
Old Phorpiex Botnet Still Evades via Bare-IP Hosting, P2P C2
A 2021-vintage Phorpiex/Kadrbot sample was found served from six sequential URL paths on a bare IP with no domain layer, then falling back to UDP peer-to-peer C2 rather than a fixed server. The case, tagged to India's government sector, shows a five-year-old commodity botnet still exploiting a defensive gap most stacks never closed.
Six sequentially-numbered URLs — /twizt/1 through /twizt/6 — sit directly on a bare IP address, 185.215.113.84, with nothing resembling a domain name anywhere in front of them. That is unusual only in how rarely operators still do it: a Windows executable flagged by 60 of 76 engines as trojan.phorpiex/kadrbot was pulled straight from that dotted-quad host, tripping two purpose-built intrusion-detection signatures — "ET INFO Executable Download from dotted-quad Host" and "ET HUNTING SUSPICIOUS…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read