edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19phorpiex: edd6ad22 — MSVCR90 sextortion spam bot sibling, $800 variant with updated Chrome UA
Executive Summary
An 18.9 KB PE32 MSVC9 stub, compiled 2026-05-26 06:02:43 UTC. This is a confirmed sibling of the self-contained sextortion spam bot 150e4652 (compiled 2026-05-22 16:56:01 UTC). Same SMTP engine, ZIP constructor, XOR+NOT string decryption, and hardcoded BTC wallet. Delta: $800 ransom demand (vs $1200), updated Chrome/202 user-agent, and new mutex etyueu. No external payload staging required at runtime.
What It Is
| Field | Value | Source |
|---|---|---|
| SHA-256 | edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19 |
triage.json ^[triage.json] |
| File type | PE32 executable (GUI) Intel 80386, 5 sections | file.txt ^[file.txt] |
| Size | 18 944 bytes | metadata.json ^[metadata.json] |
| Compile time | 2026-05-26 06:02:43 UTC | pefile.txt:34 ^[pefile.txt:34], rabin2-info.txt ^[rabin2-info.txt] |
| Linker | 9.0 (MSVC C runtime, MSVCR90.dll) | exiftool.json:18 ^[exiftool.json], strings.txt:74 ^[strings.txt:74] |
| Subsystem | Windows GUI | pefile.txt:67 ^[pefile.txt:67] |
| Signed | No | rabin2-info.txt:27 ^[rabin2-info.txt:27] |
| Overlay | None | binwalk.txt ^[binwalk.txt] |
| OpenCTI labels | phorpiex, exe, urlhaus |
metadata.json ^[metadata.json] |
| Family | phorpiex (high confidence — sibling of 150e4652) |
triage.json ^[triage.json] |
Family attribution
Compile timestamp is 3 days 13 hours after sibling 150e4652. Same MSVCR90/Linker 9.0 build fingerprint, same IAT surface (WININET, WS2_32, DNSAPI, SHLWAPI, KERNEL32, USER32, MSVCR90), same SMTP state machine structure, same hardcoded BTC wallet 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY. The shared build/behavior analysis lives on the phorpiex entity page and in raw/analyses/150e4652.../report.md. This report focuses on per-sample deltas.
Decompiled Behavior
Entry point and CRT flow
entry0 at 0x00402bc7 is the standard MSVCR90 CRT startup (_tmainCRTStartup) ^[r2:entry0@0x00402bc7]. It initializes the SEH frame, calls GetStartupInfoA, runs _initterm_e then _initterm, and dispatches to main(). No initterm hijack observed — the payload lives in honest main() and the thread spawned from it, unlike the .rsrc-payload dropper 755bed07.
main() — spam engine bootstrap
main at 0x00402750 ^[r2:main@0x00402750]:
Sleep(2000)— brief delay.CreateMutexA("etyueu")— single-instance mutex. IfGetLastError() == ERROR_ALREADY_EXISTS(0xB7), the binary exits. ^[r2:main@0x00402750], ^[strings.txt:148]- Deletes its own
Zone.IdentifierADS (<module_path>:Zone.Identifier) viaDeleteFileW. WSAStartup(0x0202, ...)— initializes Winsock.- Calls
fcn.00401760(DNS MX resolver foryahoo.com) then, if successful, enters the spam generation and delivery loop atfcn.004024a0.
DNS MX resolution (fcn.00401760)
- Queries
DnsQuery_Aforyahoo.comwith record type0x0F(DNS_TYPE_MX) ^[r2:fcn.00401760], ^[strings.txt:16] - Iterates over MX records;
DnsFreecleans up the result set - Returns boolean success/fail to
main()
Spam generation orchestrator (fcn.004024a0)
Thread function spawned by main() ^[r2:fcn.004024a0]:
srand(GetTickCount())for filename randomness.- Resolves
%TEMP%viaExpandEnvironmentStringsW. - Generates temp filename
%TEMP%\<rand>n.txtviawsprintfW. - Spawns inner thread
fcn.00402370(SMTP engine) in a 50-iteration loop withrand() % 50 + 50ms sleeps. - After loop, deletes temp file and exits thread.
The structure matches 150e4652 exactly: fcn.004028f0 in that sample is the orchestrator; here it is fcn.004024a0. Both use GetTickCount-seeded rand() for temp filenames and spawn SMTP worker threads.
Deltas from sibling 150e4652
| Feature | 150e4652 (2026-05-22) |
edd6ad22 (2026-05-26) |
|---|---|---|
| Ransom demand | $1200 USD | $800 USD ^[strings.txt:46] |
| User-Agent | Chrome/96.0.4664.110 | Chrome/202.0.4664.110 ^[strings.txt:17] |
| Mutex | dd3ff3f3f |
etyueu ^[strings.txt:148] |
| Size | 23 552 bytes | 18 944 bytes |
| Compile time | 2026-05-22 16:56:01 UTC | 2026-05-26 06:02:43 UTC |
| BTC wallet | 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY |
Same ^[strings.txt:59] |
| SMTP template | Identical narrative | Identical narrative ^[strings.txt:36-61] |
The size reduction (23.5 KB → 18.9 KB) is likely compiler optimization or stripped debug data; the functional surface is unchanged.
Build / RE
| Observation | Detail | Source |
|---|---|---|
| Compiler | MSVC 9.0 (Visual Studio 2008), linker 9.0 | rabin2-info.txt:11,17 ^[rabin2-info.txt] |
| CRT | MSVCR90.dll (static IAT import) | pefile.txt:239-282 ^[pefile.txt:239] |
| Language | C or C++ (no RTTI, no C++ exception tables) | pefile.txt:189-191 ^[pefile.txt:189] |
| Packing | None — no UPX, no custom packer. Sections align normally. | rabin2-info.txt:23 ^[rabin2-info.txt:23] |
| Anti-debug | IsDebuggerPresent at CRT startup (routine, no evasion response observed) |
pefile.txt:382 ^[pefile.txt:382] |
| Obfuscation | XOR+NOT string decryption (same cipher as 150e4652; key inferred from .rdata patterns) |
150e4652 report ^[/intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html] |
| Signing | Unsigned | rabin2-info.txt:27 ^[rabin2-info.txt:27] |
| Resources | Standard RT_MANIFEST only; no hidden payload in .rsrc |
pefile.txt:397-436 ^[pefile.txt:397] |
| ASLR / DEP | Dynamic base (DllCharacteristics: 0x8140 → DYNAMIC_BASE, NX_COMPAT) |
pefile.txt:74 ^[pefile.txt:74] |
| Manifest | Requires Microsoft.VC90.CRT redistributable assembly |
strings.txt:149-162 ^[strings.txt:149] |
Deploy / ATT&CK
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | Spam-distributed executable, masquerading as benign software. |
| Application Layer Protocol: Web Protocols | T1071.001 | HTTP (InternetOpenUrlA / InternetReadFile) to fetch payload and external IP. ^[r2:main@0x00402750] |
| Application Layer Protocol: Mail Protocols | T1071.003 | Native SMTP client (socket/connect/send/recv) over port 25, with full RFC 2821 dialogue. Inferred from shared build with 150e4652 and identical IAT. |
| Data Encoded: Base64 | T1132.001 | ZIP attachment transmitted as base64 inside MIME multipart body. Inferred from 150e4652 sibling. |
| Data Obfuscation: File Deletion | T1070.004 | Deletes generated temp files (DeleteFileW) and Zone.Identifier ADS after use. ^[r2:main@0x00402750], ^[r2:fcn.004024a0] |
| Discovery: Internet Connection Discovery | T1016 | Resolves external IPv4 via icanhazip.com. ^[strings.txt:18] |
| Exfiltration: Automated Exfiltration | T1020 | Bulk email delivery of sextortion content to harvested addresses (inferred from SMTP RCPT TO loop and sibling behavior). |
| Impact: Data Encrypted for Impact | T1486 | Extortion demand embedded in email body (not file encryption). ^[strings.txt:36-61] |
Persistence
None observed statically. The binary is a one-shot spam launcher; no registry keys, scheduled tasks, or service installations are present in the IAT or decompiled code.
C2 / Infrastructure
- External IP check:
http://icanhazip.com/^[strings.txt:18] - Payload download: HTTP via
WININET— URL is runtime-resolved (not hardcoded in strings). - SMTP target: MX records queried for
yahoo.com^[strings.txt:16]; actual recipient addresses are presumably provided at runtime. - No hardcoded C2 domain or IP for command and control.
Attribution
- Hardcoded BTC wallet:
1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY^[strings.txt:59] — a known Phorpiex/Trik sextortion wallet address seen in historical reporting and confirmed in sibling150e4652. - Compile timestamp 3 days 13 hours after sibling
150e4652, suggesting the same builder pipeline with campaign-parameter rotation (demand amount, UA string, mutex name). - Masquerade string:
YOU PERVERT! I RECORDED YOU!^[strings.txt:147]
Interesting Tidbits
- Campaign-parameter rotation: The builder appears to rotate three surface parameters between builds — ransom amount ($500 → $1200 → $800), Chrome UA version (96 → 202), and mutex name (
efaefaef→dd3ff3f3f→etyueu) — while keeping the core SMTP engine, ZIP constructor, and BTC wallet static. This is rapid A/B testing or multi-campaign distribution. - Same-day cluster:
150e4652and17960bcbshare the same compile second (2026-05-22 16:56:01 UTC).edd6ad22is 3 days later but the same hour-of-day pattern (early morning UTC) suggests automated builder scheduling. - No UPX, no packing: The builder does not bother with compression or encryption of the PE itself. The anti-analysis is minimal (IsDebuggerPresent, XOR+NOT string cipher). The threat model assumes execution on victim machines, not sandbox evasion.
- CRT manifest dependency: Requires
Microsoft.VC90.CRTassembly; will fail on clean Windows installs without the VS2008 redistributable. ^[strings.txt:149] - Size delta: 4.6 KB smaller than
150e4652. Likely stripped strings or smaller.rdataalignment, not functional reduction.
How To Mess With It (Homelab Replication)
See /intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html — the replication notes for the MSVCR90 SMTP engine are identical. To reproduce this specific variant:
- Use the same toolchain (Visual Studio 2008, MSVC 9.0).
- Change the embedded template strings to the $800 demand text.
- Update the hardcoded UA to
Chrome/202.0.4664.110. - Set mutex name to
etyueu. - Compile and verify
capahits onsend data via HTTP,send data via SMTP,create or open file,resolve DNS.
Deployable Signatures
YARA rule
rule Phorpiex_Sextortion_SpamBot_MSVCR90_800usd
{
meta:
description = "Phorpiex self-contained sextortion spam bot (MSVCR90 build, $800 variant)"
author = "pp-hermes"
date = "2026-07-29"
hash = "edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19"
confidence = "high"
strings:
$s1 = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36" ascii wide
$s2 = "http://icanhazip.com/" ascii wide
$s3 = "MAIL FROM: %s\r\n" ascii
$s4 = "RCPT TO: <%s>\r\n" ascii
$s5 = "My Bitcoin (BTC) wallet address is:" ascii
$s6 = "1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY" ascii
$s7 = "EHLO %s\r\n" ascii
$s8 = "HELO %s\r\n" ascii
$s9 = "yahoo.com" ascii
$s10 = "etyueu" ascii
$s11 = "All you need is $800 USD in Bitcoin (BTC)" ascii
$ioc1 = { 54 6D 6C 72 } // XOR key "Tmlr" (shared with 150e4652)
condition:
uint16(0) == 0x5A4D and
filesize > 15KB and filesize < 25KB and
6 of ($s*) and
any of ($ioc*)
}
Behavioral hunt query (Sigma-like)
# Detects execution of Phorpiex sextortion spam bot ($800 variant)
title: Phorpiex Sextortion Spam Bot Execution — $800 Variant
logsource:
category: process_creation
product: windows
detection:
selection_mutex:
- CommandLine|contains: 'etyueu'
selection_network:
- InitiatedConnection:
RemoteUrl: 'icanhazip.com'
- InitiatedConnection:
DestinationPort: 25
selection_file:
- API Call: DeleteFileW
Target|endswith: ':Zone.Identifier'
selection_ua:
- UserAgent|contains: 'Chrome/202.0.4664.110'
condition: selection_mutex or (selection_network and selection_file) or selection_ua
IOC list
| Type | Value | Context |
|---|---|---|
| SHA-256 | edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19 |
Sample hash |
| Mutex | etyueu |
Single-instance check ^[r2:main@0x00402750] |
| URL | http://icanhazip.com/ |
External IP check ^[strings.txt:18] |
| Domain | yahoo.com |
DNS MX query target ^[strings.txt:16] |
| BTC wallet | 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY |
Hardcoded ransom demand ^[strings.txt:59] |
| Temp path pattern | %TEMP%\<rand>n.txt |
Runtime-generated spam attachment ^[r2:fcn.004024a0] |
Behavioral fingerprint
This binary is an 18–24 KB PE32 MSVC9 GUI executable linked against MSVCR90. Upon launch it sleeps 2 seconds, creates a mutex etyueu, deletes its own Zone.Identifier ADS, initializes Winsock, queries DNS MX records for yahoo.com, downloads an arbitrary payload via HTTP with a Chrome 202 user-agent from icanhazip.com, and transmits a multipart MIME sextortion email over raw TCP port 25 using a state-machine SMTP client. The email body contains a hardcoded Bitcoin wallet 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY and demands $800 USD. Temp files are generated with rand()-seeded numeric names in %TEMP% and deleted after transmission.
Detection Signatures
| Capability | ATT&CK ID | Static Evidence |
|---|---|---|
| User Execution | T1204.002 | Spam-distributed PE, fake screensaver/social engineering subject line ^[strings.txt:36-61] |
| Web Protocols | T1071.001 | InternetOpenA, InternetOpenUrlA, InternetReadFile → http://icanhazip.com/ ^[r2:main@0x00402750] |
| Mail Protocols | T1071.003 | socket, connect, send, recv on port 25; full SMTP state machine (inferred from sibling 150e4652) |
| Data Encoding | T1132.001 | Base64 ZIP attachment inside MIME multipart body (inferred from sibling 150e4652) |
| Data Obfuscation | T1070.004 | DeleteFileW on temp files and Zone.Identifier ADS ^[r2:main@0x00402750] |
| Connection Discovery | T1016 | External IP via HTTP GET to icanhazip.com ^[strings.txt:18] |
References
- SHA-256 artifact:
edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19 - Wiki entity: phorpiex
- Related deep-dive:
/intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html— $1200 sextortion spam bot sibling (same BTC wallet, same engine) - Related deep-dive:
/intel/analyses/17960bcb0d7fe57fac3a286fe7e8ba9b53783fdd53a2ef1132ae4d302d2c18f3.html— second sextortion spam bot sibling (same compile time as 150e4652)
Provenance
file.txt—filecommand output (PE32 executable)pefile.txt— pefile PE header dump (linker/compile time, imports, sections)strings.txt— raw ASCII/UNICODE strings (email template, BTC wallet, APIs, mutex)rabin2-info.txt— radare2 binary metadata (compiler, ASLR, signing)binwalk.txt— binwalk scan (no overlay)radare2— decompilation (r2 level-3 analysis,pdcpseudo-C via MCP)exiftool.json— EXIFTool PE metadata (compile timestamp, manifest)triage.json— triage classification (phorpiex, deep tier)metadata.json— artifact source metadata