PULSE NAME
Phobos Ransomware: Analysing associated infrastructure used by 8Base
WHITE 8Base AlienVault 2024-03-06 Modified: 2024-04-15
45
IOCs
MEDIUM VOLUME
This report provides an analysis of infrastructure associated with the 8Base ransomware group, which utilizes the Phobos ransomware. The group has been highly active since mid-2023, targeting a broad range of sectors and encrypting files with a .8base extension. The report details 45 domains, 22 IP addresses, and 50 malicious file samples linked to 8Base operations. Most of this infrastructure remains undetected, with low VirusTotal detection rates. There was a spike in submissions to VirusTotal in February 2024, likely following a CISA advisory warning about 8Base. The report concludes that this infrastructure remains active and should be monitored for changes that could enable proactive threat detection.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Smokeloader SystemBC
Indicators of Compromise (45)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain admhexlogs215.xyz 2024-03-06
domain admlogs25.xyz 2024-03-06
domain admlogs85.xyz 2024-03-06
domain admxlogs215.xyz 2024-03-06
domain admxlogs25.xyz 2024-03-06
domain adstat277xm.xyz 2024-03-06
domain advserv.xyz 2024-03-06
domain amx15.xyz 2024-03-06
domain amx395.xyz 2024-03-06
domain amx55.xyz 2024-03-06
domain amx75.xyz 2024-03-06
domain blogserv.xyz 2024-03-06
domain blogxstat38.xyz 2024-03-06
domain cexsad917.xyz 2024-03-06
domain demblog289.xyz 2024-03-06
domain demstat377xm.xyz 2024-03-06
domain demstat577d.xyz 2024-03-06
domain dexblog45.xyz 2024-03-06
domain fexstat227.xyz 2024-03-06
domain fexstat257.xyz 2024-03-06
domain gentexlog238.xyz 2024-03-06
domain kmsox815.xyz 2024-03-06
domain kmstat355mx.xyz 2024-03-06
domain mentran450.xyz 2024-03-06
domain mexstat.pro 2024-03-06
domain mkhexlogs215.xyz 2024-03-06
domain mksad917.xyz 2024-03-06
domain mkstat227.xyz 2024-03-06
domain mktexlog238.xyz 2024-03-06
domain mktrex219.xyz 2024-03-06
domain moknex158.xyz 2024-03-06
domain moplex355.xyz 2024-03-06
domain mxtmx.xyz 2024-03-06
domain mxzex322.xyz 2024-03-06
domain piserver22.net 2024-03-06
domain privat1505.xyz 2024-03-06
domain samnex158.xyz 2024-03-06
domain sentrex219.xyz 2024-03-06
domain servblog757.xyz 2024-03-06
domain servermlogs27.xyz 2024-03-06
domain serverxlogs21.xyz 2024-03-06
domain servxblog79.xyz 2024-03-06
domain xemtex534.xyz 2024-03-06
domain zopte234.xyz 2024-03-06
domain zxvad95.xyz 2024-03-06