Mallox Ransomware Affiliate Uses PureCrypter in MS-SQL Attacks
ID: dc4845c1-c0d5-5f2a-bb8b-c96e62404bd7
STIX ID: report--dc4845c1-c0d5-5f2a-bb8b-c96e62404bd7
Feed Name: Sekoia.com
**Executive summary:** This report documents the compromise of a Microsoft SQL honeypot through brute-force and MS-SQL exploitation leading to attempted deployment of Mallox ransomware via the PureCrypter loader, provides detailed analysis of exploitation patterns (CLR assemblies, xp_cmdshell, Ole Automation), PureCrypter and Mallox internals, affiliate identifiers and infrastructure (notably AS208091/XHost), and includes IoCs and practical detection recommendations for MS-SQL and endpoint telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
