity page with shared build/behavior analysis
  • techniques/xor-not-string-decryption — Decrypt-key technique page
  • Artifact ID: 82357237-8819-4f15-b213-e3d3b9dcbd2d (OpenCTI)
  • Source: MalwareBazaar / OpenCTI dropped-by-phorpiex pipeline

Provenance

Static analysis performed with radare2 (analysis level 3, 78 functions recovered). FLOSS and capa tools failed in the triage pipeline (invalid CLI arguments and missing signature paths, respectively) — all string and behavioral claims are derived from radare2 decompilation and raw strings.txt. CAPE sandbox skipped due to no Windows guest available. No dynamic execution data available.