{"id":4130,"date":"2022-03-31T20:31:18","date_gmt":"2022-04-01T01:31:18","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4130"},"modified":"2022-03-31T20:31:19","modified_gmt":"2022-04-01T01:31:19","slug":"purple-fox-targets-and-threatens-windows-users","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/","title":{"rendered":"Purple Fox targets and threatens Windows users"},"content":{"rendered":"\n<p>There are many security threats that can put Windows systems at risk. Many varieties of malware that in one way or another can affect its proper functioning. Today we echo Purple Fox, a new security problem whose mission is to scan for vulnerable Windows systems.<\/p>\n\n\n\n<p>Purple Fox is malware that was previously distributed via exploit kits and Phishing emails. However, it has now added a module that allows it to scan and infect Internet-accessible Windows systems and carry out attacks.<\/p>\n\n\n\n<p>This malware has rootkit and backdoor capabilities. It was first detected in 2018 after infecting more than 30,000 devices and is used as a downloader implement for other malware strains. It is not the first time that this threat sets its sights on Windows systems.<\/p>\n\n\n\n<p>One of its qualities is to infect Windows users through their web browsers after exploiting memory corruption and elevation of privilege vulnerabilities.<\/p>\n\n\n\n<p>However, in recent months, Purple Fox attacks have intensified significantly, reaching a total of 90,000 attacks and 600% more infections, according to Guardicore Labs security researchers Amit Serper and Ophir Harpaz.<\/p>\n\n\n\n<p>Devices caught in this botnet include Windows Server machines running IIS version 7.5 and Microsoft FTP, and servers running Microsoft RPC, Microsoft Server SQL Server 2008 R2 and Microsoft HTTPAPI httpd 2.0, and Microsoft Terminal Service.<\/p>\n\n\n\n<p>Although the new worm-like behavior, Purple Fox allows it to infect servers by forcing access through vulnerable SMB services exposed to the Internet, it also uses phishing campaigns and web browser vulnerabilities to distribute its payloads.<\/p>\n\n\n\n<p>If you want to keep an eye on the sites affected by this threat then in this document you will find the Purple Fox MSI launch sites and connection servers. <a href=\"https:\/\/github.com\/guardicore\/labs_campaigns\/tree\/master\/Purple_Fox\">https:\/\/github.com\/guardicore\/labs_campaigns\/tree\/master\/Purple_Fox<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There are many security threats that can put Windows systems at risk but&#8230; today we will talk about a new one called Purple Fox&#8230;&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4131,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4130","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Purple Fox targets and threatens Windows users - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"There are many security threats that can put Windows systems at risk but... today we will talk about a new one called Purple Fox......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Purple Fox targets and threatens Windows users - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"There are many security threats that can put Windows systems at risk but... today we will talk about a new one called Purple Fox......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-01T01:31:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-01T01:31:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Purple-Fox.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"860\" \/>\n\t<meta property=\"og:image:height\" content=\"520\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Purple Fox targets and threatens Windows users\",\"datePublished\":\"2022-04-01T01:31:18+00:00\",\"dateModified\":\"2022-04-01T01:31:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/\"},\"wordCount\":290,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Purple-Fox.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/\",\"name\":\"Purple Fox targets and threatens Windows users - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Purple-Fox.jpg\",\"datePublished\":\"2022-04-01T01:31:18+00:00\",\"dateModified\":\"2022-04-01T01:31:19+00:00\",\"description\":\"There are many security threats that can put Windows systems at risk but... today we will talk about a new one called Purple Fox......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Purple-Fox.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Purple-Fox.jpg\",\"width\":860,\"height\":520},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/purple-fox-targets-and-threatens-windows-users\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Purple Fox targets and threatens Windows users\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Purple Fox targets and threatens Windows users - Truxgo Server Blog","description":"There are many security threats that can put Windows systems at risk but... today we will talk about a new one called Purple Fox......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/","og_locale":"es_MX","og_type":"article","og_title":"Purple Fox targets and threatens Windows users - Truxgo Server Blog","og_description":"There are many security threats that can put Windows systems at risk but... today we will talk about a new one called Purple Fox......","og_url":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-04-01T01:31:18+00:00","article_modified_time":"2022-04-01T01:31:19+00:00","og_image":[{"width":860,"height":520,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Purple-Fox.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Purple Fox targets and threatens Windows users","datePublished":"2022-04-01T01:31:18+00:00","dateModified":"2022-04-01T01:31:19+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/"},"wordCount":290,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Purple-Fox.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/","url":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/","name":"Purple Fox targets and threatens Windows users - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Purple-Fox.jpg","datePublished":"2022-04-01T01:31:18+00:00","dateModified":"2022-04-01T01:31:19+00:00","description":"There are many security threats that can put Windows systems at risk but... today we will talk about a new one called Purple Fox......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Purple-Fox.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Purple-Fox.jpg","width":860,"height":520},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/purple-fox-targets-and-threatens-windows-users\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Purple Fox targets and threatens Windows users"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4130","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4130"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4130\/revisions"}],"predecessor-version":[{"id":4132,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4130\/revisions\/4132"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4131"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4130"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4130"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4130"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}