typeanalysisfamilyphorpiexconfidencehighcreated2026-09-02updated2026-09-02malware-familyloadermalware-bazaarattributionpec2exfiltrationimpact
SHA-256: dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a

phorpiex: dc2936ea — sextortion spam bot $800 variant, mutex t4, 5,000 threads

Executive Summary

A self-contained sextortion spam bot compiled 2026-05-29 12:33:18 UTC, part of the active Phorpiex campaign. It is a twin build of sibling c3b1b4e4 (mutex t5), compiled ~44 seconds earlier in the same burst. The binary contains a complete SMTP engine, hardcoded $800 BTC ransom demand, and spawns 5,000 concurrent threads for email delivery. No external C2 — all infrastructure is self-contained.

What It Is

PE32 GUI, MSVC 9.0 / MSVCR90, 18,944 bytes, compiled 2026-05-29 12:33:18 UTC. ^[file.txt] Five sections (.text, .rdata, .data, .rsrc, .reloc), PE checksum 0x13B00, no digital signature, ASLR/DEP enabled. ^[pefile.txt] RT_MANIFEST resource with VC90 CRT dependency manifest. ^[pefile.txt:391]

This is a confirmed sibling of the Phorpiex sextortion spam bot cluster. See phorpiex for shared campaign architecture, and sibling c3b1b4e4 for the mutex-t5 twin. ^[entities/phorpiex.md]

How It Works

Entry Sequence (Main Thread)

  1. Sleep 2,000 ms — anti-emulation / sandbox delay gate. ^[r2:main@0x402744]
  2. CreateMutexA("t4") — single-instance enforcement. If mutex already exists (GetLastError() == 183), aborts. ^[r2:main@0x40274c]
  3. Delete Zone.Identifier ADS — DeleteFileW(L"%s:Zone.Identifier") on its own path, stripping download origin marker. ^[r2:main@0x40277e]
  4. WSAStartup(0x202) — initializes Winsock for SMTP. ^[r2:main@0x4027c7]
  5. External IP resolution — calls fcn.00401900 which fetches http://icanhazip.com/ via WinInet with a hardcoded Chrome User-Agent. ^[strings.txt:17] [strings.txt:18] Writes the result to %TEMP%\[n].txt and %TEMP%\[ddd].jpg. ^[r2:fcn.00401900]
  6. DNS MX query — DnsQuery_A("yahoo.com", DNS_TYPE_MX, 0xF) resolves Yahoo MX records for SMTP relay. ^[r2:fcn.00401790]
  7. String decryption — XOR+NOT cipher with 4-byte key "Tmlr" (0x546d6c72) decrypts the email template and SMTP commands at runtime. ^[r2:fcn.00401030] ^[strings.txt:146]
  8. Thread storm — spawns a two-tier thread dispatch loop producing 5,000 concurrent threads (100 outer iterations × 50 inner iterations). ^[r2:fcn.004024e0] Each thread calls fcn.00402340 (the per-thread SMTP worker).
  9. Post-dispatch sleep — Sleep(0xcdfe600) = 216,000,000 ms (~60 hours / 2.5 days), then loops forever. ^[r2:main@0x402831]

Per-Thread SMTP Worker (fcn.00402340)

  1. Seeds PRNG from GetTickCount() via srand().
  2. Opens a local file (likely the temp-staged email list) and randomly selects a recipient line.
  3. Parses the line with strtok on : and // delimiters.
  4. Calls fcn.00401a10 — the actual SMTP client that sends the sextortion email.

Email Template

The decrypted body is the standard Phorpiex sextortion template: ^[strings.txt:36-60]

  • Claims RAT infection and camera recording
  • Demands $800 USD in Bitcoin (BTC)
  • Hardcoded wallet: 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]
  • Lists six exchange URLs (coinbase, binance, bitrefill, crypto.com, kucoin, etoro, kraken) ^[strings.txt:49-56]
  • Subject and headers built with wsprintfA using standard SMTP format strings ^[strings.txt:21-35]

Decompiled Behavior

Entry Point

entry0 @ 0x00402BB7 — standard MSVC CRT entry that calls main(). No initterm hijack observed; this sample uses honest main() flow. ^[r2:entry0]

Notable Functions

Function Role Key Evidence
main (0x00402740) Orchestrator Sleep gate, mutex, WSAStartup, IP check, thread dispatch
fcn.00401030 String decryptor XOR with "Tmlr", then bitwise NOT
fcn.00401790 MX resolver DnsQuery_A("yahoo.com", DNS_TYPE_MX)
fcn.00401900 IP fetcher WinInet InternetOpenW + InternetOpenUrlW to icanhazip.com
fcn.004024e0 Thread dispatcher 100×50 nested loops, CreateThread + rand()%50+50 sleep jitter
fcn.00402340 Per-thread SMTP worker File read, random line select, strtok parse, fcn.00401a10 call
fcn.00401a10 SMTP client Called by thread worker; actual socket send/recv logic

Control Flow Patterns

  • No PEB walking — imports are resolved normally via IAT (MSVCR90, WININET, SHLWAPI, WS2_32, DNSAPI, KERNEL32, USER32). ^[pefile.txt:229-390]
  • No anti-VM — no IsDebuggerPresent check in main flow (imported but not called by entry path). ^[pefile.txt:377]
  • No runtime API resolution — all APIs imported statically. This is the simplest build variant in the Phorpiex cluster.

C2 Infrastructure

No remote C2 server. This binary is entirely self-contained. The only network interactions are:

  • IP check: http://icanhazip.com/ (HTTP GET, no SSL) ^[strings.txt:18]
  • MX resolution: yahoo.com via DNS API ^[strings.txt:16] ^[r2:fcn.00401790]
  • SMTP delivery: Direct MX-to-MX delivery via raw sockets (WS2_32) to resolved Yahoo MX records

BTC Wallet: 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]

Ransom Amount: $800 USD ^[strings.txt:46]

Mutex: t4 ^[r2:main@0x40274c]

Thread Count: 5,000 (100 × 50 nested loops) ^[r2:fcn.004024e0]

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 ^[strings.txt:17]

Temp Files:

  • %TEMP%\[n].txt (IP resolution staging) ^[r2:fcn.004024e0]
  • %TEMP%\[ddd].jpg (additional staging file) ^[strings.txt:181]

Interesting Tidbits

  • Twin build: dc2936ea (12:33:18 UTC) and c3b1b4e4 (12:34:02 UTC) were compiled 44 seconds apart, share identical BTC wallet, thread count, and decrypt key — only the mutex differs (t4 vs t5). This is a campaign-level parameter rotation, not a code change. ^[entities/phorpiex.md]
  • No ZIP attachment: Unlike the earlier $1200 variant (150e4652), the $800 sub-cluster omits the ZIP constructor and sends a plain-text email body. ^[entities/phorpiex.md]
  • Honest main() flow: Unlike the reflective-loader Phorpiex stubs (755bed07), this sample has no initterm hijack or shellcode staging. It is a straightforward C program with a main() function. ^[r2:entry0]
  • Chrome/202 UA: The User-Agent uses an impossible Chrome version (202.0.4664.110), a known Phorpiex campaign fingerprint. ^[strings.txt:17] ^[techniques/chrome-128-ua-masquerade.md]
  • No capa results: capa failed with missing signatures directory. ^[capa.txt]
  • YARA hits: PE_File_Generic and Suspicious_Wininet_Imports — only generic detections. ^[yara.txt]

How To Mess With It (Homelab Replication)

Not recommended for replication — this is a spam-sending tool with no educational value beyond understanding SMTP abuse. For defensive research, extract the email template and BTC wallet for IOC lists. The build stack is MSVC 9.0 (Visual Studio 2008) with standard C runtime, no special toolchain required.

Verification: compile any Win32 console app with cl.exe from VS2008, link against msvcrt.lib, and observe comparable PE structure (checksum, section layout, import table). The actual malicious behavior (SMTP engine, thread storm) is pure C code with no novel techniques.

Deployable Signatures

YARA Rule

rule Phorpiex_Sextortion_SpamBot_800usd_t4 {
    meta:
        description = "Phorpiex sextortion spam bot $800 variant, mutex t4, 5,000 threads"
        author = "triage-pipeline"
        date = "2026-09-02"
        sha256 = "dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a"
        reference = "https://www.malwarebazaar.com/sample/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a"
    strings:
        $mutex_t4 = "t4" ascii wide
        $decrypt_key = "Tmlr" ascii
        $btc_wallet = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
        $ua = "Chrome/202.0.4664.110" ascii
        $ip_check = "http://icanhazip.com/" ascii
        $yahoo_mx = "yahoo.com" ascii
        $template_1 = "I RECORDED YOU (through your camera) MASTURBATING!" ascii
        $template_2 = "All you need is $800 USD in Bitcoin (BTC)" ascii
        $ehlo = "EHLO %s\r\n" ascii
        $mail_from = "MAIL FROM: %s\r\n" ascii
        $rcpt_to = "RCPT TO: <%s>\r\n" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize < 25KB and
        pe.linker_version.major == 9 and
        pe.linker_version.minor == 0 and
        (pe.imports("MSVCR90.dll") or pe.imports("MSVCR90.dll")) and
        pe.imports("WININET.dll") and
        pe.imports("WS2_32.dll") and
        pe.imports("DNSAPI.dll") and
        $btc_wallet and
        ($mutex_t4 or $decrypt_key) and
        ($template_1 or $template_2)
}

Behavioral Hunt Query (Sigma)

title: Phorpiex Sextortion Spam Bot Mutex Creation
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - CommandLine|contains: 't4'
        - CommandLine|contains: 't5'
        - CommandLine|contains: 'etyueu'
        - CommandLine|contains: 'efaefaef'
        - CommandLine|contains: 'ww88ww8w8'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC List

Indicator Type Value Provenance
SHA-256 Hash dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a triage.json
Mutex Mutex t4 r2:main@0x40274c
BTC Wallet Cryptocurrency 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K strings.txt:59
Ransom Amount Financial $800 USD strings.txt:46
IP Check URL URL http://icanhazip.com/ strings.txt:18
MX Domain Domain yahoo.com strings.txt:16
User-Agent Network Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 strings.txt:17
Temp File Pattern File %TEMP%\[n].txt r2:fcn.004024e0
Temp File Pattern File %TEMP%\[ddd].jpg strings.txt:181
Thread Count Behavioral 5,000 concurrent SMTP threads r2:fcn.004024e0
Decrypt Key Crypto Tmlr (XOR+NOT) r2:fcn.00401030
Compiler Toolchain MSVC 9.0 (Visual Studio 2008) pefile.txt:45
PE Checksum PE 0x13B00 pefile.txt:65
Compile Time Timestamp 2026-05-29 12:33:18 UTC pefile.txt:34

Behavioral Fingerprint

On launch, this binary sleeps 2 seconds, creates a mutex named t4, deletes its own Zone.Identifier ADS, initializes Winsock, fetches the victim's public IP via icanhazip.com over HTTP with a fake Chrome/202 User-Agent, resolves yahoo.com MX records via DNS API, decrypts a hardcoded sextortion email template with XOR+NOT key Tmlr, and spawns 5,000 concurrent threads that each send the email via direct SMTP to randomly selected recipients. The main thread then sleeps for 60 hours before looping. No C2 server, no persistence mechanism, no file encryption. Pure spam delivery.

Detection Signatures

  • Mandiant capa: Failed — missing signature database. No capability mapping available. ^[capa.txt]
  • YARA: PE_File_Generic (trivial), Suspicious_Wininet_Imports (generic). ^[yara.txt]
  • SSDeep: 192:/RIISCngTBvblVPT0Y76fIkq2NleQY9T4KUSvu9zw+ggSmOiMbO5Ot1EdkF39TGW:DIblVP4Y/2N0bLu9JgPL7Nyav8U9c4 ^[ssdeep.txt]
  • TLSH: 85824B0FF9418216D1E210B452B5867BD9799C72338458DBFBD08A9D0BA86D6FC3315F ^[tlsh.txt]

References

  • MalwareBazaar: https://www.malwarebazaar.com/sample/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a
  • Phorpiex entity page: phorpiex
  • Sibling analysis (mutex t5): /intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html
  • Chrome impossible-version UA masquerade: techniques/chrome-128-ua-masquerade.md
  • Sextortion spam bot technique: phorpiex-loader-initterm-hijack.md (though this sample uses honest main)

Provenance

Analysis derived from:

  • file.txt — file v5.44
  • pefile.txt — pefile Python library, full PE header dump
  • strings.txt — strings v2.37, 183 strings recovered
  • rabin2-info.txt — radare2 v5.9.2 rabin2 -I
  • capa.txt — Mandiant capa v7.0.0 (failed — missing signatures)
  • yara.txt — custom rules PE_File_Generic, Suspicious_Wininet_Imports
  • ssdeep.txt — ssdeep v2.14.1
  • tlsh.txt — TLSH v4.8.2
  • binwalk.txt — binwalk v2.3.4 (no embedded artifacts)
  • floss.txt — flare-floss v2.3.0 (failed — argument parsing error)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • radare2 decompilation — pdg via r2ghidra-dec, functions: entry0, main, fcn.00401030, fcn.00401790, fcn.00401900, fcn.00402340, fcn.004024e0, fcn.00401a10
  • Binary: <sample dc2936ea921e.bin> (18,944 bytes)