typeanalysisfamilyphorpiexconfidencehighmalware-familyloadermsvcr90spamsextortionsmtp-clientdropped-by-phorpiex
SHA-256: edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19

phorpiex: edd6ad22 — MSVCR90 sextortion spam bot sibling, $800 variant with updated Chrome UA

Executive Summary

An 18.9 KB PE32 MSVC9 stub, compiled 2026-05-26 06:02:43 UTC. This is a confirmed sibling of the self-contained sextortion spam bot 150e4652 (compiled 2026-05-22 16:56:01 UTC). Same SMTP engine, ZIP constructor, XOR+NOT string decryption, and hardcoded BTC wallet. Delta: $800 ransom demand (vs $1200), updated Chrome/202 user-agent, and new mutex etyueu. No external payload staging required at runtime.

What It Is

Field Value Source
SHA-256 edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19 triage.json ^[triage.json]
File type PE32 executable (GUI) Intel 80386, 5 sections file.txt ^[file.txt]
Size 18 944 bytes metadata.json ^[metadata.json]
Compile time 2026-05-26 06:02:43 UTC pefile.txt:34 ^[pefile.txt:34], rabin2-info.txt ^[rabin2-info.txt]
Linker 9.0 (MSVC C runtime, MSVCR90.dll) exiftool.json:18 ^[exiftool.json], strings.txt:74 ^[strings.txt:74]
Subsystem Windows GUI pefile.txt:67 ^[pefile.txt:67]
Signed No rabin2-info.txt:27 ^[rabin2-info.txt:27]
Overlay None binwalk.txt ^[binwalk.txt]
OpenCTI labels phorpiex, exe, urlhaus metadata.json ^[metadata.json]
Family phorpiex (high confidence — sibling of 150e4652) triage.json ^[triage.json]

Family attribution

Compile timestamp is 3 days 13 hours after sibling 150e4652. Same MSVCR90/Linker 9.0 build fingerprint, same IAT surface (WININET, WS2_32, DNSAPI, SHLWAPI, KERNEL32, USER32, MSVCR90), same SMTP state machine structure, same hardcoded BTC wallet 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY. The shared build/behavior analysis lives on the phorpiex entity page and in raw/analyses/150e4652.../report.md. This report focuses on per-sample deltas.

Decompiled Behavior

Entry point and CRT flow

entry0 at 0x00402bc7 is the standard MSVCR90 CRT startup (_tmainCRTStartup) ^[r2:entry0@0x00402bc7]. It initializes the SEH frame, calls GetStartupInfoA, runs _initterm_e then _initterm, and dispatches to main(). No initterm hijack observed — the payload lives in honest main() and the thread spawned from it, unlike the .rsrc-payload dropper 755bed07.

main() — spam engine bootstrap

main at 0x00402750 ^[r2:main@0x00402750]:

  1. Sleep(2000) — brief delay.
  2. CreateMutexA("etyueu") — single-instance mutex. If GetLastError() == ERROR_ALREADY_EXISTS (0xB7), the binary exits. ^[r2:main@0x00402750], ^[strings.txt:148]
  3. Deletes its own Zone.Identifier ADS (<module_path>:Zone.Identifier) via DeleteFileW.
  4. WSAStartup(0x0202, ...) — initializes Winsock.
  5. Calls fcn.00401760 (DNS MX resolver for yahoo.com) then, if successful, enters the spam generation and delivery loop at fcn.004024a0.

DNS MX resolution (fcn.00401760)

  • Queries DnsQuery_A for yahoo.com with record type 0x0F (DNS_TYPE_MX) ^[r2:fcn.00401760], ^[strings.txt:16]
  • Iterates over MX records; DnsFree cleans up the result set
  • Returns boolean success/fail to main()

Spam generation orchestrator (fcn.004024a0)

Thread function spawned by main() ^[r2:fcn.004024a0]:

  1. srand(GetTickCount()) for filename randomness.
  2. Resolves %TEMP% via ExpandEnvironmentStringsW.
  3. Generates temp filename %TEMP%\<rand>n.txt via wsprintfW.
  4. Spawns inner thread fcn.00402370 (SMTP engine) in a 50-iteration loop with rand() % 50 + 50 ms sleeps.
  5. After loop, deletes temp file and exits thread.

The structure matches 150e4652 exactly: fcn.004028f0 in that sample is the orchestrator; here it is fcn.004024a0. Both use GetTickCount-seeded rand() for temp filenames and spawn SMTP worker threads.

Deltas from sibling 150e4652

Feature 150e4652 (2026-05-22) edd6ad22 (2026-05-26)
Ransom demand $1200 USD $800 USD ^[strings.txt:46]
User-Agent Chrome/96.0.4664.110 Chrome/202.0.4664.110 ^[strings.txt:17]
Mutex dd3ff3f3f etyueu ^[strings.txt:148]
Size 23 552 bytes 18 944 bytes
Compile time 2026-05-22 16:56:01 UTC 2026-05-26 06:02:43 UTC
BTC wallet 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY Same ^[strings.txt:59]
SMTP template Identical narrative Identical narrative ^[strings.txt:36-61]

The size reduction (23.5 KB → 18.9 KB) is likely compiler optimization or stripped debug data; the functional surface is unchanged.

Build / RE

Observation Detail Source
Compiler MSVC 9.0 (Visual Studio 2008), linker 9.0 rabin2-info.txt:11,17 ^[rabin2-info.txt]
CRT MSVCR90.dll (static IAT import) pefile.txt:239-282 ^[pefile.txt:239]
Language C or C++ (no RTTI, no C++ exception tables) pefile.txt:189-191 ^[pefile.txt:189]
Packing None — no UPX, no custom packer. Sections align normally. rabin2-info.txt:23 ^[rabin2-info.txt:23]
Anti-debug IsDebuggerPresent at CRT startup (routine, no evasion response observed) pefile.txt:382 ^[pefile.txt:382]
Obfuscation XOR+NOT string decryption (same cipher as 150e4652; key inferred from .rdata patterns) 150e4652 report ^[/intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html]
Signing Unsigned rabin2-info.txt:27 ^[rabin2-info.txt:27]
Resources Standard RT_MANIFEST only; no hidden payload in .rsrc pefile.txt:397-436 ^[pefile.txt:397]
ASLR / DEP Dynamic base (DllCharacteristics: 0x8140 → DYNAMIC_BASE, NX_COMPAT) pefile.txt:74 ^[pefile.txt:74]
Manifest Requires Microsoft.VC90.CRT redistributable assembly strings.txt:149-162 ^[strings.txt:149]

Deploy / ATT&CK

Technique ID Evidence
User Execution: Malicious File T1204.002 Spam-distributed executable, masquerading as benign software.
Application Layer Protocol: Web Protocols T1071.001 HTTP (InternetOpenUrlA / InternetReadFile) to fetch payload and external IP. ^[r2:main@0x00402750]
Application Layer Protocol: Mail Protocols T1071.003 Native SMTP client (socket/connect/send/recv) over port 25, with full RFC 2821 dialogue. Inferred from shared build with 150e4652 and identical IAT.
Data Encoded: Base64 T1132.001 ZIP attachment transmitted as base64 inside MIME multipart body. Inferred from 150e4652 sibling.
Data Obfuscation: File Deletion T1070.004 Deletes generated temp files (DeleteFileW) and Zone.Identifier ADS after use. ^[r2:main@0x00402750], ^[r2:fcn.004024a0]
Discovery: Internet Connection Discovery T1016 Resolves external IPv4 via icanhazip.com. ^[strings.txt:18]
Exfiltration: Automated Exfiltration T1020 Bulk email delivery of sextortion content to harvested addresses (inferred from SMTP RCPT TO loop and sibling behavior).
Impact: Data Encrypted for Impact T1486 Extortion demand embedded in email body (not file encryption). ^[strings.txt:36-61]

Persistence

None observed statically. The binary is a one-shot spam launcher; no registry keys, scheduled tasks, or service installations are present in the IAT or decompiled code.

C2 / Infrastructure

  • External IP check: http://icanhazip.com/ ^[strings.txt:18]
  • Payload download: HTTP via WININET — URL is runtime-resolved (not hardcoded in strings).
  • SMTP target: MX records queried for yahoo.com ^[strings.txt:16]; actual recipient addresses are presumably provided at runtime.
  • No hardcoded C2 domain or IP for command and control.

Attribution

  • Hardcoded BTC wallet: 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY ^[strings.txt:59] — a known Phorpiex/Trik sextortion wallet address seen in historical reporting and confirmed in sibling 150e4652.
  • Compile timestamp 3 days 13 hours after sibling 150e4652, suggesting the same builder pipeline with campaign-parameter rotation (demand amount, UA string, mutex name).
  • Masquerade string: YOU PERVERT! I RECORDED YOU! ^[strings.txt:147]

Interesting Tidbits

  1. Campaign-parameter rotation: The builder appears to rotate three surface parameters between builds — ransom amount ($500 → $1200 → $800), Chrome UA version (96 → 202), and mutex name (efaefaef → dd3ff3f3f → etyueu) — while keeping the core SMTP engine, ZIP constructor, and BTC wallet static. This is rapid A/B testing or multi-campaign distribution.
  2. Same-day cluster: 150e4652 and 17960bcb share the same compile second (2026-05-22 16:56:01 UTC). edd6ad22 is 3 days later but the same hour-of-day pattern (early morning UTC) suggests automated builder scheduling.
  3. No UPX, no packing: The builder does not bother with compression or encryption of the PE itself. The anti-analysis is minimal (IsDebuggerPresent, XOR+NOT string cipher). The threat model assumes execution on victim machines, not sandbox evasion.
  4. CRT manifest dependency: Requires Microsoft.VC90.CRT assembly; will fail on clean Windows installs without the VS2008 redistributable. ^[strings.txt:149]
  5. Size delta: 4.6 KB smaller than 150e4652. Likely stripped strings or smaller .rdata alignment, not functional reduction.

How To Mess With It (Homelab Replication)

See /intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html — the replication notes for the MSVCR90 SMTP engine are identical. To reproduce this specific variant:

  1. Use the same toolchain (Visual Studio 2008, MSVC 9.0).
  2. Change the embedded template strings to the $800 demand text.
  3. Update the hardcoded UA to Chrome/202.0.4664.110.
  4. Set mutex name to etyueu.
  5. Compile and verify capa hits on send data via HTTP, send data via SMTP, create or open file, resolve DNS.

Deployable Signatures

YARA rule

rule Phorpiex_Sextortion_SpamBot_MSVCR90_800usd
{
    meta:
        description = "Phorpiex self-contained sextortion spam bot (MSVCR90 build, $800 variant)"
        author      = "pp-hermes"
        date        = "2026-07-29"
        hash        = "edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19"
        confidence  = "high"
    strings:
        $s1 = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36" ascii wide
        $s2 = "http://icanhazip.com/" ascii wide
        $s3 = "MAIL FROM: %s\r\n" ascii
        $s4 = "RCPT TO: <%s>\r\n" ascii
        $s5 = "My Bitcoin (BTC) wallet address is:" ascii
        $s6 = "1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY" ascii
        $s7 = "EHLO %s\r\n" ascii
        $s8 = "HELO %s\r\n" ascii
        $s9 = "yahoo.com" ascii
        $s10 = "etyueu" ascii
        $s11 = "All you need is $800 USD in Bitcoin (BTC)" ascii
        $ioc1 = { 54 6D 6C 72 }           // XOR key "Tmlr" (shared with 150e4652)
    condition:
        uint16(0) == 0x5A4D and
        filesize > 15KB and filesize < 25KB and
        6 of ($s*) and
        any of ($ioc*)
}

Behavioral hunt query (Sigma-like)

# Detects execution of Phorpiex sextortion spam bot ($800 variant)
title: Phorpiex Sextortion Spam Bot Execution — $800 Variant
logsource:
    category: process_creation
    product: windows
detection:
    selection_mutex:
        - CommandLine|contains: 'etyueu'
    selection_network:
        - InitiatedConnection:
            RemoteUrl: 'icanhazip.com'
        - InitiatedConnection:
            DestinationPort: 25
    selection_file:
        - API Call: DeleteFileW
          Target|endswith: ':Zone.Identifier'
    selection_ua:
        - UserAgent|contains: 'Chrome/202.0.4664.110'
    condition: selection_mutex or (selection_network and selection_file) or selection_ua

IOC list

Type Value Context
SHA-256 edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19 Sample hash
Mutex etyueu Single-instance check ^[r2:main@0x00402750]
URL http://icanhazip.com/ External IP check ^[strings.txt:18]
Domain yahoo.com DNS MX query target ^[strings.txt:16]
BTC wallet 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY Hardcoded ransom demand ^[strings.txt:59]
Temp path pattern %TEMP%\<rand>n.txt Runtime-generated spam attachment ^[r2:fcn.004024a0]

Behavioral fingerprint

This binary is an 18–24 KB PE32 MSVC9 GUI executable linked against MSVCR90. Upon launch it sleeps 2 seconds, creates a mutex etyueu, deletes its own Zone.Identifier ADS, initializes Winsock, queries DNS MX records for yahoo.com, downloads an arbitrary payload via HTTP with a Chrome 202 user-agent from icanhazip.com, and transmits a multipart MIME sextortion email over raw TCP port 25 using a state-machine SMTP client. The email body contains a hardcoded Bitcoin wallet 1G1zmqks1vd9V3SdxCY71Hv9C7rHBLQbCY and demands $800 USD. Temp files are generated with rand()-seeded numeric names in %TEMP% and deleted after transmission.

Detection Signatures

Capability ATT&CK ID Static Evidence
User Execution T1204.002 Spam-distributed PE, fake screensaver/social engineering subject line ^[strings.txt:36-61]
Web Protocols T1071.001 InternetOpenA, InternetOpenUrlA, InternetReadFile → http://icanhazip.com/ ^[r2:main@0x00402750]
Mail Protocols T1071.003 socket, connect, send, recv on port 25; full SMTP state machine (inferred from sibling 150e4652)
Data Encoding T1132.001 Base64 ZIP attachment inside MIME multipart body (inferred from sibling 150e4652)
Data Obfuscation T1070.004 DeleteFileW on temp files and Zone.Identifier ADS ^[r2:main@0x00402750]
Connection Discovery T1016 External IP via HTTP GET to icanhazip.com ^[strings.txt:18]

References

  • SHA-256 artifact: edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19
  • Wiki entity: phorpiex
  • Related deep-dive: /intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html — $1200 sextortion spam bot sibling (same BTC wallet, same engine)
  • Related deep-dive: /intel/analyses/17960bcb0d7fe57fac3a286fe7e8ba9b53783fdd53a2ef1132ae4d302d2c18f3.html — second sextortion spam bot sibling (same compile time as 150e4652)

Provenance

  • file.txt — file command output (PE32 executable)
  • pefile.txt — pefile PE header dump (linker/compile time, imports, sections)
  • strings.txt — raw ASCII/UNICODE strings (email template, BTC wallet, APIs, mutex)
  • rabin2-info.txt — radare2 binary metadata (compiler, ASLR, signing)
  • binwalk.txt — binwalk scan (no overlay)
  • radare2 — decompilation (r2 level-3 analysis, pdc pseudo-C via MCP)
  • exiftool.json — EXIFTool PE metadata (compile timestamp, manifest)
  • triage.json — triage classification (phorpiex, deep tier)
  • metadata.json — artifact source metadata