PurpleFox botnet variant uses WebSockets for more secure C2 communication
Security Affairs
OCTOBER 20, 2021
The package also sets two registry values under the key “HKLMSYSTEMCurrentControlSetControlSession Manager” and runs a.vbs script that creates a Windows firewall rule to block incoming connections on ports 135, 139, and 445. . The final backdoor is a DLL file protected by the VMProtect.
Let's personalize your content