da_667 · @da_667
3107 followers · 195 posts · Server infosec.exchange

Interestingly enough, the second bot, GoTrim uses a very unique user-agent for doing external IP address checks against a number of "what's my IP address" services, with a very unique user-agent: go-external-ip

We already have a rule for that -- 2030468 go-external-ip library User-Agent

#malware #ransomware #threatintel #iocs #iocexchange #snort #suricata #nsm #threathunting #gotrim #ciaransomware

Last updated 3 years ago

securityaffairs · @securityaffairs
161 followers · 96 posts · Server infosec.exchange
Redhotcyber · @redhotcyber
264 followers · 213 posts · Server mastodon.bida.im
Anonymous :verified_neko:🏴 · @YourAnonRiots
4620 followers · 28018 posts · Server mstdn.social