bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49phorpiex: bb0a8440 — sextortion spam bot $800 variant, mutex 523535, Chrome/202 UA
Executive Summary. A 18.9 KB MSVC 9.0 PE32 self-contained sextortion spam bot from the active Phorpiex May 2026 campaign. It decrypts embedded strings with a repeating 4-byte XOR+NOT key (Tmlr), gates on a hardcoded mutex (523535), deletes its own Zone.Identifier ADS, checks external IP via icanhazip.com using a Chrome/202.0.4664.110 UA, then spawns 5,000 threads that query yahoo.com MX records and blast SMTP sextortion emails demanding $800 BTC to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49 |
| Size | 18,944 bytes ^[file.txt] |
| Type | PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt] |
| Linker | MSVC 9.0 (MSVCR90.dll), MajorLinkerVersion=0x9 ^[pefile.txt:46] |
| Compiled | Fri May 29 12:02:34 2026 UTC ^[pefile.txt:34] |
| Signed | No ^[rabin2-info.txt:27] |
| Packing | None — .text entropy 5.99, no UPX/ Themida / custom stub ^[pefile.txt:92] |
| Family | Phorpiex (22nd confirmed campaign sample) — see phorpiex for shared cluster behavior |
OpenCTI tags: dropped-by-phorpiex, exe, malware-bazaar ^[triage.json].
How It Works
- Entry gating.
mainsleeps 2,000 ms, then creates mutex523535viaCreateMutexA. IfGetLastError()returns0xB7(ERROR_ALREADY_EXISTS, 183), the process exits immediately ^[r2:main@0x00402740]. - ADS cleanup. Resolves its own module path, formats
%s:Zone.Identifier, and deletes the ADS viaDeleteFileW^[r2:main@0x0040277e]. - DNS reachability. Queries
yahoo.comMX viaDnsQuery_A(DNS type0xF). On failure, exits ^[r2:fcn.00401790]. - String decryption. Calls
fcn.00401030with a pointer to an encrypted blob. The decoder uses a 4-byte hardcoded keyTmlr(0x4041c0) and loops:buf[i] = ~(buf[i] ^ key[i % 4])^[r2:fcn.00401030]. - External IP & staging. Decrypts the
%TEMP%\n.txtpath, spawns the spam thread (fcn.004024e0), which first fetcheshttp://icanhazip.com/via WinInet with UAMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36, writes the response to the temp file, andatois the first octet as a primitive gate (>0 required) ^[r2:fcn.00401800], ^[strings.txt:17]. - Thread storm. Outer loop 0–99 (100), inner loop 0–49 (50) → 5,000 threads total. Each inner thread calls
fcn.00402340, which reads%TEMP%\n.txtline-by-line, randomly selects one target, and hands it tofcn.00401a10for SMTP delivery ^[r2:fcn.004024e0]. - SMTP conversation. State-machine driven over raw sockets (
WS2_32):socket→connectport 25 →EHLO/HELO→MAIL FROM→RCPT TO→DATA→ body →QUIT^[r2:fcn.00401a10]. - Email body. Hardcoded English sextortion template demanding $800 USD in Bitcoin to wallet
1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, with purchase-advice links to Coinbase, Binance, Bitrefill, Crypto.com, KuCoin, eToro, and Kraken ^[strings.txt:37–59]. - Anti-emulation jitter. Each thread sleeps
rand() % 50 + 50ms between spawns, seeded withGetTickCount^[r2:fcn.004024e0].
Decompiled Behavior
Entry point (main, 0x00402740)
Straightforward C-style main(). No initterm hijack (unlike some earlier Phorpiex reflective-loader siblings). Calls Sleep(2000), CreateMutexA("523535"), GetLastError(), DeleteFileW on Zone.Identifier, WSAStartup(0x202), then the DNS gate at fcn.00401790. If the gate passes, decrypts a path string and launches the spam thread via CreateThread(fcn.004024e0, decrypted_path) ^[r2:main].
String decoder (fcn.00401030, 0x00401030)
Takes a pointer to an encrypted buffer. Copies the 4-byte key Tmlr into a local stack variable. Iterates with strlen bounds, XORs each byte with key[i % 4], then applies bitwise NOT (~), writing back in-place. The operation is self-inverse ^[r2:fcn.00401030].
DNS MX prober (fcn.00401790, 0x00401790)
Calls DnsQuery_A("yahoo.com", DNS_TYPE_MX=0xF). On success (eax!=0), frees the result with DnsFree and returns 1; on failure returns 0. This is a coarse network-reachability gate before any SMTP work ^[r2:fcn.00401790].
External-IP fetcher (fcn.00401800, 0x00401800)
Opens a WinInet session with the fake Chrome/202 UA, fetches http://icanhazip.com/, reads up to 99 bytes, searches for . to confirm it looks like an IP, wraps it in brackets [<ip>], and stores the result at 0x406068 (global). On failure falls back to [0.0.0.0] ^[r2:fcn.00401800].
Spam orchestrator (fcn.004024e0, 0x004024e0)
Thread routine. Seeds PRNG with GetTickCount. Copies the thread-parameter path (decrypted %TEMP%\n.txt) into a local buffer. Expands %TEMP%, formats %sn.txt, calls fcn.00401900 (WinInet fetch of icanhazip.com) and writes result to the temp file, then atois the IP octet. If <=0, exits thread. Otherwise loops 0–99 outer / 0–49 inner, each inner iteration spawning fcn.00402340 as a new thread with a rand()%50+50 ms sleep. After 100×50 threads, sleeps 6,000 ms, deletes the temp file, and exits ^[r2:fcn.004024e0].
Target parser & mailer (fcn.00402340, 0x00402340)
Opens the temp file in "r" mode. Reads line-by-line with fgets. Skips lines probabilistically using x87 fcompp / fnstsw to compare rand()/RAND_MAX against a threshold — a primitive random line selector. Once a target is chosen, tokenizes on : and @, then calls fcn.00401a10 to send the email. If the file is empty or malformed, exits thread ^[r2:fcn.00402340].
SMTP client (fcn.00401a10, 0x00401a10)
Implements a full RFC-like SMTP client state machine (7 states) over raw WS2_32 sockets:
- State 0: Read banner, send
EHLO %sorHELO %s(fall-back ifESMTPnot in banner). - State 1: Parse response, send
MAIL FROM: <%s>. - State 2: Send
RCPT TO: <%s>. - State 3: Send
DATA\r\n. - State 4: Build
Received:headers (MailEnable and qmail variants), generate random Message-ID, randomReceivedIP octets, formatFrom:,To:,Subject:,Date:,Mime-Version:,Content-type: text/plain, then concatenate the full sextortion body paragraph by paragraph. - State 5: Send
QUIT. - State 6: Exit loop.
Subject line is passed as arg_8h (decrypted from the caller). The window-title string YOU PERVERT! I RECORDED YOU! is used as the email Subject in the DATA phase ^[r2:fcn.00401a10], ^[strings.txt:146].
C2 Infrastructure
| Indicator | Value | Note |
|---|---|---|
| External IP service | http://icanhazip.com/ |
Fetched over plain HTTP ^[strings.txt:18] |
| Fake UA | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 |
Hardcoded in .rdata ^[strings.txt:17] |
| MX domain | yahoo.com |
Queried via DnsQuery_A for SMTP relay discovery ^[strings.txt:16] |
| SMTP port | 25 (TCP) | Raw socket connect ^[r2:fcn.004010d0] |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
Hardcoded; same across $800 sub-cluster ^[strings.txt:59] |
| Mutex | 523535 |
New mutex in campaign; not seen in prior siblings ^[strings.txt:147] |
| Target list | %TEMP%\n.txt |
Decrypted path; file is created/overwritten with external IP and then read for target addresses ^[r2:fcn.004024e0] |
No traditional download C2, no callback URL, no DGA. The bot is fully self-contained after the initial external-IP check.
Interesting Tidbits
- No packing, no obfuscation beyond trivial XOR+NOT. The binary is effectively plaintext after the 4-byte decoder runs. Capabilities are entirely recoverable from static analysis ^[file.txt], ^[r2:fcn.00401030].
- Chrome/202 UA is a new campaign variant. Prior thin-downloader siblings used
Chrome/128.0.0.0orChrome/7775543322.0.0.0; this is the first observed use ofChrome/202.0.4664.110^[strings.txt:17]. - Mutex
523535breaks thet1–t13naming pattern. Prior $800 sextortion siblings rotated mutex namest1,t2,t4,t5,t7,t13,etyueu. This sample uses a numeric mutex, suggesting the builder parameter space is larger than previously mapped ^[strings.txt:147]. - Window title string present.
YOU PERVERT! I RECORDED YOU!appears in the subject line of the SMTPDATAphase, matching thet1andt13siblings ^[strings.txt:146]. - x87 FPU used as a PRNG comparator. The target-selection loop in
fcn.00402340usesfcompp+fnstswto decide whether to skip a line — an unusual anti-emulation tick that defeats naive x86 emulators lacking x87 support ^[r2:fcn.00402340]. - MailEnable masquerade. The
Received:header claimsMailEnable ESMTPand a qmail invocation line, both classic Phorpiex email-forgery tells ^[strings.txt:27–28]. IsDebuggerPresentimported but unused in the decompiled entry path. The import is present in the IAT (YARA hitSuspicious_Wininet_Imports) butmaindoes not call it ^[pefile.txt:377], ^[r2:main].
How To Mess With It (Homelab Replication)
Goal: Build a functionally equivalent SMTP sextortion spam bot in C that reproduces the static fingerprint (MSVCR90 imports, WinInet + WS2_32 surface, XOR+NOT string encryption, raw-socket SMTP state machine).
Toolchain: Visual Studio 2008 (MSVC 9.0) or VS 2008 Express with Platform SDK. Target: Win32 GUI, /MT (static CRT links against MSVCR90.dll).
Flags: /O2 /GS- (optimizations on, buffer security check off — matches the stripped, minimal binary).
Working source outline:
#include <winsock2.h>
#include <wininet.h>
#include <windows.h>
#include <stdio.h>
#pragma comment(lib, "ws2_32.lib")
#pragma comment(lib, "wininet.lib")
void decrypt(char* buf, size_t len) {
const char key[] = "Tmlr";
for (size_t i = 0; i < len; i++)
buf[i] = ~(buf[i] ^ key[i % 4]);
}
int main() {
Sleep(2000);
HANDLE h = CreateMutexA(NULL, FALSE, "523535");
if (GetLastError() == ERROR_ALREADY_EXISTS) return 0;
// ... WSAStartup, DnsQuery_A, InternetOpenA with Chrome/202 UA,
// ... thread loops, raw socket SMTP, etc.
return 0;
}
Verification: Compile, run strings.exe and confirm Tmlr, 523535, Chrome/202.0.4664.110, 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, MailEnable ESMTP, and yahoo.com are present. Run YARA rule below against the binary — should hit.
Deployable Signatures
YARA Rule — Phorpiex Sextortion $800 Sub-Cluster
rule phorpiex_sextortion_800usd {
meta:
description = "Phorpiex May 2026 sextortion spam bot ($800 variant)"
author = "Demetrian Titus"
date = "2026-09-03"
hash = "bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49"
reference = "https://malwarebazaar.abuse.ch/sample/bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49/"
strings:
$key = "Tmlr" ascii wide
$btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii wide
$ua = "Chrome/202.0.4664.110" ascii wide
$mx = "yahoo.com" ascii wide
$ip_check = "http://icanhazip.com/" ascii wide
$mailenable = "MailEnable ESMTP" ascii wide
$subject = "YOU PERVERT! I RECORDED YOU!" ascii wide
$rcpt = "RCPT TO: <%s>" ascii wide
$data = "DATA\r\n" ascii wide
$quit = "QUIT" ascii wide
condition:
uint16(0) == 0x5A4D and
pe.imports("MSVCR90.dll") and
pe.imports("WININET.dll") and
pe.imports("WS2_32.dll") and
($key or $btc) and
3 of ($ua, $mx, $ip_check, $mailenable, $subject, $rcpt, $data, $quit)
}
Sigma Rule — SMTP Thread-Storm + Sextortion Content
title: Phorpiex Sextortion Spam Bot Execution
status: experimental
description: Detects a process spawning a large number of threads and making outbound SMTP (port 25) connections shortly after launch, accompanied by DNS MX queries and known sextortion keywords in memory.
logsource:
category: process_creation
product: windows
detection:
selection_process:
CommandLine|contains:
- '.exe'
selection_network:
Initiated: 'true'
DestinationPort: 25
selection_dns:
QueryName: 'yahoo.com'
QueryType: 'MX'
selection_memory:
- 'YOU PERVERT! I RECORDED YOU!'
- '1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K'
- 'MailEnable ESMTP'
condition: selection_process and selection_network and selection_dns and selection_memory
falsepositives:
- Legitimate bulk-email applications (unlikely to hardcode the above strings)
level: high
Note: The Sigma rule uses a composite detection model (process + network + DNS + memory). In practice, split this into separate detections for your SIEM: one for high-volume thread creation to port 25, one for DNS MX queries to yahoo.com by non-mail-client processes, and one for memory-string hunting.
IOC List
| Type | Indicator | Context |
|---|---|---|
| Hash (SHA-256) | bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49 |
Sample |
| Hash (SHA-1) | f54a9d8bc19234cc94a3f6a21d72a7ab990c316f |
.text section ^[pefile.txt:95] |
| Hash (MD5) | 81ac7e070738eb402aebbc06fa75778d |
.text section ^[pefile.txt:93] |
| Mutex | 523535 |
Single-instance gating ^[strings.txt:147] |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
Hardcoded ransom address ^[strings.txt:59] |
| URL | http://icanhazip.com/ |
External IP check ^[strings.txt:18] |
| User-Agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 |
WinInet masquerade ^[strings.txt:17] |
| File path | %TEMP%\n.txt |
Target list staging / IP writeback ^[r2:fcn.004024e0] |
| DNS MX | yahoo.com |
SMTP relay discovery ^[strings.txt:16] |
| SMTP banner probe | EHLO, HELO, MAIL FROM, RCPT TO, DATA, QUIT |
Hardcoded commands ^[strings.txt:22–25], ^[strings.txt:35] |
| Registry / ADS | :Zone.Identifier |
Deleted on self ^[r2:main] |
| YARA hit | Suspicious_Wininet_Imports |
Generic WinInet import match ^[yara.txt] |
Behavioral Fingerprint
On launch, this binary sleeps 2 seconds, creates a global mutex named 523535, and deletes its own Zone.Identifier ADS. It then queries DNS for MX records of yahoo.com; if that fails, it exits. Next it decrypts embedded strings using a 4-byte XOR+NOT cipher with key Tmlr, fetches its external IP via WinInet from icanhazip.com using a Chrome/202.0.4664.110 User-Agent, writes the IP to %TEMP%\n.txt, and validates the first octet is non-zero. It then enters a double loop (100 × 50) spawning 5,000 threads, each of which reads a random line from the temp file, opens a raw TCP socket to port 25, and walks through an SMTP state machine to deliver a sextortion email demanding $800 USD in Bitcoin to 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Each thread spawn is jittered by rand() % 50 + 50 ms. No C2 download, no persistence beyond the initial run.
Detection Signatures
| MITRE ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1204.002 | User Execution: Malicious File | Spam-distributed PE with social-engineered filename ^[triage.json] |
| T1059.003 | Windows Command Shell | Not observed; pure C binary |
| T1071.001 | Application Layer Protocol: Web Protocols | WinInet fetch to icanhazip.com with fake Chrome UA ^[r2:fcn.00401800] |
| T1071.003 | Application Layer Protocol: Mail Protocols | Raw SMTP over TCP/25 to MX-resolved relay ^[r2:fcn.00401a10] |
| T1567.001 | Exfiltration Over Web Service | External IP disclosure to icanhazip.com (recon, not exfil) ^[r2:fcn.00401800] |
| T1496 | Resource Hijacking | 5,000-thread SMTP blast consumes CPU and network bandwidth ^[r2:fcn.004024e0] |
| T1562.001 | Impair Defenses: Disable or Modify Tools | Deletes Zone.Identifier ADS to suppress security warnings ^[r2:main] |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | DNS MX gate + external IP gate; GetTickCount-seeded rand jitter ^[r2:fcn.00401790], ^[r2:fcn.004024e0] |
References
- phorpiex — Campaign entity page with full cluster history and earlier siblings
- xor-not-string-decryption — Technique page documenting the
Tmlrdecoder - MalwareBazaar: https://malwarebazaar.abuse.ch/sample/bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49/
- OpenCTI artifact ID:
4c6353f2-8c80-4e26-9004-35e32ea966dd^[metadata.json]
Provenance
- Static artifacts read from
wiki/wiki/raw/analyses/bb0a8440.../:file.txt,pefile.txt,strings.txt,metadata.json,triage.json,yara.txt,rabin2-info.txt,binwalk.txt,floss.txt(errored),capa.txt(errored),dynamic-analysis.md(CAPE skipped). - Radare2 analysis:
radare2 5.9.8opened at0x400000, analyzed at level 3 (aaa), 78 functions recovered. Decompilation viapdc. - No Ghidra analysis performed (pyghidra MCP not available in environment).
- No CAPE dynamic detonation (no Windows guest available).