DanaBot Launches DDoS Attack
ID: 17ff8979-90e2-5bc2-b7a2-248d1bedc71e
STIX ID: report--17ff8979-90e2-5bc2-b7a2-248d1bedc71e
Feed Name: Zscaler Security Research Blog
This ThreatLabz report documents an active DanaBot affiliate (ID 5) campaign that delivered a Delphi-based HTTP DDoS executable via DanaBot's download-and-execute functionality to target the Ukrainian Ministry of Defense webmail and an IP associated with invaders-rf.com; the report includes the DDoS binary SHA-256, screenshots, contextual analysis of DanaBot as a malware-as-a-service, and notes potential additional credential/document theft and uncertain attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
