Interestingly enough, the second bot, GoTrim uses a very unique user-agent for doing external IP address checks against a number of "what's my IP address" services, with a very unique user-agent: go-external-ip
We already have a rule for that -- 2030468 go-external-ip library User-Agent
#Malware #Ransomware #ThreatIntel #iocs #iocexchange #Snort #Suricata #NSM #ThreatHunting #GoTrim #CIARansomware
#malware #ransomware #threatintel #iocs #iocexchange #snort #suricata #nsm #threathunting #gotrim #ciaransomware
#GoTrim #botnet actively brute forces #WordPress and #OpenCart sites
https://securityaffairs.co/wordpress/139647/malware/gotrim-botnet-wordpress.html
#securityaffairs #hacking
#gotrim #botnet #wordpress #OpenCart #securityaffairs #hacking
Il nuova botnet GoTrim prende di mira gli account di amministrazione di WordPress
Gli specialisti di #Fortinet hanno scoperto un nuovo #malware chiamato #GoTrim il quale è stato scritto in #Go e sta scansionando Internet alla ricerca di siti #WordPress per forzare la #password degli #amministratori del sito e ottenerne il controllo.
#redhotcyber #informationsecurity #ethicalhacking #dataprotection #hacking #cybersecurity #cybercrime #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #privacy #infosecurity
#infosecurity #privacy #CyberSecurityNews #cybersecuritytraining #CyberSecurityAwareness #cybercrime #cybersecurity #hacking #dataprotection #ethicalhacking #informationsecurity #redhotcyber #amministratori #password #wordpress #go #gotrim #malware #fortinet
New Go-Based "#GoTrim" Botnet Threatens #WordPress Sites: Protect Your Admin Account Now!
https://thehackernews.com/2022/12/new-gotrim-botnet-attempting-to-break.html
#CyberSecurity #Hacking #InfoSec #WordPress #gotrim