8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29cphorpiex: 8f257c0e — sextortion spam bot $800 variant, mutex t9
Executive Summary: MSVC 9.0 PE32 GUI sextortion spam bot, 18.9 KB, compiled 2026-05-29 12:37:51 UTC. Mutex t9; eleventh confirmed sibling in the $800 sub-cluster. Same Tmlr XOR+NOT string-decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP dispatch engine via yahoo.com MX resolution. Window title string YOU PERVERT! I RECORDED YOU! present (also in t1, t7, t10–t13). Static-only — CAPE skipped (no Windows guest).
What It Is
- File: PE32 executable (GUI) Intel 80386, 5 sections, 18,944 bytes ^[file.txt]
- Toolchain: MSVC 9.0 / MSVCR90.dll static CRT, LinkerVersion 9.0, compiled Fri May 29 12:37:51 2026 UTC ^[pefile.txt:34] ^[exiftool.json:15]
- Entry point:
0x2bb7(CRTmainafterinittermboilerplate) ^[rabin2-info.txt:5] - No packing, no signing, no anti-debug/VM beyond
IsDebuggerPresentimport (unreached in static view) ^[rabin2-info.txt:27] ^[rabin2-info.txt:21] - IAT surface: MSVCR90, WININET, SHLWAPI, WS2_32, DNSAPI, KERNEL32, USER32 ^[rabin2-info.txt — import list]
- YARA:
PE_File_Generic,Suspicious_Wininet_Imports^[yara.txt] - OpenCTI labels:
dropped-by-phorpiex,exe,malware-bazaar^[metadata.json]
How It Works
Entry Flow (main @ 0x00402740)
- Sleep 2,000 ms — anti-emulation gate before any meaningful work. ^[r2:main]
- Mutex gating —
CreateMutexA("t9"); ifGetLastError() == ERROR_ALREADY_EXISTS (0xB7), exits. ^[r2:main] - Zone.Identifier deletion — builds
%s:Zone.Identifierpath from own module filename and deletes the ADS. ^[r2:main] - Winsock init —
WSAStartup(0x202, &wsadata). ^[r2:main] - External IP fetch — calls
fcn.00401800which fetcheshttp://icanhazip.com/via WinInet (InternetOpenAwith fake Chrome/202 UA) and wraps the result in[<ip>]. Falls back to[0.0.0.0]. ^[r2:fcn.00401800] - Thread storm — decrypts the SMTP server string then launches 50 inner threads (
fcn.00402340) in an outer loop of 100 iterations (5,000 total threads), each thread sleepsrand() % 50 + 50ms between spawns. ^[r2:fcn.004024e0] - Main thread sleeps —
Sleep(0xcdfe600)(~216 million ms ≈ 60 hours), then exits. ^[r2:main]
String Decryption (fcn.00401030)
- Key:
Tmlr\x00(4 bytes + null) ^[r2:fcn.00401030] ^[strings.txt:147] - Algorithm: XOR each byte of ciphertext with corresponding key byte, cycling through key length. After XOR, apply bitwise NOT (
~). Confirmed identical to siblingsedd6ad22,150e4652,c3b1b4e4, etc. ^[r2:fcn.00401030]
SMTP Spam Engine (fcn.00402340 → fcn.00401a10)
- Target domain:
yahoo.com(hardcoded, resolved viaDnsQuery_Afor MX records) ^[r2:fcn.00401790] - Recipients: read from
%TEMP%\<rand>n.txt— a file generated earlier containing email addresses (format: one per line,:delimited with local-part and domain). ^[r2:fcn.004024e0] - SMTP state machine (7 states via switch/jump table in
fcn.00401a10): 0. ParseESMTPbanner viaStrStrAEHLO <domain>orHELO <domain>MAIL FROM: <%s>RCPT TO: <%s>DATA- Message body assembly — full sextortion template with forged headers (MailEnable/qmail Received lines, randomized Message-ID, Date, Subject)
QUIT
- Email body: Standard Phorpiex sextortion template — $800 BTC demand, hardcoded wallet
1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, six exchange URLs (coinbase, binance, bitrefill, crypto.com, kucoin, etoro, kraken). ^[strings.txt:37-60] - Subject line:
YOU PERVERT! I RECORDED YOU!^[strings.txt:146] ^[r2:fcn.00401a10] - Fake User-Agent:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36^[strings.txt:17]
Network IOCs
| Indicator | Value | Provenance |
|---|---|---|
| SMTP target domain | yahoo.com |
^[strings.txt:16] |
| External IP check | http://icanhazip.com/ |
^[strings.txt:18] |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
^[strings.txt:59] |
| Mutex | t9 |
^[r2:main] |
| Staging file | %TEMP%\%sn.txt |
^[strings.txt:162] |
| Fake UA | Chrome/202.0.4664.110 |
^[strings.txt:17] |
Decompiled Behavior
See phorpiex entity page for shared cluster analysis. Per-sample deltas:
- Mutex
t9— new in this sample; no priort9observed in the $800 sub-cluster. Sits betweent7(12:36:22) andt10(12:39:58) chronologically, confirming the campaign burst rotated mutex names on ~3-minute intervals. ^[r2:main] - Window title
YOU PERVERT! I RECORDED YOU!— present (also in t1, t7, t10–t13, 523535). This is a builder toggle, not a code delta. ^[strings.txt:146] - Decrypt key
Tmlr— identical to all $800 siblings. ^[r2:fcn.00401030] - Thread count 5,000 (50 × 100) — same as t5, t7, t10–t13. ^[r2:fcn.004024e0]
- No ZIP attachment — email body is inline text/plain, consistent with post-t5 builds. ^[r2:fcn.00401a10]
Interesting Tidbits
- Timestamp precision: compiled at 12:37:51 UTC, exactly 1 minute 29 seconds after
t7(12:36:22) and 2 minutes 7 seconds beforet10(12:39:58). The builder is clearly parameter-rotating in a tight loop. ^[pefile.txt:34] - PE Checksum:
0x14106— unique to this sample (not shared with any sibling). ^[pefile.txt:65] - Floss failure:
floss.txtcontains only CLI error output (invalid--noargument parse), meaning decoded strings were not recovered by the automated pipeline. The decrypt keyTmlrwas recovered from raw strings and confirmed via static decompilation. ^[floss.txt] - Capa failure: signatures path missing; no capability report generated. ^[capa.txt]
- No
.rsrcpayload:.rsrcsection is only 688 bytes (manifest + version info padding), confirming this is a self-contained spam bot, not a dropper. ^[pefile.txt]
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2008 (MSVC 9.0) with /MT static CRT, 32-bit Release.
Source sketch (simplified decrypt loop):
void decrypt(char *buf, size_t len) {
const char key[] = "Tmlr";
for (size_t i = 0; i < len; i++) {
buf[i] ^= key[i % 4];
buf[i] = ~buf[i];
}
}
Verification: XOR the ciphertext bytes at 0x40602c (SMTP server string) with Tmlr then NOT; result should be yahoo.com.
Deployable Signatures
YARA
rule phorpiex_sextortion_800_t9 {
meta:
description = "Phorpiex sextortion spam bot $800 variant, mutex t9"
author = "titus"
date = "2026-09-05"
sha256 = "8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c"
strings:
$mut = "t9" ascii wide
$ua = "Chrome/202.0.4664.110 Safari/537.36" ascii
$btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
$subj = "YOU PERVERT! I RECORDED YOU!" ascii
$key = "Tmlr" ascii
$ehlo = "EHLO %s\r\n" ascii
$rcpt = "RCPT TO: <%s>\r\n" ascii
condition:
uint16(0) == 0x5A4D and
filesize < 25KB and
all of ($mut, $ua, $btc, $subj, $key) and
2 of ($ehlo, $rcpt)
}
IOCs
| Type | Value |
|---|---|
| SHA-256 | 8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c |
| Mutex | t9 |
| BTC | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
| Domain | yahoo.com (MX resolution target) |
| URL | http://icanhazip.com/ (external IP check) |
| Fake UA | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 |
| Staging file | %TEMP%\<rand>n.txt |
Behavioral Fingerprint
On launch, this binary sleeps 2 seconds, creates mutex t9, deletes its own Zone.Identifier ADS, initializes Winsock, fetches external IP from icanhazip.com via WinInet with a fake Chrome/202 UA, then spawns 5,000 threads over ~100 iterations. Each thread reads email addresses from %TEMP%\<rand>n.txt and delivers sextortion emails via direct SMTP to yahoo.com MX servers using a hardcoded template with $800 BTC demand and subject YOU PERVERT! I RECORDED YOU!. The main thread then sleeps ~60 hours before exiting.
Detection Signatures (ATT&CK)
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | Spam-distributed PE ^[file.txt] |
| Application Layer Protocol: Email | T1071.003 | Self-contained SMTP client ^[r2:fcn.00401a10] |
| Data from Local System | T1005 | Reads %TEMP%\*.txt for recipient list ^[r2:fcn.004024e0] |
| Ingress Tool Transfer | T1105 | None observed (self-contained, no downloader) |
| Impact: Extortion | T1491 | Sextortion email with BTC wallet ^[strings.txt:37-60] |
| Defense Evasion: Delete Indicator | T1070.004 | Deletes Zone.Identifier ADS ^[r2:main] |
| Discovery: System Network Config | T1016 | Queries yahoo.com MX via DnsQuery_A ^[r2:fcn.00401790] |
| Command and Control | T1071 | SMTP C2 to public mail servers ^[r2:fcn.00401a10] |
References
- phorpiex — Cluster entity page with shared build/behavior analysis
- techniques/xor-not-string-decryption — Decrypt-key technique page
- Artifact ID:
82357237-8819-4f15-b213-e3d3b9dcbd2d(OpenCTI) - Source: MalwareBazaar / OpenCTI
dropped-by-phorpiexpipeline
Provenance
Static analysis performed with radare2 (analysis level 3, 78 functions recovered). FLOSS and capa tools failed in the triage pipeline (invalid CLI arguments and missing signature paths, respectively) — all string and behavioral claims are derived from radare2 decompilation and raw strings.txt. CAPE sandbox skipped due to no Windows guest available. No dynamic execution data available.