dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5aphorpiex: dc2936ea — sextortion spam bot $800 variant, mutex t4, 5,000 threads
Executive Summary
A self-contained sextortion spam bot compiled 2026-05-29 12:33:18 UTC, part of the active Phorpiex campaign. It is a twin build of sibling c3b1b4e4 (mutex t5), compiled ~44 seconds earlier in the same burst. The binary contains a complete SMTP engine, hardcoded $800 BTC ransom demand, and spawns 5,000 concurrent threads for email delivery. No external C2 — all infrastructure is self-contained.
What It Is
PE32 GUI, MSVC 9.0 / MSVCR90, 18,944 bytes, compiled 2026-05-29 12:33:18 UTC. ^[file.txt] Five sections (.text, .rdata, .data, .rsrc, .reloc), PE checksum 0x13B00, no digital signature, ASLR/DEP enabled. ^[pefile.txt] RT_MANIFEST resource with VC90 CRT dependency manifest. ^[pefile.txt:391]
This is a confirmed sibling of the Phorpiex sextortion spam bot cluster. See phorpiex for shared campaign architecture, and sibling c3b1b4e4 for the mutex-t5 twin. ^[entities/phorpiex.md]
How It Works
Entry Sequence (Main Thread)
- Sleep 2,000 ms — anti-emulation / sandbox delay gate. ^[r2:main@0x402744]
- CreateMutexA("t4") — single-instance enforcement. If mutex already exists (
GetLastError() == 183), aborts. ^[r2:main@0x40274c] - Delete Zone.Identifier ADS —
DeleteFileW(L"%s:Zone.Identifier")on its own path, stripping download origin marker. ^[r2:main@0x40277e] - WSAStartup(0x202) — initializes Winsock for SMTP. ^[r2:main@0x4027c7]
- External IP resolution — calls
fcn.00401900which fetcheshttp://icanhazip.com/via WinInet with a hardcoded Chrome User-Agent. ^[strings.txt:17] [strings.txt:18] Writes the result to%TEMP%\[n].txtand%TEMP%\[ddd].jpg. ^[r2:fcn.00401900] - DNS MX query —
DnsQuery_A("yahoo.com", DNS_TYPE_MX, 0xF)resolves Yahoo MX records for SMTP relay. ^[r2:fcn.00401790] - String decryption — XOR+NOT cipher with 4-byte key
"Tmlr"(0x546d6c72) decrypts the email template and SMTP commands at runtime. ^[r2:fcn.00401030] ^[strings.txt:146] - Thread storm — spawns a two-tier thread dispatch loop producing 5,000 concurrent threads (100 outer iterations × 50 inner iterations). ^[r2:fcn.004024e0] Each thread calls
fcn.00402340(the per-thread SMTP worker). - Post-dispatch sleep —
Sleep(0xcdfe600)= 216,000,000 ms (~60 hours / 2.5 days), then loops forever. ^[r2:main@0x402831]
Per-Thread SMTP Worker (fcn.00402340)
- Seeds PRNG from
GetTickCount()viasrand(). - Opens a local file (likely the temp-staged email list) and randomly selects a recipient line.
- Parses the line with
strtokon:and//delimiters. - Calls
fcn.00401a10— the actual SMTP client that sends the sextortion email.
Email Template
The decrypted body is the standard Phorpiex sextortion template: ^[strings.txt:36-60]
- Claims RAT infection and camera recording
- Demands $800 USD in Bitcoin (BTC)
- Hardcoded wallet:
1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K^[strings.txt:59] - Lists six exchange URLs (coinbase, binance, bitrefill, crypto.com, kucoin, etoro, kraken) ^[strings.txt:49-56]
- Subject and headers built with
wsprintfAusing standard SMTP format strings ^[strings.txt:21-35]
Decompiled Behavior
Entry Point
entry0 @ 0x00402BB7 — standard MSVC CRT entry that calls main(). No initterm hijack observed; this sample uses honest main() flow. ^[r2:entry0]
Notable Functions
| Function | Role | Key Evidence |
|---|---|---|
main (0x00402740) |
Orchestrator | Sleep gate, mutex, WSAStartup, IP check, thread dispatch |
fcn.00401030 |
String decryptor | XOR with "Tmlr", then bitwise NOT |
fcn.00401790 |
MX resolver | DnsQuery_A("yahoo.com", DNS_TYPE_MX) |
fcn.00401900 |
IP fetcher | WinInet InternetOpenW + InternetOpenUrlW to icanhazip.com |
fcn.004024e0 |
Thread dispatcher | 100×50 nested loops, CreateThread + rand()%50+50 sleep jitter |
fcn.00402340 |
Per-thread SMTP worker | File read, random line select, strtok parse, fcn.00401a10 call |
fcn.00401a10 |
SMTP client | Called by thread worker; actual socket send/recv logic |
Control Flow Patterns
- No PEB walking — imports are resolved normally via IAT (MSVCR90, WININET, SHLWAPI, WS2_32, DNSAPI, KERNEL32, USER32). ^[pefile.txt:229-390]
- No anti-VM — no
IsDebuggerPresentcheck in main flow (imported but not called by entry path). ^[pefile.txt:377] - No runtime API resolution — all APIs imported statically. This is the simplest build variant in the Phorpiex cluster.
C2 Infrastructure
No remote C2 server. This binary is entirely self-contained. The only network interactions are:
- IP check:
http://icanhazip.com/(HTTP GET, no SSL) ^[strings.txt:18] - MX resolution:
yahoo.comvia DNS API ^[strings.txt:16] ^[r2:fcn.00401790] - SMTP delivery: Direct MX-to-MX delivery via raw sockets (WS2_32) to resolved Yahoo MX records
BTC Wallet: 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K ^[strings.txt:59]
Ransom Amount: $800 USD ^[strings.txt:46]
Mutex: t4 ^[r2:main@0x40274c]
Thread Count: 5,000 (100 × 50 nested loops) ^[r2:fcn.004024e0]
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 ^[strings.txt:17]
Temp Files:
%TEMP%\[n].txt(IP resolution staging) ^[r2:fcn.004024e0]%TEMP%\[ddd].jpg(additional staging file) ^[strings.txt:181]
Interesting Tidbits
- Twin build:
dc2936ea(12:33:18 UTC) andc3b1b4e4(12:34:02 UTC) were compiled 44 seconds apart, share identical BTC wallet, thread count, and decrypt key — only the mutex differs (t4vst5). This is a campaign-level parameter rotation, not a code change. ^[entities/phorpiex.md] - No ZIP attachment: Unlike the earlier $1200 variant (
150e4652), the $800 sub-cluster omits the ZIP constructor and sends a plain-text email body. ^[entities/phorpiex.md] - Honest
main()flow: Unlike the reflective-loader Phorpiex stubs (755bed07), this sample has noinittermhijack or shellcode staging. It is a straightforward C program with amain()function. ^[r2:entry0] - Chrome/202 UA: The User-Agent uses an impossible Chrome version (
202.0.4664.110), a known Phorpiex campaign fingerprint. ^[strings.txt:17] ^[techniques/chrome-128-ua-masquerade.md] - No capa results: capa failed with missing signatures directory. ^[capa.txt]
- YARA hits:
PE_File_GenericandSuspicious_Wininet_Imports— only generic detections. ^[yara.txt]
How To Mess With It (Homelab Replication)
Not recommended for replication — this is a spam-sending tool with no educational value beyond understanding SMTP abuse. For defensive research, extract the email template and BTC wallet for IOC lists. The build stack is MSVC 9.0 (Visual Studio 2008) with standard C runtime, no special toolchain required.
Verification: compile any Win32 console app with cl.exe from VS2008, link against msvcrt.lib, and observe comparable PE structure (checksum, section layout, import table). The actual malicious behavior (SMTP engine, thread storm) is pure C code with no novel techniques.
Deployable Signatures
YARA Rule
rule Phorpiex_Sextortion_SpamBot_800usd_t4 {
meta:
description = "Phorpiex sextortion spam bot $800 variant, mutex t4, 5,000 threads"
author = "triage-pipeline"
date = "2026-09-02"
sha256 = "dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a"
reference = "https://www.malwarebazaar.com/sample/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a"
strings:
$mutex_t4 = "t4" ascii wide
$decrypt_key = "Tmlr" ascii
$btc_wallet = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
$ua = "Chrome/202.0.4664.110" ascii
$ip_check = "http://icanhazip.com/" ascii
$yahoo_mx = "yahoo.com" ascii
$template_1 = "I RECORDED YOU (through your camera) MASTURBATING!" ascii
$template_2 = "All you need is $800 USD in Bitcoin (BTC)" ascii
$ehlo = "EHLO %s\r\n" ascii
$mail_from = "MAIL FROM: %s\r\n" ascii
$rcpt_to = "RCPT TO: <%s>\r\n" ascii
condition:
uint16(0) == 0x5A4D and
filesize < 25KB and
pe.linker_version.major == 9 and
pe.linker_version.minor == 0 and
(pe.imports("MSVCR90.dll") or pe.imports("MSVCR90.dll")) and
pe.imports("WININET.dll") and
pe.imports("WS2_32.dll") and
pe.imports("DNSAPI.dll") and
$btc_wallet and
($mutex_t4 or $decrypt_key) and
($template_1 or $template_2)
}
Behavioral Hunt Query (Sigma)
title: Phorpiex Sextortion Spam Bot Mutex Creation
logsource:
category: process_creation
product: windows
detection:
selection:
- CommandLine|contains: 't4'
- CommandLine|contains: 't5'
- CommandLine|contains: 'etyueu'
- CommandLine|contains: 'efaefaef'
- CommandLine|contains: 'ww88ww8w8'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Indicator | Type | Value | Provenance |
|---|---|---|---|
| SHA-256 | Hash | dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a |
triage.json |
| Mutex | Mutex | t4 |
r2:main@0x40274c |
| BTC Wallet | Cryptocurrency | 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K |
strings.txt:59 |
| Ransom Amount | Financial | $800 USD | strings.txt:46 |
| IP Check URL | URL | http://icanhazip.com/ |
strings.txt:18 |
| MX Domain | Domain | yahoo.com |
strings.txt:16 |
| User-Agent | Network | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 |
strings.txt:17 |
| Temp File Pattern | File | %TEMP%\[n].txt |
r2:fcn.004024e0 |
| Temp File Pattern | File | %TEMP%\[ddd].jpg |
strings.txt:181 |
| Thread Count | Behavioral | 5,000 concurrent SMTP threads | r2:fcn.004024e0 |
| Decrypt Key | Crypto | Tmlr (XOR+NOT) |
r2:fcn.00401030 |
| Compiler | Toolchain | MSVC 9.0 (Visual Studio 2008) | pefile.txt:45 |
| PE Checksum | PE | 0x13B00 |
pefile.txt:65 |
| Compile Time | Timestamp | 2026-05-29 12:33:18 UTC | pefile.txt:34 |
Behavioral Fingerprint
On launch, this binary sleeps 2 seconds, creates a mutex named t4, deletes its own Zone.Identifier ADS, initializes Winsock, fetches the victim's public IP via icanhazip.com over HTTP with a fake Chrome/202 User-Agent, resolves yahoo.com MX records via DNS API, decrypts a hardcoded sextortion email template with XOR+NOT key Tmlr, and spawns 5,000 concurrent threads that each send the email via direct SMTP to randomly selected recipients. The main thread then sleeps for 60 hours before looping. No C2 server, no persistence mechanism, no file encryption. Pure spam delivery.
Detection Signatures
- Mandiant capa: Failed — missing signature database. No capability mapping available. ^[capa.txt]
- YARA:
PE_File_Generic(trivial),Suspicious_Wininet_Imports(generic). ^[yara.txt] - SSDeep:
192:/RIISCngTBvblVPT0Y76fIkq2NleQY9T4KUSvu9zw+ggSmOiMbO5Ot1EdkF39TGW:DIblVP4Y/2N0bLu9JgPL7Nyav8U9c4^[ssdeep.txt] - TLSH:
85824B0FF9418216D1E210B452B5867BD9799C72338458DBFBD08A9D0BA86D6FC3315F^[tlsh.txt]
References
- MalwareBazaar: https://www.malwarebazaar.com/sample/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a
- Phorpiex entity page: phorpiex
- Sibling analysis (mutex
t5): /intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html - Chrome impossible-version UA masquerade: techniques/chrome-128-ua-masquerade.md
- Sextortion spam bot technique: phorpiex-loader-initterm-hijack.md (though this sample uses honest main)
Provenance
Analysis derived from:
file.txt—filev5.44pefile.txt—pefilePython library, full PE header dumpstrings.txt—stringsv2.37, 183 strings recoveredrabin2-info.txt— radare2 v5.9.2rabin2 -Icapa.txt— Mandiant capa v7.0.0 (failed — missing signatures)yara.txt— custom rulesPE_File_Generic,Suspicious_Wininet_Importsssdeep.txt— ssdeep v2.14.1tlsh.txt— TLSH v4.8.2binwalk.txt— binwalk v2.3.4 (no embedded artifacts)floss.txt— flare-floss v2.3.0 (failed — argument parsing error)dynamic-analysis.md— CAPE skipped (no Windows guest)- radare2 decompilation —
pdgvia r2ghidra-dec, functions: entry0, main, fcn.00401030, fcn.00401790, fcn.00401900, fcn.00402340, fcn.004024e0, fcn.00401a10 - Binary:
<sample dc2936ea921e.bin>(18,944 bytes)