home.social

#phorpiex — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #phorpiex, aggregated by home.social.

fetched live
  1. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  2. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  3. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  4. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  5. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  6. If you've been monitoring that #phorpiex "Your Document" with document\.zip from Jenny @ gsd . com, it's now dropping #lockbit hosted at:

    http:// 193.233 .132 .177/lbb.exe

    app.any.run/tasks/206f3ae9-cdd

  7. If you've been monitoring that #phorpiex "Your Document" with document\.zip from Jenny @ gsd . com, it's now dropping #lockbit hosted at:

    http:// 193.233 .132 .177/lbb.exe

    app.any.run/tasks/206f3ae9-cdd

  8. If you've been monitoring that #phorpiex "Your Document" with document\.zip from Jenny @ gsd . com, it's now dropping #lockbit hosted at:

    http:// 193.233 .132 .177/lbb.exe

    app.any.run/tasks/206f3ae9-cdd

  9. A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:

    gist.github.com/silence-is-bes

    #retrohunt

  10. A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:

    gist.github.com/silence-is-bes

    #retrohunt

  11. A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:

    gist.github.com/silence-is-bes

    #retrohunt

  12. A (late again :( ) csv formatted list of #malspam campaigns that crossed my path in March to include subjects, malware, hashes, c2's, and email exfil addresses. Side note; #phorpiex campaign at 35K+ is the largest I've seen and ongoing:

    gist.github.com/silence-is-bes

    #retrohunt

  13. Campagne #Malware #Italy Week 13

    👻💣🔥☠️
    #AgentTesla: Pagamenti
    #Remcos: Delivery
    #Irata: APK Bank
    #Phorpiex: Documenti
    #Guloader: Ordine
    #PlanetStealer: Conferma
    #Lokibot: Preventivo
    #Pikabot: Resend

    #mwitaly