#phorpiex — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #phorpiex, aggregated by home.social.
-
Almost Half of Malware Samples Communicate Direct to IP
Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.
Pulse ID: 6a71e43a0127c62218b7c365
Pulse Link: https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365
Pulse Author: AlienVault
Created: 2026-08-04 13:08:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault
-
Almost Half of Malware Samples Communicate Direct to IP
Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.
Pulse ID: 6a71e43a0127c62218b7c365
Pulse Link: https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365
Pulse Author: AlienVault
Created: 2026-08-04 13:08:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault
-
Almost Half of Malware Samples Communicate Direct to IP
Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.
Pulse ID: 6a71e43a0127c62218b7c365
Pulse Link: https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365
Pulse Author: AlienVault
Created: 2026-08-04 13:08:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault
-
Almost Half of Malware Samples Communicate Direct to IP
Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.
Pulse ID: 6a71e43a0127c62218b7c365
Pulse Link: https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365
Pulse Author: AlienVault
Created: 2026-08-04 13:08:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault
-
Almost Half of Malware Samples Communicate Direct to IP
Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.
Pulse ID: 6a71e43a0127c62218b7c365
Pulse Link: https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365
Pulse Author: AlienVault
Created: 2026-08-04 13:08:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault
-
If you've been monitoring that #phorpiex "Your Document" with document\.zip from Jenny @ gsd . com, it's now dropping #lockbit hosted at:
http:// 193.233 .132 .177/lbb.exe
https://app.any.run/tasks/206f3ae9-cdd7-4ee4-a1b5-f9cccf3541fc
-
If you've been monitoring that #phorpiex "Your Document" with document\.zip from Jenny @ gsd . com, it's now dropping #lockbit hosted at:
http:// 193.233 .132 .177/lbb.exe
https://app.any.run/tasks/206f3ae9-cdd7-4ee4-a1b5-f9cccf3541fc
-
If you've been monitoring that #phorpiex "Your Document" with document\.zip from Jenny @ gsd . com, it's now dropping #lockbit hosted at:
http:// 193.233 .132 .177/lbb.exe
https://app.any.run/tasks/206f3ae9-cdd7-4ee4-a1b5-f9cccf3541fc
-
A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:
https://gist.github.com/silence-is-best/e0fa9b5c4d5028a2e853d98b702cacdf
-
A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:
https://gist.github.com/silence-is-best/e0fa9b5c4d5028a2e853d98b702cacdf
-
A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:
https://gist.github.com/silence-is-best/e0fa9b5c4d5028a2e853d98b702cacdf
-
A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:
https://gist.github.com/silence-is-best/e0fa9b5c4d5028a2e853d98b702cacdf
-
Campagne #Malware #Italy Week 13
👻💣🔥☠️
#AgentTesla: Pagamenti
#Remcos: Delivery
#Irata: APK Bank
#Phorpiex: Documenti
#Guloader: Ordine
#PlanetStealer: Conferma
#Lokibot: Preventivo
#Pikabot: Resend -
Un (héroe) anónimo está eliminando el #malware #Phorpiex de PCs infectados y aconseja a sus usuarios usar un #antivirus https://www.xataka.com/seguridad/heroe-anonimo-esta-eliminando-malware-phorpiex-pcs-infectados-aconseja-a-sus-usuarios-usar-antivirus vía @[email protected] #ciberseguridad