typeanalysisfamilyphorpiexconfidencehighmalware-familyloadermalware-bazaarattributionsextortionsmtp-exfiltrationc2defense-evasion
SHA-256: b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95

phorpiex: b221a625 — sextortion spam bot, mutex t12, 12:41:46 UTC campaign burst

Executive Summary

23rd confirmed Phorpiex campaign sample. Self-contained sextortion spam bot compiled with MSVC 9.0, linked to MSVCR90.dll, 18.9 KB. Hardcoded XOR+NOT decrypt key Tmlr, mutex t12, window title YOU PERVERT! I RECORDED YOU!, and BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Part of the May 29 2026 ~30-minute campaign burst (t1–t13 + numeric mutex variants). Static-only; CAPE skipped.

What It Is

Attribute Value
SHA-256 b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95
Size 18,944 bytes
File type PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
Compiler MSVC 9.0 (linker 9.0) ^[pefile.txt]
Timestamp 2026-05-29 12:41:46 UTC ^[pefile.txt]
CRT MSVCR90.dll (static manifest, version 9.0.21022.8) ^[strings.txt:147]
Signed No ^[rabin2-info.txt]
ASLR / DEP Yes (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt]

OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar. ^[metadata.json]

How It Works

Entry point → main(): standard MSVC CRT entry0 → main() flow. main() sleeps 2,000 ms, creates mutex t12, then branches on GetLastError() == ERROR_ALREADY_EXISTS (0xB7). If mutex exists, exits; otherwise proceeds. ^[r2:main]

Single-instance gating + anti-forensics: Before spawning threads, deletes its own :Zone.Identifier ADS via DeleteFileW with a wsprintfW-formatted path. ^[r2:main]

External IP resolution: Calls fcn.00401800, which opens a WinInet session with UA Mozilla/5.0 ... Chrome/202.0.4664.110 ... ^[strings.txt:17], fetches http://icanhazip.com/, parses the dotted-quad response, and wraps it as [x.x.x.x]. Falls back to [0.0.0.0] on failure. ^[r2:fcn.00401800]

MX query: Calls fcn.00401790, which queries yahoo.com (type MX, 0x0F) via DnsQuery_A. On success, opens a TCP socket to the resolved MX and passes it to the SMTP engine. ^[r2:fcn.00401790]

String decryption: fcn.00401030 implements a 4-byte XOR+NOT loop using key Tmlr. Each input byte is XORed with the key byte (cycling), then NOTed. ^[r2:fcn.00401030]

SMTP engine: fcn.00401a10 runs a 7-case state machine over raw TCP socket I/O:

  1. Parse banner → detect ESMTP
  2. EHLO %s or HELO %s
  3. MAIL FROM: <%s>
  4. RCPT TO: <%s>
  5. DATA
  6. Assemble full RFC-822 message with spoofed Received: headers, random local-part generation (fcn.004013c0 produces 3–15 lowercase chars), and the hardcoded sextortion body
  7. QUIT

The message body is the standard Phorpiex sextortion template: claims R.A.T. infection, camera recording, demands $800 USD in BTC to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, with purchase links for Coinbase, Binance, Bitrefill, Crypto.com, Kucoin, eToro, Kraken. ^[strings.txt:36-61]

Thread dispatch: fcn.004024e0 (thread proc) loops 100×50 = 5,000 thread spawns. Each thread re-reads the victim count from %TEMP%\<n>.txt, sleeps a random 0–100 ms between spawns, and after 100 outer iterations sleeps 20,000 ms before re-reading the count and exiting if count ≤ 1. ^[r2:fcn.004024e0]

Downloader helper: fcn.00401900 fetches payloads via WinInet (InternetOpenW/InternetOpenUrlW/InternetReadFile) with the same Chrome/202 UA, writes to a CreateFileW handle. Used for potential payload updates. ^[r2:fcn.00401900]

Decompiled Behavior

  • entry0 @ 0x402bb7: Standard MSVC 9.0 CRT startup. No initterm hijack — honest main() flow. ^[r2:entry0]
  • main @ 0x402740: Sleep → mutex → Zone.Identifier deletion → WSAStartup → MX query → decrypt → thread spawn. ^[r2:main]
  • fcn.00401030: XOR+NOT string decryptor with key Tmlr. ^[r2:fcn.00401030]
  • fcn.00401790: DNS MX query for yahoo.com. ^[r2:fcn.00401790]
  • fcn.00401800: HTTP GET to icanhazip.com for external IP. ^[r2:fcn.00401800]
  • fcn.00401900: WinInet downloader (payload fetcher). ^[r2:fcn.00401900]
  • fcn.00401a10: Raw TCP SMTP client with 7-case state machine. ^[r2:fcn.00401a10]
  • fcn.004024e0: Thread proc — 5,000-thread spam dispatch loop. ^[r2:fcn.004024e0]

C2 Infrastructure

IOC Value Source
MX target yahoo.com ^[strings.txt:16]
External IP check http://icanhazip.com/ ^[strings.txt:18]
Fake UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/202.0.4664.110 Safari/537.36 ^[strings.txt:17]
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]
Mutex t12 ^[r2:main]
Decrypt key Tmlr ^[strings.txt:160], ^[r2:fcn.00401030]
Window title YOU PERVERT! I RECORDED YOU! ^[strings.txt:146]
Ransom demand $800 USD ^[strings.txt:46]

No ZIP attachment — email body is inline text (ZIP-less variant, matching t1–t13 sub-cluster).

Interesting Tidbits

  • Campaign burst timing: Compiled at 12:41:46 UTC, between t5 (12:34:02) and t13 (12:42:51). This fills a ~7-minute gap in the documented burst, confirming continuous builder rotation. ^[pefile.txt]
  • No ZIP constructor: Unlike the 150e4652 $1200 variant, this sample omits the ZIP attachment builder. Inline text only, reducing binary size to 18.9 KB.
  • Identical .text hash expected: Prior siblings in the $800 sub-cluster share an identical .text section (same SMTP engine code). Likely true here too — the .text entropy of 5.99 is consistent with the cluster. ^[pefile.txt]
  • Chrome/202 UA: Impossible Chrome version (202.x) used across the entire May 29 burst. The builder hardcodes this; no UA rotation per sample. ^[strings.txt:17]
  • Window title in .data: The YOU PERVERT! string lives at 0x4000 in the .data section, confirming it's part of the decrypted payload rather than the raw binary — consistent with the XOR+NOT obfuscation pattern. ^[strings.txt:146]

How To Mess With It

Toolchain: MSVC 9.0 (Visual Studio 2008), x86, Windows GUI subsystem.

Replication sketch: Compile a minimal Win32 PE with WinInet + WS2_32 + DNSAPI imports. Implement a 7-case SMTP state machine over raw TCP. Use DnsQuery_A for MX resolution. Use InternetOpenA/InternetReadFile for IP check. The XOR+NOT decryptor is trivial: for (i=0; s[i]; i++) s[i] = ~(s[i] ^ key[i % 4]);.

Verification: Build a test binary with the same import set and a hardcoded Tmlr key. Run strings — the key should appear plaintext. Compare section entropy to sibling t5 (.text ~5.99).

Deployable Signatures

YARA Rule

rule Phorpiex_Sextortion_SpamBot_May2026 {
    meta:
        description = "Phorpiex sextortion spam bot — May 2026 campaign burst"
        author = "PacketPursuit SOC"
        date = "2026-09-04"
        sha256 = "b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95"
    strings:
        $key = "Tmlr" ascii wide
        $ua = "Chrome/202.0.4664.110" ascii wide
        $mx = "yahoo.com" ascii wide
        $btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii wide
        $title = "YOU PERVERT! I RECORDED YOU!" ascii wide
        $ehlo = "EHLO %s" ascii
        $mailfrom = "MAIL FROM: %s" ascii
        $rcptto = "RCPT TO: <%s>" ascii
        $data = "DATA\r\n" ascii
        $quit = "QUIT" ascii
        $ipcheck = "http://icanhazip.com/" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        $key and
        ($ua or $btc or $title) and
        3 of ($ehlo, $mailfrom, $rcptto, $data, $quit)
}

IOC List

Indicator Type Value
SHA-256 hash b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95
SHA-1 hash 4a077a0ed10d4bf84244f50e243608c8a41734bd (.text)
MD5 hash 787720059300256f7d5e3159ccbe51d7 (.text)
Mutex mutex t12
BTC wallet cryptocurrency 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K
Fake UA network Mozilla/5.0 ... Chrome/202.0.4664.110 ...
MX target network yahoo.com
External IP check network http://icanhazip.com/
Window title string YOU PERVERT! I RECORDED YOU!
Decrypt key string Tmlr

Behavioral Fingerprint

A PE32 GUI executable compiled with MSVC 9.0 and linked to MSVCR90.dll, approximately 18–19 KB. On launch it sleeps 2 seconds, creates a single-instance ASCII mutex (pattern t[0-9]+ or numeric), deletes its own :Zone.Identifier ADS, queries yahoo.com MX records via DnsQuery_A, resolves its external IP via http://icanhazip.com/ using a hardcoded Chrome/202 UA, decrypts embedded strings with a 4-byte XOR+NOT key (observed: Tmlr), then spawns up to 5,000 threads delivering inline-text sextortion emails via raw TCP SMTP. The email demands $800–$1200 USD in Bitcoin to a hardcoded wallet and includes purchase links for major exchanges. No ZIP attachment in the $800 variant cluster.

Detection Signatures

Technique ID Evidence
User Execution: Malicious File T1204.002 Spam-distributed PE
Application Layer Protocol: SMTP T1071.003 Raw TCP SMTP client
OS Credential Dumping T1003 Claims access to files/accounts (social engineering)
Data from Local System T1005 Reads %TEMP%\<n>.txt for victim count
Ingress Tool Transfer T1105 WinInet downloader (fcn.00401900)
Network Service Scanning T1046 MX query for yahoo.com
Scheduled Task/Job T1053 Inferred from historical Phorpiex reporting
Defense Evasion: Delete Indicator T1070.004 Deletes :Zone.Identifier ADS

References

  • phorpiex — campaign umbrella entity
  • smtp-exfiltration — raw TCP SMTP delivery pattern
  • OpenCTI artifact: 622012dc-4a21-4e51-9962-92fa0f4a3eca
  • MalwareBazaar: b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95

Provenance

Analysis based on static artifacts: file.txt, strings.txt, pefile.txt, rabin2-info.txt, metadata.json, triage.json, yara.txt, capa.txt (failed — missing signatures), floss.txt (failed — bad CLI flags). Decompilation via radare2 (r2mcp) at analysis level 3, 78 functions recovered. No dynamic execution — CAPE skipped (no Windows guest available). All claims cite ^[source] markers.