僵尸网络新秀:Dysphoria 演进与深度技术分析
ID: 11000e50-6842-5deb-8634-700d41736a20
STIX ID: report--11000e50-6842-5deb-8634-700d41736a20
Feed Name: QiAnXin XLab
This report analyzes the Dysphoria botnet: an actively evolving IoT-focused malware family (estimated ~200k bots) that conducts large-scale DDoS and has introduced sophisticated features such as customized RC4-like string encryption, ENS/SNS blockchain-based C2 resolution, and conversion of infected hosts into C2 relay/proxy nodes via UPnP and epoll-based forwarding; it includes timelines, malware technical analysis, propagation methods (weak Telnet/SSH credentials and multiple IoT RCE CVEs), protocol formats, and a comprehensive set of IOCs (IPs, domains, ENS/SNS names, and sample hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
