Grixba Play Ransomware: GT_NET.exe Network Scan, inf_g.dll Load, and Recon Output Staging
Detects core indicators of Grixba malware, including the persistence path of GT_NET.exe in the Public Music directory, the loading of the associated malicious CoreScanner module (inf_g.dll), staging of reconnaissance output files, and the use of GT_NET.exe to perform network lateral movement via WMI/WinRM ports.
SentinelOne

