Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
131
Global rank
110 infographic chevron month
Month rank
118 infographic chevron week
Week rank
0
IOCs

Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.

Ransomware
Type
Unknown
Origin
1 October, 2017
First seen
28 August, 2026
Last seen

How to analyze Phobos with ANY.RUN

Type
Unknown
Origin
1 October, 2017
First seen
28 August, 2026
Last seen

IOCs

IP addresses
151.101.1.91
172.211.123.249
128.24.231.65
142.251.110.91
95.100.102.9
48.209.6.48
172.67.152.238
151.101.193.91
34.107.243.93
23.216.77.21
20.190.160.17
48.209.133.15
34.149.226.178
151.101.65.91
171.252.207.173
20.165.94.63
142.251.153.119
151.101.129.91
48.209.138.168
23.52.181.212
Hashes
69b61b2c00323cea3686315617d0f452e205dae10c47e02cbe1ea96fea38f582
84b900dbd7fa978d6e0caee26fc54f2f61d92c9c75d10b35f00e3e82cd1d67b4
d782c6495b2acf68d549a0e40f4e0ef1486bb9308339918a3c47f2d10f89e649
36de18aec56bb58a6d38a70eedfdaca641433e37c133443145b4350fc06ef0d3
65231fda10d8d1b3823d71b2a1bac055e501b162ee2a1bc1748fdf030a0fd957
0ad292d58dbd5e36546a592b04acb0b539667c9966fdef298720ed6ef2537bbe
ae95e99a96251abaf8de15c9cdaddb8cefb1b8b320b10a4f1f4e1dc3c25c1b1a
117dbba356d6c0d7b653ed798efa3fc3c340aa2b4c65f5f9525ca1db8ba29205
c1f842d7e1a4cb0e653628152ec61ac7f0695406053eaa594019d3ab3624ba35
b8b7c1dcc49ca052a1a6bb5e1719d7e857fdf404bdb7697b09a38268748a3541
827bd1a8d9abaa3382e5142fedf1250a2e703bf1a3fed14dd76a12caa5e1249d
7ef51f5f4d7dbefa1df684242e16e49b8b8ccba3c1f8deba4c9676dad0e48f97
4bb7d12d28c9ccdffb33b1b2de0af96be9fbb364ac5de3f50d3cf8414fe07ad4
5542150d4ae52118f967599d2a1de8db03e4cb6ae67b1f9713a93e4c4cb4d597
ca8454c4c39d6af3031647a09652cbc1ec347f54070d03ea554e15a1fa4550b8
a4afa1a3119baf774fa3766494dca7563759415f7840b8748c2d98178b84d46c
a0ae42b79e08516f2881bd261c4be775dda499abb5fe09454099935aa062b385
549e5f79cff0bd87be44e945e4a1561aa1ef5864587a2a3620c4d3aef26d0c38
b6db0c8e8167db9e94e48d91f5a4995983046462e7203aac6dcf30fe13fc116d
99e46332bbb16df6423a13ad7d4392f6ac91d86709cf8b17f129ed61ef2c4f8c
Domains
contile.services.mozilla.com
activation-v2.sls.microsoft.com
sb-ssl.l.google.com
www.microsoft.com
firefox.settings.services.mozilla.com
mozilla.map.fastly.net
shein.sjv.io
detectportal.firefox.com
tagesschau.de
tracking.prf.hn
normandy.tombstone.experimenter.prod.webservices.mozgcp.net
safebrowsing.googleapis.com
ads-img.mozilla.org
licensing.mp.microsoft.com
www.google.com
spocs.getpocket.com
dyna.wikimedia.org
www.adidas.dk
slscr.update.microsoft.com
settings-win.data.microsoft.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://firefox.settings.services.mozilla.com/v1/buckets/monitor/collections/changes/changeset?collection=url-parser-default-unknown-schemes-interventions&bucket=main&_expected=0
https://contile.services.mozilla.com/v1/tiles
https://spocs.getpocket.com/spocs
https://firefox.settings.services.mozilla.com/v1/
https://firefox.settings.services.mozilla.com/v1/buckets/main/collections/url-parser-default-unknown-schemes-interventions/changeset?_expected=1743513175300&_since=%221726769128879%22
http://detectportal.firefox.com/canonical.html
http://detectportal.firefox.com/success.txt?ipv4
https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2026-03-08-09-54-23.chain
https://content-signature-2.cdn.mozilla.net/g/chains/202402/remote-settings.content-signature.mozilla.org-2026-09-24-19-49-17.chain
https://ads-img.mozilla.org/v1/images?image_data=cnakbmh0dhbzoi8vyw1wlwfzc2v0ljq1dhuxyzauy29tl2fzc2v0cy8xmdazlza4zmvjmwzkmzvmythmyji3otg4mtbhnmnmyjuynwnimjvlogu2owy1nzdiymm2zdkyzmi3mdy4y2i2mwfly2muanbneiahbvfbpnoupgwcyezrywbxqod2joih7vgfcfrx-tsyvg
https://ads-img.mozilla.org/v1/images?image_data=cnakbmh0dhbzoi8vyw1wlwfzc2v0ljq1dhuxyzauy29tl2fzc2v0cy8xndmzl2uxzwezmmi2n2i0mgm3ogy0yzu5mwfjnjy1nza5zjbimdmwm2y5yje5mtrindmzntkwotg5ytc0nzm4nmjln2quanbneiagvjxk1imrcy0r8zcvv71l4i940juulcokpskbbzjxuq
https://ads-img.mozilla.org/v1/images?image_data=cnakbmh0dhbzoi8vyw1wlwfzc2v0ljq1dhuxyzauy29tl2fzc2v0cy8xntu3lzzkmdlhntk2nja0mgjmmdu3yzc2mje0zmvizgrhywm5mgyyzte4zjmxythjzwy1ymq2mwy0ymq4nty4mtllndeuanbneia_fwnamwox0383jgfpjgilhvm5oeicnelbkg3jcczcya
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

What is Phobos Ransomware?

Phobos Ransomware encrypts data until a ransom is paid. 77% of Phobos attacks are successful according to the latest research. This malicious program was recorded in the wild for the first time in October 2017.

General description of Phobos Ransomware

Phobos ransomware appeared in 2017 in Dharma, also known as the CrySIS, family. A year later Phobos developed and spread rapidly. In 2019, it accounted for 8.9% of the submitted ransomware attacks. The First-quarter of 2020 showed that the Phobos strain was noted as one of the most common ransomware with 9.70% of submissions. It constantly gets updates and new versions.

The ransomware targets organizations all over the world. Phobos compromises RDP servers that are open or have weak security. Then cyber criminals send ransom notes, where the victim is asked to contact one of the emails to get the decryption key.

Phobos attackers exactly like Dharma ones can discuss ransom amounts depending on the company. The Ransom amount can reach 20,000 USD in Bitcoin. It is lower than usual ransomware demands because Phobos chooses small companies as victims. And sometimes cybercriminals don’t give up the decryption key even after the payment.

The malicious program uses encrypt data using AES and adds extensions to infected files such as .phobos, .phoenix, .actin, .help, .mamba and others. These files can be fully or partially encrypted.

Phobos is named after the Greek god of fear, but there is nothing divine about it. Criminals buy this malware in RaaS packages, so even without deep technical knowledge, they have an opportunity to design their own strain and organize an attack on the chosen victim.

Phobos malware analysis

The ANY.RUN malware hunting service features a video that displays the complete execution process of Phobos.

phobos ransomware process graph

Figure 1: Shows the graph of processes created by the ANY.RUN interactive malware analysis service

phobos ransom note

Figure 2: Phobos ransom note

Phobos Ransomware execution process

The execution process of the Phobos ransomware is relatively typical for this type of malware such as Troldesh. The executable file makes its way into an infected system and runs, then the main malicious activity begins. After the start of execution, the Ransomware deletes shadow copies. Interestingly though, as soon as it encrypts all targeted files, Phobos pops up a ransom note on the desktop, which is the ransomware executable file itself.

Phobos Ransomware distribution

Phobos has several ways to end up on your machine:

  • phishing emails with attachments
  • poorly secured RDP ports
  • fake updates
  • exploits
  • deceptive downloads
  • web injectors
  • repacked and infected installers

These distribution methods help attackers to steal victims’ information and encrypt the data by running Trojan or other malware. And a variety of the infected files is huge: documents, PDF and text files, databases, photos and videos, archives, etc. They can be located both in internal and external folders. Phobos gets rid of files’ shadow copies and backups.

Conclusion

Phobos is not a new type of ransomware, moreover, it has some similarities to Dharma. There is no need for criminals who use Phobos to be qualified specialists. Nevertheless, this ransomware always evolves, and its attacks are effective. It has a lot of ways to get into your device to get a ransom. That is why Phobos can be a serious threat to organizations.

HAVE A LOOK AT

ClickLock screenshot
ClickLock
clicklock
ClickLock is a macOS information stealer and remote backdoor distributed via deceptive, terminal-based social engineering pages. Once executed, it bypasses Gatekeeper checks by stripping download quarantine flags and signing its executable with ad-hoc digital certificates. If users resist its initial demands, the malware initiates high-frequency background loops that repeatedly kill vital operating system applications to force plaintext password entry. It exfiltrates captured browser data, system keychain credentials, and cryptocurrency wallets to a Telegram bot before establishing a permanent backdoor.
Read More
Kratos screenshot
Kratos
kratos
Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More
Netwalker screenshot
Netwalker
netwalker ransomware
Netwalker is ransomware — it belongs to a malware family which encrypts files and demands users to pay a ransom to get their data back. Netwalker utilizes several sophisticated techniques, such as process hollowing and code obfuscation to target corporate victims.
Read More
Sliver screenshot
Sliver
sliver
Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.
Read More