da_667 · @da_667
3107 followers · 195 posts · Server infosec.exchange

Interestingly enough, the second bot, GoTrim uses a very unique user-agent for doing external IP address checks against a number of "what's my IP address" services, with a very unique user-agent: go-external-ip

We already have a rule for that -- 2030468 go-external-ip library User-Agent

#malware #ransomware #threatintel #iocs #iocexchange #snort #suricata #nsm #threathunting #gotrim #ciaransomware

Last updated 3 years ago

Unperson ❌ · @Unperson
42 followers · 144 posts · Server ioc.exchange

Big thanks to @seb and those moderating here on for the hosting. I appreciate it greatly. ❤️

#iocexchange #mastodon #instance

Last updated 3 years ago