Downloader Malware Written in JPHP Interpreter
ID: dd38f5c2-e49a-5709-9210-22d8ef341a65
STIX ID: report--dd38f5c2-e49a-5709-9210-22d8ef341a65
Feed Name: ASEC
**Executive summary:** ASEC discovered and analyzed a JPHP-based downloader distributed in a ZIP with an embedded JRE that executes PHP-compiled bytecode (.phb). The malware disables Windows Defender monitoring, contacts an initial C2, and uses Telegram short URLs to fetch a dynamic additional C2; it is observed to download secondary data-stealing malware (e.g., Strrat, Danabot). The report includes MD5 hashes and IP addresses as IOCs and highlights the use of obscure tooling (JPHP) to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
