win.phorpiex (Back to overview)

Phorpiex

aka: Trik
URLhaus      

Proofpoint describes Phorpiex/Trik as a SDBot fork (thus IRC-based) that has been used to distribute GandCrab, Pushdo, Pony, and coinminers. The name Trik is derived from PDB strings.

References
https://www.johannesbader.ch/2016/02/phorpiex/
https://blog.trendmicro.com/trendlabs-security-intelligence/shylock-not-the-lone-threat-targeting-skype/
https://www.bleepingcomputer.com/news/security/trik-spam-botnet-leaks-43-million-email-addresses/
https://www.crowdstrike.com/blog/pinchy-spider-adopts-big-game-hunting/
https://www.proofpoint.com/us/threat-insight/post/phorpiex-decade-spamming-shadows

There is no Yara-Signature yet.