logo

Downloader Malware Written in JPHP Interpreter

ID: dd38f5c2-e49a-5709-9210-22d8ef341a65

STIX ID: report--dd38f5c2-e49a-5709-9210-22d8ef341a65

Feed Name: ASEC

Threat Score
68/100

Date Published: 2025-03-13

Date Updated: 2026-04-26

Author: ATCP

...
...

**Executive summary:** ASEC discovered and analyzed a JPHP-based downloader distributed in a ZIP with an embedded JRE that executes PHP-compiled bytecode (.phb). The malware disables Windows Defender monitoring, contacts an initial C2, and uses Telegram short URLs to fetch a dynamic additional C2; it is observed to download secondary data-stealing malware (e.g., Strrat, Danabot). The report includes MD5 hashes and IP addresses as IOCs and highlights the use of obscure tooling (JPHP) to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.