C&CMembers
C&C

Old Phorpiex Botnet Still Evades via Bare-IP Hosting, P2P C2

A 2021-vintage Phorpiex/Kadrbot sample was found served from six sequential URL paths on a bare IP with no domain layer, then falling back to UDP peer-to-peer C2 rather than a fixed server. The case, tagged to India's government sector, shows a five-year-old commodity botnet still exploiting a defensive gap most stacks never closed.

Aug 15, 2026, 06:52 (UTC+9)Last seenAug 15, 2026Severity100ByCTX TeamIOC17MITRE31RegionsIN

Six sequentially-numbered URLs — /twizt/1 through /twizt/6 — sit directly on a bare IP address, 185.215.113.84, with nothing resembling a domain name anywhere in front of them. That is unusual only in how rarely operators still do it: a Windows executable flagged by 60 of 76 engines as trojan.phorpiex/kadrbot was pulled straight from that dotted-quad host, tripping two purpose-built intrusion-detection signatures — "ET INFO Executable Download from dotted-quad Host" and "ET HUNTING SUSPICIOUS…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence