b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95phorpiex: b221a625 — sextortion spam bot, mutex t12, 12:41:46 UTC campaign burst
Executive Summary
23rd confirmed Phorpiex campaign sample. Self-contained sextortion spam bot compiled with MSVC 9.0, linked to MSVCR90.dll, 18.9 KB. Hardcoded XOR+NOT decrypt key Tmlr, mutex t12, window title YOU PERVERT! I RECORDED YOU!, and BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Part of the May 29 2026 ~30-minute campaign burst (t1–t13 + numeric mutex variants). Static-only; CAPE skipped.
What It Is
| Attribute | Value |
|---|---|
| SHA-256 | b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95 |
| Size | 18,944 bytes |
| File type | PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt] |
| Compiler | MSVC 9.0 (linker 9.0) ^[pefile.txt] |
| Timestamp | 2026-05-29 12:41:46 UTC ^[pefile.txt] |
| CRT | MSVCR90.dll (static manifest, version 9.0.21022.8) ^[strings.txt:147] |
| Signed | No ^[rabin2-info.txt] |
| ASLR / DEP | Yes (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt] |
OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar. ^[metadata.json]
How It Works
Entry point → main(): standard MSVC CRT entry0 → main() flow. main() sleeps 2,000 ms, creates mutex t12, then branches on GetLastError() == ERROR_ALREADY_EXISTS (0xB7). If mutex exists, exits; otherwise proceeds. ^[r2:main]
Single-instance gating + anti-forensics: Before spawning threads, deletes its own :Zone.Identifier ADS via DeleteFileW with a wsprintfW-formatted path. ^[r2:main]
External IP resolution: Calls fcn.00401800, which opens a WinInet session with UA Mozilla/5.0 ... Chrome/202.0.4664.110 ... ^[strings.txt:17], fetches http://icanhazip.com/, parses the dotted-quad response, and wraps it as [x.x.x.x]. Falls back to [0.0.0.0] on failure. ^[r2:fcn.00401800]
MX query: Calls fcn.00401790, which queries yahoo.com (type MX, 0x0F) via DnsQuery_A. On success, opens a TCP socket to the resolved MX and passes it to the SMTP engine. ^[r2:fcn.00401790]
String decryption: fcn.00401030 implements a 4-byte XOR+NOT loop using key Tmlr. Each input byte is XORed with the key byte (cycling), then NOTed. ^[r2:fcn.00401030]
SMTP engine: fcn.00401a10 runs a 7-case state machine over raw TCP socket I/O:
- Parse banner → detect
ESMTP EHLO %sorHELO %sMAIL FROM: <%s>RCPT TO: <%s>DATA- Assemble full RFC-822 message with spoofed
Received:headers, random local-part generation (fcn.004013c0produces 3–15 lowercase chars), and the hardcoded sextortion body QUIT
The message body is the standard Phorpiex sextortion template: claims R.A.T. infection, camera recording, demands $800 USD in BTC to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, with purchase links for Coinbase, Binance, Bitrefill, Crypto.com, Kucoin, eToro, Kraken. ^[strings.txt:36-61]
Thread dispatch: fcn.004024e0 (thread proc) loops 100×50 = 5,000 thread spawns. Each thread re-reads the victim count from %TEMP%\<n>.txt, sleeps a random 0–100 ms between spawns, and after 100 outer iterations sleeps 20,000 ms before re-reading the count and exiting if count ≤ 1. ^[r2:fcn.004024e0]
Downloader helper: fcn.00401900 fetches payloads via WinInet (InternetOpenW/InternetOpenUrlW/InternetReadFile) with the same Chrome/202 UA, writes to a CreateFileW handle. Used for potential payload updates. ^[r2:fcn.00401900]
Decompiled Behavior
- entry0 @ 0x402bb7: Standard MSVC 9.0 CRT startup. No
inittermhijack — honestmain()flow. ^[r2:entry0] - main @ 0x402740: Sleep → mutex → Zone.Identifier deletion → WSAStartup → MX query → decrypt → thread spawn. ^[r2:main]
- fcn.00401030: XOR+NOT string decryptor with key
Tmlr. ^[r2:fcn.00401030] - fcn.00401790: DNS MX query for
yahoo.com. ^[r2:fcn.00401790] - fcn.00401800: HTTP GET to
icanhazip.comfor external IP. ^[r2:fcn.00401800] - fcn.00401900: WinInet downloader (payload fetcher). ^[r2:fcn.00401900]
- fcn.00401a10: Raw TCP SMTP client with 7-case state machine. ^[r2:fcn.00401a10]
- fcn.004024e0: Thread proc — 5,000-thread spam dispatch loop. ^[r2:fcn.004024e0]
C2 Infrastructure
| IOC | Value | Source |
|---|---|---|
| MX target | yahoo.com |
^[strings.txt:16] |
| External IP check | http://icanhazip.com/ |
^[strings.txt:18] |
| Fake UA | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/202.0.4664.110 Safari/537.36 |
^[strings.txt:17] |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
^[strings.txt:59] |
| Mutex | t12 |
^[r2:main] |
| Decrypt key | Tmlr |
^[strings.txt:160], ^[r2:fcn.00401030] |
| Window title | YOU PERVERT! I RECORDED YOU! |
^[strings.txt:146] |
| Ransom demand | $800 USD |
^[strings.txt:46] |
No ZIP attachment — email body is inline text (ZIP-less variant, matching t1–t13 sub-cluster).
Interesting Tidbits
- Campaign burst timing: Compiled at 12:41:46 UTC, between
t5(12:34:02) andt13(12:42:51). This fills a ~7-minute gap in the documented burst, confirming continuous builder rotation. ^[pefile.txt] - No ZIP constructor: Unlike the
150e4652$1200 variant, this sample omits the ZIP attachment builder. Inline text only, reducing binary size to 18.9 KB. - Identical
.texthash expected: Prior siblings in the $800 sub-cluster share an identical.textsection (same SMTP engine code). Likely true here too — the.textentropy of 5.99 is consistent with the cluster. ^[pefile.txt] - Chrome/202 UA: Impossible Chrome version (202.x) used across the entire May 29 burst. The builder hardcodes this; no UA rotation per sample. ^[strings.txt:17]
- Window title in .data: The
YOU PERVERT!string lives at 0x4000 in the.datasection, confirming it's part of the decrypted payload rather than the raw binary — consistent with the XOR+NOT obfuscation pattern. ^[strings.txt:146]
How To Mess With It
Toolchain: MSVC 9.0 (Visual Studio 2008), x86, Windows GUI subsystem.
Replication sketch: Compile a minimal Win32 PE with WinInet + WS2_32 + DNSAPI imports. Implement a 7-case SMTP state machine over raw TCP. Use DnsQuery_A for MX resolution. Use InternetOpenA/InternetReadFile for IP check. The XOR+NOT decryptor is trivial: for (i=0; s[i]; i++) s[i] = ~(s[i] ^ key[i % 4]);.
Verification: Build a test binary with the same import set and a hardcoded Tmlr key. Run strings — the key should appear plaintext. Compare section entropy to sibling t5 (.text ~5.99).
Deployable Signatures
YARA Rule
rule Phorpiex_Sextortion_SpamBot_May2026 {
meta:
description = "Phorpiex sextortion spam bot — May 2026 campaign burst"
author = "PacketPursuit SOC"
date = "2026-09-04"
sha256 = "b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95"
strings:
$key = "Tmlr" ascii wide
$ua = "Chrome/202.0.4664.110" ascii wide
$mx = "yahoo.com" ascii wide
$btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii wide
$title = "YOU PERVERT! I RECORDED YOU!" ascii wide
$ehlo = "EHLO %s" ascii
$mailfrom = "MAIL FROM: %s" ascii
$rcptto = "RCPT TO: <%s>" ascii
$data = "DATA\r\n" ascii
$quit = "QUIT" ascii
$ipcheck = "http://icanhazip.com/" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
$key and
($ua or $btc or $title) and
3 of ($ehlo, $mailfrom, $rcptto, $data, $quit)
}
IOC List
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | hash | b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95 |
| SHA-1 | hash | 4a077a0ed10d4bf84244f50e243608c8a41734bd (.text) |
| MD5 | hash | 787720059300256f7d5e3159ccbe51d7 (.text) |
| Mutex | mutex | t12 |
| BTC wallet | cryptocurrency | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
| Fake UA | network | Mozilla/5.0 ... Chrome/202.0.4664.110 ... |
| MX target | network | yahoo.com |
| External IP check | network | http://icanhazip.com/ |
| Window title | string | YOU PERVERT! I RECORDED YOU! |
| Decrypt key | string | Tmlr |
Behavioral Fingerprint
A PE32 GUI executable compiled with MSVC 9.0 and linked to MSVCR90.dll, approximately 18–19 KB. On launch it sleeps 2 seconds, creates a single-instance ASCII mutex (pattern t[0-9]+ or numeric), deletes its own :Zone.Identifier ADS, queries yahoo.com MX records via DnsQuery_A, resolves its external IP via http://icanhazip.com/ using a hardcoded Chrome/202 UA, decrypts embedded strings with a 4-byte XOR+NOT key (observed: Tmlr), then spawns up to 5,000 threads delivering inline-text sextortion emails via raw TCP SMTP. The email demands $800–$1200 USD in Bitcoin to a hardcoded wallet and includes purchase links for major exchanges. No ZIP attachment in the $800 variant cluster.
Detection Signatures
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | Spam-distributed PE |
| Application Layer Protocol: SMTP | T1071.003 | Raw TCP SMTP client |
| OS Credential Dumping | T1003 | Claims access to files/accounts (social engineering) |
| Data from Local System | T1005 | Reads %TEMP%\<n>.txt for victim count |
| Ingress Tool Transfer | T1105 | WinInet downloader (fcn.00401900) |
| Network Service Scanning | T1046 | MX query for yahoo.com |
| Scheduled Task/Job | T1053 | Inferred from historical Phorpiex reporting |
| Defense Evasion: Delete Indicator | T1070.004 | Deletes :Zone.Identifier ADS |
References
- phorpiex — campaign umbrella entity
- smtp-exfiltration — raw TCP SMTP delivery pattern
- OpenCTI artifact:
622012dc-4a21-4e51-9962-92fa0f4a3eca - MalwareBazaar:
b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95
Provenance
Analysis based on static artifacts: file.txt, strings.txt, pefile.txt, rabin2-info.txt, metadata.json, triage.json, yara.txt, capa.txt (failed — missing signatures), floss.txt (failed — bad CLI flags). Decompilation via radare2 (r2mcp) at analysis level 3, 78 functions recovered. No dynamic execution — CAPE skipped (no Windows guest available). All claims cite ^[source] markers.