typeanalysisfamilyphorpiexconfidencehighcreated2026-09-03updated2026-09-03malware-familypemsvcc2-protocolexfiltrationimpactmitre-attck
SHA-256: bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49

phorpiex: bb0a8440 — sextortion spam bot $800 variant, mutex 523535, Chrome/202 UA

Executive Summary. A 18.9 KB MSVC 9.0 PE32 self-contained sextortion spam bot from the active Phorpiex May 2026 campaign. It decrypts embedded strings with a repeating 4-byte XOR+NOT key (Tmlr), gates on a hardcoded mutex (523535), deletes its own Zone.Identifier ADS, checks external IP via icanhazip.com using a Chrome/202.0.4664.110 UA, then spawns 5,000 threads that query yahoo.com MX records and blast SMTP sextortion emails demanding $800 BTC to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49
Size 18,944 bytes ^[file.txt]
Type PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
Linker MSVC 9.0 (MSVCR90.dll), MajorLinkerVersion=0x9 ^[pefile.txt:46]
Compiled Fri May 29 12:02:34 2026 UTC ^[pefile.txt:34]
Signed No ^[rabin2-info.txt:27]
Packing None — .text entropy 5.99, no UPX/ Themida / custom stub ^[pefile.txt:92]
Family Phorpiex (22nd confirmed campaign sample) — see phorpiex for shared cluster behavior

OpenCTI tags: dropped-by-phorpiex, exe, malware-bazaar ^[triage.json].

How It Works

  1. Entry gating. main sleeps 2,000 ms, then creates mutex 523535 via CreateMutexA. If GetLastError() returns 0xB7 (ERROR_ALREADY_EXISTS, 183), the process exits immediately ^[r2:main@0x00402740].
  2. ADS cleanup. Resolves its own module path, formats %s:Zone.Identifier, and deletes the ADS via DeleteFileW ^[r2:main@0x0040277e].
  3. DNS reachability. Queries yahoo.com MX via DnsQuery_A (DNS type 0xF). On failure, exits ^[r2:fcn.00401790].
  4. String decryption. Calls fcn.00401030 with a pointer to an encrypted blob. The decoder uses a 4-byte hardcoded key Tmlr (0x4041c0) and loops: buf[i] = ~(buf[i] ^ key[i % 4]) ^[r2:fcn.00401030].
  5. External IP & staging. Decrypts the %TEMP%\n.txt path, spawns the spam thread (fcn.004024e0), which first fetches http://icanhazip.com/ via WinInet with UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36, writes the response to the temp file, and atois the first octet as a primitive gate (>0 required) ^[r2:fcn.00401800], ^[strings.txt:17].
  6. Thread storm. Outer loop 0–99 (100), inner loop 0–49 (50) → 5,000 threads total. Each inner thread calls fcn.00402340, which reads %TEMP%\n.txt line-by-line, randomly selects one target, and hands it to fcn.00401a10 for SMTP delivery ^[r2:fcn.004024e0].
  7. SMTP conversation. State-machine driven over raw sockets (WS2_32): socket → connect port 25 → EHLO / HELO → MAIL FROM → RCPT TO → DATA → body → QUIT ^[r2:fcn.00401a10].
  8. Email body. Hardcoded English sextortion template demanding $800 USD in Bitcoin to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, with purchase-advice links to Coinbase, Binance, Bitrefill, Crypto.com, KuCoin, eToro, and Kraken ^[strings.txt:37–59].
  9. Anti-emulation jitter. Each thread sleeps rand() % 50 + 50 ms between spawns, seeded with GetTickCount ^[r2:fcn.004024e0].

Decompiled Behavior

Entry point (main, 0x00402740) Straightforward C-style main(). No initterm hijack (unlike some earlier Phorpiex reflective-loader siblings). Calls Sleep(2000), CreateMutexA("523535"), GetLastError(), DeleteFileW on Zone.Identifier, WSAStartup(0x202), then the DNS gate at fcn.00401790. If the gate passes, decrypts a path string and launches the spam thread via CreateThread(fcn.004024e0, decrypted_path) ^[r2:main].

String decoder (fcn.00401030, 0x00401030) Takes a pointer to an encrypted buffer. Copies the 4-byte key Tmlr into a local stack variable. Iterates with strlen bounds, XORs each byte with key[i % 4], then applies bitwise NOT (~), writing back in-place. The operation is self-inverse ^[r2:fcn.00401030].

DNS MX prober (fcn.00401790, 0x00401790) Calls DnsQuery_A("yahoo.com", DNS_TYPE_MX=0xF). On success (eax!=0), frees the result with DnsFree and returns 1; on failure returns 0. This is a coarse network-reachability gate before any SMTP work ^[r2:fcn.00401790].

External-IP fetcher (fcn.00401800, 0x00401800) Opens a WinInet session with the fake Chrome/202 UA, fetches http://icanhazip.com/, reads up to 99 bytes, searches for . to confirm it looks like an IP, wraps it in brackets [<ip>], and stores the result at 0x406068 (global). On failure falls back to [0.0.0.0] ^[r2:fcn.00401800].

Spam orchestrator (fcn.004024e0, 0x004024e0) Thread routine. Seeds PRNG with GetTickCount. Copies the thread-parameter path (decrypted %TEMP%\n.txt) into a local buffer. Expands %TEMP%, formats %sn.txt, calls fcn.00401900 (WinInet fetch of icanhazip.com) and writes result to the temp file, then atois the IP octet. If <=0, exits thread. Otherwise loops 0–99 outer / 0–49 inner, each inner iteration spawning fcn.00402340 as a new thread with a rand()%50+50 ms sleep. After 100×50 threads, sleeps 6,000 ms, deletes the temp file, and exits ^[r2:fcn.004024e0].

Target parser & mailer (fcn.00402340, 0x00402340) Opens the temp file in "r" mode. Reads line-by-line with fgets. Skips lines probabilistically using x87 fcompp / fnstsw to compare rand()/RAND_MAX against a threshold — a primitive random line selector. Once a target is chosen, tokenizes on : and @, then calls fcn.00401a10 to send the email. If the file is empty or malformed, exits thread ^[r2:fcn.00402340].

SMTP client (fcn.00401a10, 0x00401a10) Implements a full RFC-like SMTP client state machine (7 states) over raw WS2_32 sockets:

  • State 0: Read banner, send EHLO %s or HELO %s (fall-back if ESMTP not in banner).
  • State 1: Parse response, send MAIL FROM: <%s>.
  • State 2: Send RCPT TO: <%s>.
  • State 3: Send DATA\r\n.
  • State 4: Build Received: headers (MailEnable and qmail variants), generate random Message-ID, random Received IP octets, format From:, To:, Subject:, Date:, Mime-Version:, Content-type: text/plain, then concatenate the full sextortion body paragraph by paragraph.
  • State 5: Send QUIT.
  • State 6: Exit loop.

Subject line is passed as arg_8h (decrypted from the caller). The window-title string YOU PERVERT! I RECORDED YOU! is used as the email Subject in the DATA phase ^[r2:fcn.00401a10], ^[strings.txt:146].

C2 Infrastructure

Indicator Value Note
External IP service http://icanhazip.com/ Fetched over plain HTTP ^[strings.txt:18]
Fake UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 Hardcoded in .rdata ^[strings.txt:17]
MX domain yahoo.com Queried via DnsQuery_A for SMTP relay discovery ^[strings.txt:16]
SMTP port 25 (TCP) Raw socket connect ^[r2:fcn.004010d0]
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K Hardcoded; same across $800 sub-cluster ^[strings.txt:59]
Mutex 523535 New mutex in campaign; not seen in prior siblings ^[strings.txt:147]
Target list %TEMP%\n.txt Decrypted path; file is created/overwritten with external IP and then read for target addresses ^[r2:fcn.004024e0]

No traditional download C2, no callback URL, no DGA. The bot is fully self-contained after the initial external-IP check.

Interesting Tidbits

  • No packing, no obfuscation beyond trivial XOR+NOT. The binary is effectively plaintext after the 4-byte decoder runs. Capabilities are entirely recoverable from static analysis ^[file.txt], ^[r2:fcn.00401030].
  • Chrome/202 UA is a new campaign variant. Prior thin-downloader siblings used Chrome/128.0.0.0 or Chrome/7775543322.0.0.0; this is the first observed use of Chrome/202.0.4664.110 ^[strings.txt:17].
  • Mutex 523535 breaks the t1–t13 naming pattern. Prior $800 sextortion siblings rotated mutex names t1, t2, t4, t5, t7, t13, etyueu. This sample uses a numeric mutex, suggesting the builder parameter space is larger than previously mapped ^[strings.txt:147].
  • Window title string present. YOU PERVERT! I RECORDED YOU! appears in the subject line of the SMTP DATA phase, matching the t1 and t13 siblings ^[strings.txt:146].
  • x87 FPU used as a PRNG comparator. The target-selection loop in fcn.00402340 uses fcompp + fnstsw to decide whether to skip a line — an unusual anti-emulation tick that defeats naive x86 emulators lacking x87 support ^[r2:fcn.00402340].
  • MailEnable masquerade. The Received: header claims MailEnable ESMTP and a qmail invocation line, both classic Phorpiex email-forgery tells ^[strings.txt:27–28].
  • IsDebuggerPresent imported but unused in the decompiled entry path. The import is present in the IAT (YARA hit Suspicious_Wininet_Imports) but main does not call it ^[pefile.txt:377], ^[r2:main].

How To Mess With It (Homelab Replication)

Goal: Build a functionally equivalent SMTP sextortion spam bot in C that reproduces the static fingerprint (MSVCR90 imports, WinInet + WS2_32 surface, XOR+NOT string encryption, raw-socket SMTP state machine).

Toolchain: Visual Studio 2008 (MSVC 9.0) or VS 2008 Express with Platform SDK. Target: Win32 GUI, /MT (static CRT links against MSVCR90.dll).

Flags: /O2 /GS- (optimizations on, buffer security check off — matches the stripped, minimal binary).

Working source outline:

#include <winsock2.h>
#include <wininet.h>
#include <windows.h>
#include <stdio.h>
#pragma comment(lib, "ws2_32.lib")
#pragma comment(lib, "wininet.lib")

void decrypt(char* buf, size_t len) {
    const char key[] = "Tmlr";
    for (size_t i = 0; i < len; i++)
        buf[i] = ~(buf[i] ^ key[i % 4]);
}

int main() {
    Sleep(2000);
    HANDLE h = CreateMutexA(NULL, FALSE, "523535");
    if (GetLastError() == ERROR_ALREADY_EXISTS) return 0;
    // ... WSAStartup, DnsQuery_A, InternetOpenA with Chrome/202 UA,
    // ... thread loops, raw socket SMTP, etc.
    return 0;
}

Verification: Compile, run strings.exe and confirm Tmlr, 523535, Chrome/202.0.4664.110, 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, MailEnable ESMTP, and yahoo.com are present. Run YARA rule below against the binary — should hit.

Deployable Signatures

YARA Rule — Phorpiex Sextortion $800 Sub-Cluster

rule phorpiex_sextortion_800usd {
    meta:
        description = "Phorpiex May 2026 sextortion spam bot ($800 variant)"
        author      = "Demetrian Titus"
        date        = "2026-09-03"
        hash        = "bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49"
        reference   = "https://malwarebazaar.abuse.ch/sample/bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49/"
    strings:
        $key        = "Tmlr" ascii wide
        $btc        = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii wide
        $ua         = "Chrome/202.0.4664.110" ascii wide
        $mx         = "yahoo.com" ascii wide
        $ip_check   = "http://icanhazip.com/" ascii wide
        $mailenable = "MailEnable ESMTP" ascii wide
        $subject    = "YOU PERVERT! I RECORDED YOU!" ascii wide
        $rcpt       = "RCPT TO: <%s>" ascii wide
        $data       = "DATA\r\n" ascii wide
        $quit       = "QUIT" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        pe.imports("MSVCR90.dll") and
        pe.imports("WININET.dll") and
        pe.imports("WS2_32.dll") and
        ($key or $btc) and
        3 of ($ua, $mx, $ip_check, $mailenable, $subject, $rcpt, $data, $quit)
}

Sigma Rule — SMTP Thread-Storm + Sextortion Content

title: Phorpiex Sextortion Spam Bot Execution
status: experimental
description: Detects a process spawning a large number of threads and making outbound SMTP (port 25) connections shortly after launch, accompanied by DNS MX queries and known sextortion keywords in memory.
logsource:
    category: process_creation
    product: windows
detection:
    selection_process:
        CommandLine|contains:
            - '.exe'
    selection_network:
        Initiated: 'true'
        DestinationPort: 25
    selection_dns:
        QueryName: 'yahoo.com'
        QueryType: 'MX'
    selection_memory:
        - 'YOU PERVERT! I RECORDED YOU!'
        - '1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K'
        - 'MailEnable ESMTP'
    condition: selection_process and selection_network and selection_dns and selection_memory
falsepositives:
    - Legitimate bulk-email applications (unlikely to hardcode the above strings)
level: high

Note: The Sigma rule uses a composite detection model (process + network + DNS + memory). In practice, split this into separate detections for your SIEM: one for high-volume thread creation to port 25, one for DNS MX queries to yahoo.com by non-mail-client processes, and one for memory-string hunting.

IOC List

Type Indicator Context
Hash (SHA-256) bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49 Sample
Hash (SHA-1) f54a9d8bc19234cc94a3f6a21d72a7ab990c316f .text section ^[pefile.txt:95]
Hash (MD5) 81ac7e070738eb402aebbc06fa75778d .text section ^[pefile.txt:93]
Mutex 523535 Single-instance gating ^[strings.txt:147]
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K Hardcoded ransom address ^[strings.txt:59]
URL http://icanhazip.com/ External IP check ^[strings.txt:18]
User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 WinInet masquerade ^[strings.txt:17]
File path %TEMP%\n.txt Target list staging / IP writeback ^[r2:fcn.004024e0]
DNS MX yahoo.com SMTP relay discovery ^[strings.txt:16]
SMTP banner probe EHLO, HELO, MAIL FROM, RCPT TO, DATA, QUIT Hardcoded commands ^[strings.txt:22–25], ^[strings.txt:35]
Registry / ADS :Zone.Identifier Deleted on self ^[r2:main]
YARA hit Suspicious_Wininet_Imports Generic WinInet import match ^[yara.txt]

Behavioral Fingerprint

On launch, this binary sleeps 2 seconds, creates a global mutex named 523535, and deletes its own Zone.Identifier ADS. It then queries DNS for MX records of yahoo.com; if that fails, it exits. Next it decrypts embedded strings using a 4-byte XOR+NOT cipher with key Tmlr, fetches its external IP via WinInet from icanhazip.com using a Chrome/202.0.4664.110 User-Agent, writes the IP to %TEMP%\n.txt, and validates the first octet is non-zero. It then enters a double loop (100 × 50) spawning 5,000 threads, each of which reads a random line from the temp file, opens a raw TCP socket to port 25, and walks through an SMTP state machine to deliver a sextortion email demanding $800 USD in Bitcoin to 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Each thread spawn is jittered by rand() % 50 + 50 ms. No C2 download, no persistence beyond the initial run.

Detection Signatures

MITRE ATT&CK ID Technique Evidence
T1204.002 User Execution: Malicious File Spam-distributed PE with social-engineered filename ^[triage.json]
T1059.003 Windows Command Shell Not observed; pure C binary
T1071.001 Application Layer Protocol: Web Protocols WinInet fetch to icanhazip.com with fake Chrome UA ^[r2:fcn.00401800]
T1071.003 Application Layer Protocol: Mail Protocols Raw SMTP over TCP/25 to MX-resolved relay ^[r2:fcn.00401a10]
T1567.001 Exfiltration Over Web Service External IP disclosure to icanhazip.com (recon, not exfil) ^[r2:fcn.00401800]
T1496 Resource Hijacking 5,000-thread SMTP blast consumes CPU and network bandwidth ^[r2:fcn.004024e0]
T1562.001 Impair Defenses: Disable or Modify Tools Deletes Zone.Identifier ADS to suppress security warnings ^[r2:main]
T1497.001 Virtualization/Sandbox Evasion: System Checks DNS MX gate + external IP gate; GetTickCount-seeded rand jitter ^[r2:fcn.00401790], ^[r2:fcn.004024e0]

References

  • phorpiex — Campaign entity page with full cluster history and earlier siblings
  • xor-not-string-decryption — Technique page documenting the Tmlr decoder
  • MalwareBazaar: https://malwarebazaar.abuse.ch/sample/bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49/
  • OpenCTI artifact ID: 4c6353f2-8c80-4e26-9004-35e32ea966dd ^[metadata.json]

Provenance

  • Static artifacts read from wiki/wiki/raw/analyses/bb0a8440.../: file.txt, pefile.txt, strings.txt, metadata.json, triage.json, yara.txt, rabin2-info.txt, binwalk.txt, floss.txt (errored), capa.txt (errored), dynamic-analysis.md (CAPE skipped).
  • Radare2 analysis: radare2 5.9.8 opened at 0x400000, analyzed at level 3 (aaa), 78 functions recovered. Decompilation via pdc.
  • No Ghidra analysis performed (pyghidra MCP not available in environment).
  • No CAPE dynamic detonation (no Windows guest available).