typeanalysisfamilyphorpiexconfidencehighmalware-familymalware-bazaarattributionc2-protocolsmtp-exfiltration
SHA-256: cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556

phorpiex: cff535e6 — MSVC9 sextortion spam bot, mutex t8, $800 variant

Executive Summary: Thirteenth confirmed variant in the Phorpiex $800 sextortion spam-bot sub-cluster. MSVC 9.0 PE32, 19 KB, self-contained WinInet+WS2_32 SMTP engine. XOR+NOT string decryption with key Tmlr. Mutex t8, compiled 12:37:13 UTC May 29 — fills the ~51-second gap between t7 (12:36:22) and t9 (12:37:51), confirming continuous builder rotation. Static-only (CAPE skipped — no Windows guest).

1. Build / RE

Toolchain: MSVC 9.0 (LinkerVersion 9.0), MSVCR90.dll static CRT, PE32 GUI, 5 sections (.text entropy 5.99, .rdata 5.11). ^[file.txt] ^[rabin2-info.txt] Compiled 2026-05-29 12:37:13 UTC. ^[exiftool.json:15]

Packing / obfuscation: None. No packer, no crypter, no section encryption. Binary is plaintext C with standard CRT imports. ^[pefile.txt]

Anti-analysis: Minimal. IsDebuggerPresent imported ^[pefile.txt:377] but no VM checks, no timing gates, no anti-disassembly tricks. Entry point is honest main() (not initterm hijack as seen in older Phorpiex loader variants).

String decryption: Runtime XOR+NOT loop using key "Tmlr" (little-endian dword 0x726c6d54). ^[r2:fcn.00401030] The decryptor iterates the key cyclically: plaintext = ~(ciphertext ^ key_byte). Same key shared by all $800 sub-cluster siblings.

Code quality: Straightforward C. Heavy use of wsprintfA/strcat for SMTP message assembly. No heap allocations observed; all buffers are stack-local or .data globals. Nested CreateThread loops spawn 5,000 worker threads (outer 100 × inner 50). ^[r2:fcn.004024e0]

Signing: Unsigned. signed: false in rabin2; no certificate table. ^[rabin2-info.txt:27]

Resources: Single RT_MANIFEST resource (assembly identity Microsoft.VC90.CRT v9.0.21022.8). No embedded payload resources or encrypted blobs. ^[pefile.txt:393-431]

2. Deploy / ATT&CK

T1204.002 — User Execution: Malicious File (spam-distributed PE).
T1071.003 — Application Layer Protocol: Mail Protocols (self-contained SMTP client over TCP/25).
T1583.001 — Acquire Infrastructure: Domains (yahoo.com MX resolution via DnsQuery_A).
T1589.002 — Gather Victim Network Information (public IP fetch via http://icanhazip.com/).
T1497.001 — Virtualization/Sandbox Evasion: Time-Based Evasion — a 2-second Sleep(2000) at main() entry before mutex creation. ^[r2:main]

Persistence: None observed. No registry writes, no scheduled tasks, no startup-folder copies. Purely spam-delivery utility.

Execution flow:

  1. Sleep(2000) → CreateMutexA("t8") → exit if mutex exists (single-instance gate). ^[r2:main]
  2. Delete %MODULE_PATH%:Zone.Identifier ADS to remove download mark. ^[r2:main]
  3. WSAStartup → DnsQuery_A("yahoo.com", DNS_TYPE_MX) → validate MX records exist. ^[r2:fcn.00401790]
  4. WinInet fetch of http://icanhazip.com/ to obtain external IP; parse first dotted-quad. ^[r2:fcn.00401800]
  5. Decrypt strings in-place with "Tmlr" key (XOR+NOT). ^[r2:fcn.00401030]
  6. Spawn SMTP spam thread (fcn.004024e0) which launches 5,000 workers.
  7. Each worker reads a victim email from %TEMP%\<rand>n.txt, connects to the resolved MX on TCP/25, and walks an SMTP state machine: EHLO/HELO → MAIL FROM → RCPT TO → DATA → inline sextortion body → QUIT. ^[r2:fcn.00401a10]

Email template: Full inline sextortion text, $800 BTC demand, wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Subject line hardcoded as "YOU PERVERT! I RECORDED YOU!". ^[strings.txt:146] ^[r2:fcn.00401a10]

C2 / Infrastructure: No traditional C2. The bot is fully autonomous:

  • MX target: yahoo.com (DNS A/MX via DNSAPI.DnsQuery_A).
  • Public IP recon: http://icanhazip.com/ (clear-text HTTP).
  • Fake UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 — impossible Chrome version. ^[strings.txt:17]

Attribution: Campaign burst compilation times confirm continuous builder rotation: t1 (12:13:57) → t2 (12:15:01) → t4 (12:33:18) → t5 (12:34:02) → t7 (12:36:22) → this sample t8 (12:37:13) → t9 (12:37:51) → t10 (12:39:58) → t11 (12:40:35) → t12 (12:41:46) → t13 (12:42:51). All share identical XOR+NOT key Tmlr, identical BTC wallet, identical 5,000-thread SMTP engine, and identical $800 ransom demand. This is parameter-rotated campaign output, not code evolution.

Interesting Tidbits

  • The Zone.Identifier ADS deletion is a defensive counter-forensics step to hide the download origin. ^[r2:main]
  • The email body is constructed with 20+ sequential strcat calls against a single 260-byte stack buffer — a primitive but effective in-memory assembler. ^[r2:fcn.00401a10]
  • CreateThread is called with a thread-function pointer that is actually a raw byte string in the decompilation ("U\x8b\xec\x81\xec@\t" at 0x4024e0) — the thread entry is a real function, the r2 decompiler is showing raw bytes at the reference site. ^[r2:main]
  • The mutex name "t8" breaks the numeric t1–t13 sequence only by the absence of t3 and t6 in the corpus so far; the builder likely generates them and they simply haven't been ingested yet.

Deployable Signatures

YARA

rule Phorpiex_Sextortion_800USD_Tmlr : phorpiex
{
    meta:
        description = "Phorpiex $800 sextortion spam bot — Tmlr XOR+NOT decryptor"
        author = "packetpursuit"
        date = "2026-09-05"
        hash = "cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556"
    strings:
        $key = "Tmlr" ascii
        $ua = "Chrome/202.0.4664.110" ascii
        $wallet = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
        $subject = "YOU PERVERT! I RECORDED YOU!" ascii
        $ehlo = "EHLO %s\r\n" ascii
        $mailfrom = "MAIL FROM: %s\r\n" ascii
        $rcptto = "RCPT TO: <%s>\r\n" ascii
        $yahoo = "yahoo.com" ascii
    condition:
        uint16(0) == 0x5A4D and
        4 of them and
        filesize < 25KB
}

IOCs

  • SHA-256: cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556
  • Mutex: t8
  • BTC wallet: 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K
  • Fake UA: Mozilla/5.0 ... Chrome/202.0.4664.110 ...
  • Recon URL: http://icanhazip.com/
  • MX target: yahoo.com
  • Subject: YOU PERVERT! I RECORDED YOU!
  • Ransom demand: $800 USD in Bitcoin (BTC)
  • Temp file pattern: %TEMP%\%sn.txt (victim email list), %TEMP%\%d%d%d.jpg (attachment placeholder, unused in this build)

Behavioral Fingerprint

On execution, the binary sleeps 2 seconds, creates a mutex named t8, deletes its own Zone.Identifier ADS, queries DNS for yahoo.com MX records, fetches icanhazip.com to learn its external IP, then spawns 5,000 threads each opening a TCP connection to port 25 and transmitting an SMTP envelope with a hardcoded sextortion body demanding $800 in Bitcoin.

Detection Signatures

Technique Mapping Evidence
T1204.002 User Execution: Malicious File Spam-distributed PE32 GUI ^[file.txt]
T1071.003 Mail Protocols Self-contained SMTP engine via WS2_32 ^[r2:fcn.00401a10]
T1583.001 Domains MX resolution against yahoo.com ^[r2:fcn.00401790]
T1589.002 Network Information HTTP GET to icanhazip.com ^[strings.txt:18]
T1497.001 Time-Based Evasion Sleep(2000) at entry ^[r2:main]

References

Provenance

Static analysis performed with radare2 (level 3 auto-analysis, 78 functions recovered). No dynamic execution available (CAPE skipped — no Windows guest). All claims cite r2 decompilation or raw tool output. String decryption algorithm inferred from disassembly of fcn.00401030 and confirmed against plaintext strings visible post-decrypt in the .rdata section.