Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
ID: 364bd871-e53e-595e-995c-cf4c22146d88
STIX ID: report--364bd871-e53e-595e-995c-cf4c22146d88
Feed Name: SANS ISC Diary
This report analyzes an x86_64 RedTail Linux payload recovered from a DShield honeypot: the author executed the sample in an isolated Ubuntu VM, collected pre/post memory images and extensive telemetry, and observed consistent behaviors including detailed host profiling (CPU, cache, NUMA, DMI), process masquerading (changing visible names to php/postgres), termination of monitoring tools via SIGKILL, persistence via @reboot cron entries, dynamic high-port TCP listeners, attempted firewall modification, and repeated failed connection attempts to multiple external IPs on TCP/853 (consistent with DNS-over-TLS resolver initialization); accompanying setup.sh and clean.sh were statically analyzed but not executed during the dynamic runs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
