C&CMembers
C&C

One Ukrainian IP, Four One-Letter Payloads, Zero Sandbox Alarms

A single Ukrainian IP address serves four minimally named executables carrying a Phorpiex-and-GandCrab payload that 63 of 75 antivirus engines flag as malicious — yet every sandbox it meets returns a clean verdict. The distribution node has operated largely unblocked at the network layer since at least February 2026.

Jun 25, 2026, 17:35 (UTC+9)Last seenJun 26, 2026Severity100ByCTX TeamIOC11MITRE38RegionsCN

A 182-kilobyte Windows executable that 63 of 75 static antivirus engines flag as malicious walks through dynamic analysis without triggering a single sandbox alarm. That contradiction — near-universal static detection paired with a 99-confidence CLEAN verdict from Zenbox — sits at the centre of an active Phorpiex-and-GandCrab distribution operation whose entire observable infrastructure collapses to a single Ukrainian IP address, 92.63.197.106, operating under ASN 211736 (FOP Dmytro Nedilskyi).

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence