cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000phorpiex: cbc59001 — sextortion spam bot, mutex t11, 12:40:35 UTC campaign burst
Executive Summary
24th confirmed Phorpiex campaign sample. Self-contained sextortion spam bot compiled with MSVC 9.0, linked to MSVCR90.dll, 18.9 KB. Hardcoded XOR+NOT decrypt key Tmlr, mutex t11, window title YOU PERVERT! I RECORDED YOU!, and BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Part of the May 29 2026 ~30-minute campaign burst (t1–t13 + numeric mutex variants). Compiled between t7 (12:36:22) and t12 (12:41:46). Static-only; CAPE skipped.
What It Is
| Attribute | Value |
|---|---|
| SHA-256 | cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000 |
| Size | 18,944 bytes |
| File type | PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt] |
| Compiler | MSVC 9.0 (linker 9.0) ^[pefile.txt] |
| Timestamp | 2026-05-29 12:40:35 UTC ^[pefile.txt] |
| CRT | MSVCR90.dll (static manifest, version 9.0.21022.8) ^[strings.txt:147] |
| Signed | No ^[rabin2-info.txt] |
| ASLR / DEP | Yes (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt] |
OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar. ^[metadata.json]
How It Works
Entry point → main(): standard MSVC CRT entry0 → main() flow. main() sleeps 2,000 ms, creates mutex t11, then branches on GetLastError() == ERROR_ALREADY_EXISTS (0xB7). If mutex exists, exits; otherwise proceeds. ^[r2:main]
Single-instance gating + anti-forensics: Before spawning threads, deletes its own :Zone.Identifier ADS via DeleteFileW with a wsprintfW-formatted path. ^[r2:main]
External IP resolution: Calls fcn.00401800, which opens a WinInet session with UA Mozilla/5.0 ... Chrome/202.0.4664.110 ... ^[strings.txt:17], fetches http://icanhazip.com/, parses the dotted-quad response, and wraps it as [x.x.x.x]. Falls back to [0.0.0.0] on failure. ^[r2:fcn.00401800]
MX query: Calls fcn.00401790, which queries yahoo.com (type MX, 0x0F) via DnsQuery_A. On success, opens a TCP socket to the resolved MX and passes it to the SMTP engine. ^[r2:fcn.00401790]
String decryption: fcn.00401030 implements a 4-byte XOR+NOT loop using key Tmlr. Each input byte is XORed with the key byte (cycling), then NOTed. ^[r2:fcn.00401030]
SMTP engine: fcn.00401a10 runs a 7-case state machine over raw TCP socket I/O:
- Parse banner → detect
ESMTP EHLO %sorHELO %sMAIL FROM: <%s>RCPT TO: <%s>DATA- Assemble full RFC-822 message with spoofed
Received:headers, random local-part generation (fcn.004013c0produces 3–15 lowercase chars), and the hardcoded sextortion body QUIT
The message body is the standard Phorpiex sextortion template: claims R.A.T. infection, camera recording, demands $800 USD in BTC to wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, with purchase links for Coinbase, Binance, Bitrefill, Crypto.com, Kucoin, eToro, Kraken. ^[strings.txt:36-61]
Thread dispatch: fcn.004024e0 (thread proc) loops 100×50 = 5,000 thread spawns. Each thread re-reads the victim count from %TEMP%\<n>.txt, sleeps a random 0–100 ms between spawns, and after 100 outer iterations sleeps 20,000 ms before re-reading the count and exiting if count ≤ 1. ^[r2:fcn.004024e0]
Downloader helper: fcn.00401900 fetches payloads via WinInet (InternetOpenW/InternetOpenUrlW/InternetReadFile) with the same Chrome/202 UA, writes to a CreateFileW handle. Used for potential payload updates. ^[r2:fcn.00401900]
Decompiled Behavior
- entry0 @ 0x402bb7: Standard MSVC 9.0 CRT startup. No
inittermhijack — honestmain()flow. ^[r2:entry0] - main @ 0x402740: Sleep → mutex → Zone.Identifier deletion → WSAStartup → MX query → decrypt → thread spawn. ^[r2:main]
- fcn.00401030: XOR+NOT string decryptor with key
Tmlr. ^[r2:fcn.00401030] - fcn.00401790: DNS MX query for
yahoo.com. ^[r2:fcn.00401790] - fcn.00401800: HTTP GET to
icanhazip.comfor external IP. ^[r2:fcn.00401800] - fcn.00401900: WinInet downloader (payload fetcher). ^[r2:fcn.00401900]
- fcn.00401a10: Raw TCP SMTP client with 7-case state machine. ^[r2:fcn.00401a10]
- fcn.004024e0: Thread proc — 5,000-thread spam dispatch loop. ^[r2:fcn.004024e0]
C2 Infrastructure
| IOC | Value | Source |
|---|---|---|
| MX target | yahoo.com |
^[strings.txt:16] |
| External IP check | http://icanhazip.com/ |
^[strings.txt:18] |
| Fake UA | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/202.0.4664.110 Safari/537.36 |
^[strings.txt:17] |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
^[strings.txt:59] |
| Mutex | t11 |
^[r2:main] |
| Decrypt key | Tmlr |
^[strings.txt:160], ^[r2:fcn.00401030] |
| Window title | YOU PERVERT! I RECORDED YOU! |
^[strings.txt:146] |
| Ransom demand | $800 USD |
^[strings.txt:46] |
No ZIP attachment — email body is inline text (ZIP-less variant, matching t1–t13 sub-cluster).
Interesting Tidbits
- Campaign burst timing: Compiled at 12:40:35 UTC, between
t7(12:36:22) andt12(12:41:46). Fits the ~30-minute continuous builder rotation documented across the burst. ^[pefile.txt] - No ZIP constructor: Unlike the
150e4652$1200 variant, this sample omits the ZIP attachment builder. Inline text only, reducing binary size to 18.9 KB. - Identical
.texthash expected: Prior siblings in the $800 sub-cluster share an identical.textsection (same SMTP engine code). Likely true here too — the.textentropy of 5.99 is consistent with the cluster. ^[pefile.txt] - Chrome/202 UA: Impossible Chrome version (202.x) used across the entire May 29 burst. The builder hardcodes this; no UA rotation per sample. ^[strings.txt:17]
- Window title in .data: The
YOU PERVERT!string lives at 0x4000 in the.datasection, confirming it's part of the decrypted payload rather than the raw binary — consistent with the XOR+NOT obfuscation pattern. ^[strings.txt:146]
How To Mess With It
Toolchain: MSVC 9.0 (Visual Studio 2008), x86, Windows GUI subsystem.
Replication sketch: Compile a minimal Win32 PE with WinInet + WS2_32 + DNSAPI imports. Implement a 7-case SMTP state machine over raw TCP. Use DnsQuery_A for MX resolution. Use InternetOpenA/InternetReadFile for IP check. The XOR+NOT decryptor is trivial: for (i=0; s[i]; i++) s[i] = ~(s[i] ^ key[i % 4]);.
Verification: Build a test binary with the same import set and a hardcoded Tmlr key. Run strings — the key should appear plaintext. Compare section entropy to sibling t5 (.text ~5.99).
Deployable Signatures
YARA rule
rule phorpiex_sextortion_spam_bot_800 {
meta:
description = "Phorpiex sextortion spam bot $800 variant (t1-t13 burst)"
author = "PacketPursuit"
date = "2026-09-04"
hash = "cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000"
strings:
$key = "Tmlr" ascii wide
$ua = "Chrome/202.0.4664.110" ascii wide
$btc = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii wide
$title = "YOU PERVERT! I RECORDED YOU!" ascii wide
$mx = "yahoo.com" ascii wide
$ipcheck = "http://icanhazip.com/" ascii wide
$helo = "EHLO %s" ascii
$mailfrom = "MAIL FROM: %s" ascii
$rcptto = "RCPT TO: <%s>" ascii
$received = "Received: from %s ([%d.%d.%d.%d]) by %s with MailEnable ESMTP; %s" ascii
condition:
uint16(0) == 0x5A4D and
$key and $ua and $btc and ($helo or $mailfrom or $rcptto)
}
Behavioral hunt query (Sigma-style)
title: Phorpiex Sextortion Spam Bot Activity
status: experimental
description: Detects Phorpiex sextortion spam bot process behavior
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 't11'
- 't12'
- 't13'
- 't1'
- 't2'
- 't4'
- 't5'
- 't7'
network:
Initiated: 'true'
DestinationPort: 25
condition: selection and network
falsepositives:
- Unknown
level: high
IOC list
| Type | Value |
|---|---|
| SHA-256 | cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000 |
| SHA-1 | 4a077a0ed10d4bf84244f50e243608c8a41734bd |
| MD5 | 787720059300256f7d5e3159ccbe51d7 |
| Mutex | t11 |
| Decrypt key | Tmlr |
| BTC wallet | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
| Fake UA | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/202.0.4664.110 Safari/537.36 |
| MX target | yahoo.com |
| IP check | http://icanhazip.com/ |
| Temp file | %TEMP%\n.txt (victim list) |
| Temp file | %TEMP%\%d%d%d.jpg (sidecar) |
| Window title | YOU PERVERT! I RECORDED YOU! |
| Ransom | $800 USD |
Behavioral fingerprint statement
This binary is a self-contained MSVC 9.0 PE32 GUI executable that sleeps 2 seconds on launch, creates a single-instance mutex (pattern t[0-9]+ or numeric), deletes its own Zone.Identifier ADS, resolves yahoo.com MX records via DNS, fetches its external IP from icanhazip.com using a hardcoded Chrome/202 UA, then spawns 5,000 threads that each open raw TCP/25 sockets to the resolved MX and deliver a sextortion email demanding $800 USD in Bitcoin to a hardcoded wallet. All strings are decrypted at runtime using a 4-byte XOR+NOT loop with key Tmlr.
Detection Signatures
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | Spam-distributed PE ^[metadata.json] |
| OS Credential Dumping | T1003 | Claims access to accounts/camera ^[strings.txt:39] |
| Application Layer Protocol: SMTP | T1071.003 | Raw TCP/25 SMTP dialog ^[r2:fcn.00401a10] |
| Exfiltration Over C2 Channel | T1041 | SMTP email delivery of sextortion demand ^[r2:fcn.00401a10] |
| Data Encrypted for Impact | T1486 | Sextortion demand (psychological impact) ^[strings.txt:46] |
| Obfuscated Files or Information | T1027 | XOR+NOT string decryption ^[r2:fcn.00401030] |
| Impersonation | T1659 | Spoofs sender address, masquerades as victim's own account ^[strings.txt:41] |
| Delete Indicator Artifact | T1070.004 | Deletes :Zone.Identifier ADS ^[r2:main] |
| Single Mutex Instance | — | CreateMutexA with t11; exits on ERROR_ALREADY_EXISTS ^[r2:main] |
References
- OpenCTI artifact ID:
47f390f9-9e4e-4af9-be6e-2b5d7129583c^[metadata.json] - MalwareBazaar source (inferred from OpenCTI
malware-bazaartag) ^[metadata.json] - Related wiki pages: phorpiex, xor-not-string-decryption
Provenance
Analysis derived from:
file.txt— file(1) outputstrings.txt— raw strings (line numbers cited)pefile.txt— pefile.py header dumprabin2-info.txt— radare2 binary infometadata.json/triage.json— OpenCTI pipeline metadata- radare2 decompilation of functions at 0x402740 (main), 0x401030 (decryptor), 0x401790 (DNS MX), 0x401800 (IP check), 0x401900 (downloader), 0x401a10 (SMTP engine), 0x4024e0 (thread proc)
- Static-only; CAPE skipped (no Windows guest available) ^[dynamic-analysis.md]
^[/intel/analyses/cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000.html]