AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network
ID: 0e2bf5f3-a406-59e6-b169-8c2e3006eb3f
STIX ID: report--0e2bf5f3-a406-59e6-b169-8c2e3006eb3f
Feed Name: cybersecurityNews.com
Threat Score
AryStinger intel: a catalogue of C2 domains, downloader domains/URLs, multiple MD5 hashes for RTL819X and Linux samples, malicious process/binary names, a hardcoded XOR key, and a scanner IP tied to exploitation via CVE-2013-3307 and CVE-2016-5681, indicating an active IoT/Linux malware campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
