Four Seconds to Botnet - Analyzing a Self Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary], (Wed, Feb 11th)
ID: 2e049837-4c26-5d7a-bf65-61e76e983d03
STIX ID: report--2e049837-4c26-5d7a-bf65-61e76e983d03
Feed Name: SANS ISC Diary
This SANS/ISC sensor report documents a rapid SSH brute-force compromise of a Raspberry Pi that uploaded a 4.7KB bash worm which established persistence, killed competing malware, added a C2 hostname, joined IRC-based command channels using RSA-signed commands, and deployed zmap and sshpass to scan and propagate using default/weak credentials (pi/raspberry, pi/raspberryraspberry993311). The incident demonstrates automated worm propagation, IoT-targeted credential stuffing, and provides IP/hostname indicators and mitigation recommendations (disable password auth, remove default users, enable fail2ban, network-segment IoT).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
