Battling Cryptojacking, Botnets, and IABs [Guest Diary], (Thu, Jan 15th)
ID: 1b45f5c0-282e-565e-84dc-f186df9ba291
STIX ID: report--1b45f5c0-282e-565e-84dc-f186df9ba291
Feed Name: SANS ISC Diary
This guest diary analyzes DShield honeypot traffic showing a common attack chain: SSH password-spray -> automated system enumeration -> SSH persistence setup -> transfer and execution of a Go-based trojan/miner linked to botnet/cryptojacking operations. The author provides observed IPs and a malware hash, maps the attacker TTPs (attribution to an ‘Outlaw’ runbook is used as a threat model), and recommends mitigations including disabling password SSH auth, enforcing MFA, file integrity monitoring, log centralization, and proactive threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
