cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556phorpiex: cff535e6 — MSVC9 sextortion spam bot, mutex t8, $800 variant
Executive Summary: Thirteenth confirmed variant in the Phorpiex $800 sextortion spam-bot sub-cluster. MSVC 9.0 PE32, 19 KB, self-contained WinInet+WS2_32 SMTP engine. XOR+NOT string decryption with key Tmlr. Mutex t8, compiled 12:37:13 UTC May 29 — fills the ~51-second gap between t7 (12:36:22) and t9 (12:37:51), confirming continuous builder rotation. Static-only (CAPE skipped — no Windows guest).
1. Build / RE
Toolchain: MSVC 9.0 (LinkerVersion 9.0), MSVCR90.dll static CRT, PE32 GUI, 5 sections (.text entropy 5.99, .rdata 5.11). ^[file.txt] ^[rabin2-info.txt] Compiled 2026-05-29 12:37:13 UTC. ^[exiftool.json:15]
Packing / obfuscation: None. No packer, no crypter, no section encryption. Binary is plaintext C with standard CRT imports. ^[pefile.txt]
Anti-analysis: Minimal. IsDebuggerPresent imported ^[pefile.txt:377] but no VM checks, no timing gates, no anti-disassembly tricks. Entry point is honest main() (not initterm hijack as seen in older Phorpiex loader variants).
String decryption: Runtime XOR+NOT loop using key "Tmlr" (little-endian dword 0x726c6d54). ^[r2:fcn.00401030] The decryptor iterates the key cyclically: plaintext = ~(ciphertext ^ key_byte). Same key shared by all $800 sub-cluster siblings.
Code quality: Straightforward C. Heavy use of wsprintfA/strcat for SMTP message assembly. No heap allocations observed; all buffers are stack-local or .data globals. Nested CreateThread loops spawn 5,000 worker threads (outer 100 × inner 50). ^[r2:fcn.004024e0]
Signing: Unsigned. signed: false in rabin2; no certificate table. ^[rabin2-info.txt:27]
Resources: Single RT_MANIFEST resource (assembly identity Microsoft.VC90.CRT v9.0.21022.8). No embedded payload resources or encrypted blobs. ^[pefile.txt:393-431]
2. Deploy / ATT&CK
T1204.002 — User Execution: Malicious File (spam-distributed PE).
T1071.003 — Application Layer Protocol: Mail Protocols (self-contained SMTP client over TCP/25).
T1583.001 — Acquire Infrastructure: Domains (yahoo.com MX resolution via DnsQuery_A).
T1589.002 — Gather Victim Network Information (public IP fetch via http://icanhazip.com/).
T1497.001 — Virtualization/Sandbox Evasion: Time-Based Evasion — a 2-second Sleep(2000) at main() entry before mutex creation. ^[r2:main]
Persistence: None observed. No registry writes, no scheduled tasks, no startup-folder copies. Purely spam-delivery utility.
Execution flow:
Sleep(2000)→CreateMutexA("t8")→ exit if mutex exists (single-instance gate). ^[r2:main]- Delete
%MODULE_PATH%:Zone.IdentifierADS to remove download mark. ^[r2:main] WSAStartup→DnsQuery_A("yahoo.com", DNS_TYPE_MX)→ validate MX records exist. ^[r2:fcn.00401790]- WinInet fetch of
http://icanhazip.com/to obtain external IP; parse first dotted-quad. ^[r2:fcn.00401800] - Decrypt strings in-place with
"Tmlr"key (XOR+NOT). ^[r2:fcn.00401030] - Spawn SMTP spam thread (
fcn.004024e0) which launches 5,000 workers. - Each worker reads a victim email from
%TEMP%\<rand>n.txt, connects to the resolved MX on TCP/25, and walks an SMTP state machine:EHLO/HELO→MAIL FROM→RCPT TO→DATA→ inline sextortion body →QUIT. ^[r2:fcn.00401a10]
Email template: Full inline sextortion text, $800 BTC demand, wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Subject line hardcoded as "YOU PERVERT! I RECORDED YOU!". ^[strings.txt:146] ^[r2:fcn.00401a10]
C2 / Infrastructure: No traditional C2. The bot is fully autonomous:
- MX target:
yahoo.com(DNS A/MX viaDNSAPI.DnsQuery_A). - Public IP recon:
http://icanhazip.com/(clear-text HTTP). - Fake UA:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36— impossible Chrome version. ^[strings.txt:17]
Attribution: Campaign burst compilation times confirm continuous builder rotation: t1 (12:13:57) → t2 (12:15:01) → t4 (12:33:18) → t5 (12:34:02) → t7 (12:36:22) → this sample t8 (12:37:13) → t9 (12:37:51) → t10 (12:39:58) → t11 (12:40:35) → t12 (12:41:46) → t13 (12:42:51). All share identical XOR+NOT key Tmlr, identical BTC wallet, identical 5,000-thread SMTP engine, and identical $800 ransom demand. This is parameter-rotated campaign output, not code evolution.
Interesting Tidbits
- The
Zone.IdentifierADS deletion is a defensive counter-forensics step to hide the download origin. ^[r2:main] - The email body is constructed with 20+ sequential
strcatcalls against a single 260-byte stack buffer — a primitive but effective in-memory assembler. ^[r2:fcn.00401a10] CreateThreadis called with a thread-function pointer that is actually a raw byte string in the decompilation ("U\x8b\xec\x81\xec@\t"at0x4024e0) — the thread entry is a real function, the r2 decompiler is showing raw bytes at the reference site. ^[r2:main]- The mutex name
"t8"breaks the numerict1–t13sequence only by the absence oft3andt6in the corpus so far; the builder likely generates them and they simply haven't been ingested yet.
Deployable Signatures
YARA
rule Phorpiex_Sextortion_800USD_Tmlr : phorpiex
{
meta:
description = "Phorpiex $800 sextortion spam bot — Tmlr XOR+NOT decryptor"
author = "packetpursuit"
date = "2026-09-05"
hash = "cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556"
strings:
$key = "Tmlr" ascii
$ua = "Chrome/202.0.4664.110" ascii
$wallet = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
$subject = "YOU PERVERT! I RECORDED YOU!" ascii
$ehlo = "EHLO %s\r\n" ascii
$mailfrom = "MAIL FROM: %s\r\n" ascii
$rcptto = "RCPT TO: <%s>\r\n" ascii
$yahoo = "yahoo.com" ascii
condition:
uint16(0) == 0x5A4D and
4 of them and
filesize < 25KB
}
IOCs
- SHA-256:
cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556 - Mutex:
t8 - BTC wallet:
1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K - Fake UA:
Mozilla/5.0 ... Chrome/202.0.4664.110 ... - Recon URL:
http://icanhazip.com/ - MX target:
yahoo.com - Subject:
YOU PERVERT! I RECORDED YOU! - Ransom demand:
$800 USD in Bitcoin (BTC) - Temp file pattern:
%TEMP%\%sn.txt(victim email list),%TEMP%\%d%d%d.jpg(attachment placeholder, unused in this build)
Behavioral Fingerprint
On execution, the binary sleeps 2 seconds, creates a mutex named t8, deletes its own Zone.Identifier ADS, queries DNS for yahoo.com MX records, fetches icanhazip.com to learn its external IP, then spawns 5,000 threads each opening a TCP connection to port 25 and transmitting an SMTP envelope with a hardcoded sextortion body demanding $800 in Bitcoin.
Detection Signatures
| Technique | Mapping | Evidence |
|---|---|---|
| T1204.002 | User Execution: Malicious File | Spam-distributed PE32 GUI ^[file.txt] |
| T1071.003 | Mail Protocols | Self-contained SMTP engine via WS2_32 ^[r2:fcn.00401a10] |
| T1583.001 | Domains | MX resolution against yahoo.com ^[r2:fcn.00401790] |
| T1589.002 | Network Information | HTTP GET to icanhazip.com ^[strings.txt:18] |
| T1497.001 | Time-Based Evasion | Sleep(2000) at entry ^[r2:main] |
References
- phorpiex — cluster entity page
- xor-not-string-decryption — build/RE technique page
- smtp-exfiltration — concept page
- MalwareBazaar:
cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556
Provenance
Static analysis performed with radare2 (level 3 auto-analysis, 78 functions recovered). No dynamic execution available (CAPE skipped — no Windows guest). All claims cite r2 decompilation or raw tool output. String decryption algorithm inferred from disassembly of fcn.00401030 and confirmed against plaintext strings visible post-decrypt in the .rdata section.