New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector
ID: bf5245fa-e2d7-56fd-ad68-e019179da92e
STIX ID: report--bf5245fa-e2d7-56fd-ad68-e019179da92e
Feed Name: cybersecurityNews.com
Threat Score
**Udados** is a newly identified botnet that leverages infected hosts to perform high-volume HTTP POST DDoS attacks; the report provides C2 indicators (AS214943/RAILNET, IP 178.16.54.87, domain ryxuz.com), the command '!httppost' with duration/threads and Base64 payloads, telemetry JSON fields used for bot management, and IOCs (two SHA256 hashes and the URI /uda/ph.php) to assist detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
