s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-jar.pronsis_loader

📛 Threat Title

Malware family: Pronsis Loader

Category: Pronsis Loader First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `jar.pronsis_loader`. Printable name: Pronsis Loader.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    A new malware called Pronsis Loader has been discovered, with similarities to D3F@ck Loader . Both use JPHP-compiled executables, but Pronsis uses NSIS for installation instead of Inno Setup.

  • web:hivepro.com

    Analyze Traffic to Malicious IPs: Use network monitoring to detect traffic to malicious domains and IPs linked to known malware servers. Look for connections attempting to contact command-and-control (C2) servers associated with malware like Pronsis Loader , SUNSPINNER, and PURESTEALER.

  • web:malpedia.caad.fkie.fraunhofer.de

    Pronsis Loader Propose Change According to TrustWave, this is a loader leveraging JPHP, which was observed fetching Latrodectus and Lumma.

  • web:thecyberwire.com

    Shawn Kanady, Global Director of Trustwave SpiderLabs, to discuss their work on " Pronsis Loader : A JPHP-Driven Malware Diverging from D3F@ck Loader ." Trustwave SpiderLabs has uncovered Pronsis Loader , a new malware variant using the rare programming language JPHP and stealthy installation tactics to evade detection. The malware is capable of delivering high-risk payloads like Lumma Stealer and ...

  • web:www.anvilogic.com

    When installed, these programs result in the download of various commodity malware families," according to Google Threat Intelligence Group. On Windows systems, UNC5812 employs a malware chain beginning with Pronsis Loader , which facilitates downloading a decoy mapping application, SUNSPINNER, and the final payload, PURESTEALER.

  • web:www.broadcom.com

    Pronsis Loader is a new malware variant leveraged recently in campaigns delivering Lumma Stealer and Latrodectus payloads. The malware utilizes executables compiled in JPHP programming language, which is a Java implementation of PHP. Pronsis also uses Nullsoft Scriptable Install System (NSIS) for the deployments in the observed campaigns.

  • web:www.cubix.co

    A JPHP-powered malware , Pronsis Loader , has emerged as a massive threat to businesses protecting their applications and platforms using traditional detection methods. Cybercriminals constantly introduce new methods and technologies to breach defenses and compromise systems. The discovery of a new custom malware loader , dubbed Pronsis Loader , highlights how attackers utilize advanced techniques ...

  • web:www.levelblue.com

    Trustwave's Threat Intelligence team has discovered a new malware dubbed Pronsis Loader , with its earliest known variant dating back to November 2023.

  • web:www.techradar.com

    JPHP - a rare choice in cybercrime Pronsis Loader can evade signature-based detection systems, which are typically designed to recognize more common programming languages in malware .

  • web:www.vcindi.com

    Meanwhile, Pronsis Loader's adaptability signals an increasing complexity in malware deployment tactics. As cybersecurity threats evolve, awareness of these tools and their potential impact is essential for organizations and individuals alike to protect against the growing cyber threat landscape.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.