logo

Mallox Ransomware Affiliate Uses PureCrypter in MS-SQL Attacks

ID: dc4845c1-c0d5-5f2a-bb8b-c96e62404bd7

STIX ID: report--dc4845c1-c0d5-5f2a-bb8b-c96e62404bd7

Feed Name: Sekoia.com

Threat Score
75/100

Date Published: 2024-05-13

Date Updated: 2026-07-20

...
...

**Executive summary:** This report documents the compromise of a Microsoft SQL honeypot through brute-force and MS-SQL exploitation leading to attempted deployment of Mallox ransomware via the PureCrypter loader, provides detailed analysis of exploitation patterns (CLR assemblies, xp_cmdshell, Ole Automation), PureCrypter and Mallox internals, affiliate identifiers and infrastructure (notably AS208091/XHost), and includes IoCs and practical detection recommendations for MS-SQL and endpoint telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.