216.73.217.22

Phorpiex - Downloader Delivering Ransomware

· Published 29/01/2025 12:58 · Modified 29/01/2025 13:32

Export JSON

Essential information

Published
29/01/2025 12:58
Modified
29/01/2025 13:32
Tags
2025-01-29 botnet downloader gandcrab lockbit phishing phorpiex ransomware twizt
Related entities
13 observables, 1 intrusion sets (apt), 2 malware, 14 others

Description

The report analyzes the 's role in delivering Black . It highlights the automated execution of through , minimal changes to the 's code since its source code sale in 2021, and direct deployment of without network expansion. The analysis covers the infection flow, emails, and technical details of different variants. Key features include URL cache deletion, library obfuscation, indicator removal, and persistence mechanisms. The report also provides a comparative analysis of , , and variants, along with IOCs and MITRE ATT&CK mapping.

External references