· @wrdlbrmpft
60 followers · 777 posts · Server social.tchncs.de

Nach über einer Woche haben wir jetzt tatsächlich Infos bekommen, die im Falle des Falles sicher Zeit gespart hätten, wenn wir sie vorher gehabt hätten. Da ist auch nichts geheimes oder neues dran:

sentinelone.com/labs/noname057
decoded.avast.io/martinchlumec

#DDOSIA #ddos #noname5716

Last updated 1 year ago

Day 5️⃣8️⃣ of : I was stoked this morning when I got a hit from the machO tag in MalwareBazzar 🎉 twitter.com/geenensp uploaded some samples of the ddosia/GoStresser botnet client which is a Go app that users self-infect (??) for the cause. Writing a signature is pretty easy using to Go package/struct names, file names, and a regex pattern the app uses so with that down, what else is interesting in here? 🤔

The most fun part is the main.BackendLink global which embeds the C2 servers IP address of 94[.]140[.]115[.]129 - using this we can see the C2 server is still online, pull it's targeting list and checkout who's next.

If you need yet another reason to detect unexpected VPN clients, add Surfshark 🦈 to the list - the botnet operators specifically call it out before joining their network clients should enable it (see web.archive.org/web/2022101318).

YARA: github.com/shellcromancer/Days

#100DaysofYARA #DDOSIA #go_stresser #ioc

Last updated 1 year ago

Tarnkappe.info · @tarnkappeinfo
1529 followers · 3787 posts · Server social.tchncs.de