typeanalysisfamilyphorpiexconfidencehighmalware-familyloadermalware-bazaarattributionsextortionsmtp-exfiltrationc2defense-evasion
SHA-256: cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000

phorpiex: cbc59001 — sextortion spam bot, mutex t11, 12:40:35 UTC campaign burst

Executive Summary

24th confirmed Phorpiex campaign sample. Self-contained sextortion spam bot compiled with MSVC 9.0, linked to MSVCR90.dll, 18.9 KB. Hardcoded XOR+NOT decrypt key Tmlr, mutex t11, window title YOU PERVERT! I RECORDED YOU!, and BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Part of the May 29 2026 ~30-minute campaign burst (t1–t13 + numeric mutex variants). Compiled between t7 (12:36:22) and t12 (12:41:46). Static-only; CAPE skipped.

What It Is

Attribute Value
SHA-256 cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000
Size 18,944 bytes
File type PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
Compiler MSVC 9.0 (linker 9.0) ^[pefile.txt]
Timestamp 2026-05-29 12:40:35 UTC ^[pefile.txt]
CRT MSVCR90.dll (static manifest, version 9.0.21022.8) ^[strings.txt:147]
Signed No ^[rabin2-info.txt]
ASLR / DEP Yes (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt]

OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar. ^[metadata.json]

How It Works

Entry point → main(): standard MSVC CRT entry0 → main() flow. main() sleeps 2,000 ms, creates mutex t11, then branches on GetLastError() == ERROR_ALREADY_EXISTS (0xB7). If mutex exists, exits; otherwise proceeds. ^[r2:main]

Single-instance gating + anti-forensics: Before spawning threads, deletes its own :Zone.Identifier ADS via DeleteFileW with a wsprintfW-formatted path. ^[r2:main]

External IP resolution: Calls fcn.00401800, which opens a WinInet session with UA Mozilla/5.0 ... Chrome/202.0.4664.110 ... ^[strings.txt:17], fetches http://icanhazip.com/, parses the dotted-quad response, and wraps it as [x.x.x.x]. Falls back to [0.0.0.0] on failure. ^[r2:fcn.00401800]

MX query: Calls fcn.00401790, which queries yahoo.com (type MX, 0x0F) via DnsQuery_A. On success, opens a TCP socket to the resolved MX and passes it to the SMTP engine. ^[r2:fcn.00401790]

String decryption: fcn.00401030 implements a 4-byte XOR+NOT loop using key Tmlr. Each input byte is XORed with the key byte (cycling), then NOTed. ^[r2:fcn.00401030]

SMTP engine: fcn.00401a10 runs a 7-case state machine over raw TCP socket I/O:

  1. Parse banner → detect ESMTP
  2. EHLO %s or HELO %s
  3. MAIL FROM: <%s>
  4. RCPT TO: <%s>
  5. DATA
  6. Assemble full RFC-822 message with spoofed Received: headers, random local-part generation (fcn.004013c0 produces 3–15 lowercase chars), and the hardcoded sextortion body
  7. QUIT

The message body is the standard Phorpiex sextortion template: claims R.A.T. infection, camera recording, demands $800 USD in BTC to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, with purchase links for Coinbase, Binance, Bitrefill, Crypto.com, Kucoin, eToro, Kraken. ^[strings.txt:36-61]

Thread dispatch: fcn.004024e0 (thread proc) loops 100×50 = 5,000 thread spawns. Each thread re-reads the victim count from %TEMP%\<n>.txt, sleeps a random 0–100 ms between spawns, and after 100 outer iterations sleeps 20,000 ms before re-reading the count and exiting if count ≤ 1. ^[r2:fcn.004024e0]

Downloader helper: fcn.00401900 fetches payloads via WinInet (InternetOpenW/InternetOpenUrlW/InternetReadFile) with the same Chrome/202 UA, writes to a CreateFileW handle. Used for potential payload updates. ^[r2:fcn.00401900]

Decompiled Behavior

  • entry0 @ 0x402bb7: Standard MSVC 9.0 CRT startup. No initterm hijack — honest main() flow. ^[r2:entry0]
  • main @ 0x402740: Sleep → mutex → Zone.Identifier deletion → WSAStartup → MX query → decrypt → thread spawn. ^[r2:main]
  • fcn.00401030: XOR+NOT string decryptor with key Tmlr. ^[r2:fcn.00401030]
  • fcn.00401790: DNS MX query for yahoo.com. ^[r2:fcn.00401790]
  • fcn.00401800: HTTP GET to icanhazip.com for external IP. ^[r2:fcn.00401800]
  • fcn.00401900: WinInet downloader (payload fetcher). ^[r2:fcn.00401900]
  • fcn.00401a10: Raw TCP SMTP client with 7-case state machine. ^[r2:fcn.00401a10]
  • fcn.004024e0: Thread proc — 5,000-thread spam dispatch loop. ^[r2:fcn.004024e0]

C2 Infrastructure

IOC Value Source
MX target yahoo.com ^[strings.txt:16]
External IP check http://icanhazip.com/ ^[strings.txt:18]
Fake UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/202.0.4664.110 Safari/537.36 ^[strings.txt:17]
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]
Mutex t11 ^[r2:main]
Decrypt key Tmlr ^[strings.txt:160], ^[r2:fcn.00401030]
Window title YOU PERVERT! I RECORDED YOU! ^[strings.txt:146]
Ransom demand $800 USD ^[strings.txt:46]

No ZIP attachment — email body is inline text (ZIP-less variant, matching t1–t13 sub-cluster).

Interesting Tidbits

  • Campaign burst timing: Compiled at 12:40:35 UTC, between t7 (12:36:22) and t12 (12:41:46). Fits the ~30-minute continuous builder rotation documented across the burst. ^[pefile.txt]
  • No ZIP constructor: Unlike the 150e4652 $1200 variant, this sample omits the ZIP attachment builder. Inline text only, reducing binary size to 18.9 KB.
  • Identical .text hash expected: Prior siblings in the $800 sub-cluster share an identical .text section (same SMTP engine code). Likely true here too — the .text entropy of 5.99 is consistent with the cluster. ^[pefile.txt]
  • Chrome/202 UA: Impossible Chrome version (202.x) used across the entire May 29 burst. The builder hardcodes this; no UA rotation per sample. ^[strings.txt:17]
  • Window title in .data: The YOU PERVERT! string lives at 0x4000 in the .data section, confirming it's part of the decrypted payload rather than the raw binary — consistent with the XOR+NOT obfuscation pattern. ^[strings.txt:146]

How To Mess With It

Toolchain: MSVC 9.0 (Visual Studio 2008), x86, Windows GUI subsystem.

Replication sketch: Compile a minimal Win32 PE with WinInet + WS2_32 + DNSAPI imports. Implement a 7-case SMTP state machine over raw TCP. Use DnsQuery_A for MX resolution. Use InternetOpenA/InternetReadFile for IP check. The XOR+NOT decryptor is trivial: for (i=0; s[i]; i++) s[i] = ~(s[i] ^ key[i % 4]);.

Verification: Build a test binary with the same import set and a hardcoded Tmlr key. Run strings — the key should appear plaintext. Compare section entropy to sibling t5 (.text ~5.99).

Deployable Signatures

YARA rule

rule phorpiex_sextortion_spam_bot_800 {
    meta:
        description = "Phorpiex sextortion spam bot $800 variant (t1-t13 burst)"
        author = "PacketPursuit"
        date = "2026-09-04"
        hash = "cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000"
    strings:
        $key = "Tmlr" ascii wide
        $ua = "Chrome/202.0.4664.110" ascii wide
        $btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii wide
        $title = "YOU PERVERT! I RECORDED YOU!" ascii wide
        $mx = "yahoo.com" ascii wide
        $ipcheck = "http://icanhazip.com/" ascii wide
        $helo = "EHLO %s" ascii
        $mailfrom = "MAIL FROM: %s" ascii
        $rcptto = "RCPT TO: <%s>" ascii
        $received = "Received: from %s ([%d.%d.%d.%d]) by %s with MailEnable ESMTP; %s" ascii
    condition:
        uint16(0) == 0x5A4D and
        $key and $ua and $btc and ($helo or $mailfrom or $rcptto)
}

Behavioral hunt query (Sigma-style)

title: Phorpiex Sextortion Spam Bot Activity
status: experimental
description: Detects Phorpiex sextortion spam bot process behavior
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - 't11'
            - 't12'
            - 't13'
            - 't1'
            - 't2'
            - 't4'
            - 't5'
            - 't7'
    network:
        Initiated: 'true'
        DestinationPort: 25
    condition: selection and network
falsepositives:
    - Unknown
level: high

IOC list

Type Value
SHA-256 cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000
SHA-1 4a077a0ed10d4bf84244f50e243608c8a41734bd
MD5 787720059300256f7d5e3159ccbe51d7
Mutex t11
Decrypt key Tmlr
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K
Fake UA Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/202.0.4664.110 Safari/537.36
MX target yahoo.com
IP check http://icanhazip.com/
Temp file %TEMP%\n.txt (victim list)
Temp file %TEMP%\%d%d%d.jpg (sidecar)
Window title YOU PERVERT! I RECORDED YOU!
Ransom $800 USD

Behavioral fingerprint statement

This binary is a self-contained MSVC 9.0 PE32 GUI executable that sleeps 2 seconds on launch, creates a single-instance mutex (pattern t[0-9]+ or numeric), deletes its own Zone.Identifier ADS, resolves yahoo.com MX records via DNS, fetches its external IP from icanhazip.com using a hardcoded Chrome/202 UA, then spawns 5,000 threads that each open raw TCP/25 sockets to the resolved MX and deliver a sextortion email demanding $800 USD in Bitcoin to a hardcoded wallet. All strings are decrypted at runtime using a 4-byte XOR+NOT loop with key Tmlr.

Detection Signatures

Technique ATT&CK ID Evidence
User Execution: Malicious File T1204.002 Spam-distributed PE ^[metadata.json]
OS Credential Dumping T1003 Claims access to accounts/camera ^[strings.txt:39]
Application Layer Protocol: SMTP T1071.003 Raw TCP/25 SMTP dialog ^[r2:fcn.00401a10]
Exfiltration Over C2 Channel T1041 SMTP email delivery of sextortion demand ^[r2:fcn.00401a10]
Data Encrypted for Impact T1486 Sextortion demand (psychological impact) ^[strings.txt:46]
Obfuscated Files or Information T1027 XOR+NOT string decryption ^[r2:fcn.00401030]
Impersonation T1659 Spoofs sender address, masquerades as victim's own account ^[strings.txt:41]
Delete Indicator Artifact T1070.004 Deletes :Zone.Identifier ADS ^[r2:main]
Single Mutex Instance — CreateMutexA with t11; exits on ERROR_ALREADY_EXISTS ^[r2:main]

References

  • OpenCTI artifact ID: 47f390f9-9e4e-4af9-be6e-2b5d7129583c ^[metadata.json]
  • MalwareBazaar source (inferred from OpenCTI malware-bazaar tag) ^[metadata.json]
  • Related wiki pages: phorpiex, xor-not-string-decryption

Provenance

Analysis derived from:

  • file.txt — file(1) output
  • strings.txt — raw strings (line numbers cited)
  • pefile.txt — pefile.py header dump
  • rabin2-info.txt — radare2 binary info
  • metadata.json / triage.json — OpenCTI pipeline metadata
  • radare2 decompilation of functions at 0x402740 (main), 0x401030 (decryptor), 0x401790 (DNS MX), 0x401800 (IP check), 0x401900 (downloader), 0x401a10 (SMTP engine), 0x4024e0 (thread proc)
  • Static-only; CAPE skipped (no Windows guest available) ^[dynamic-analysis.md]

^[/intel/analyses/cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000.html]