logo

30 Days Of Cycbot

ID: 5eb24301-c923-56fc-b4eb-2ec2557700f0

STIX ID: report--5eb24301-c923-56fc-b4eb-2ec2557700f0

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report documents analysis of the Cycbot botnet (observed since March 10 and initially detected around August 2010), describing a characteristic HTTP beaconing pattern (?tq=BASE64 and optional vNUM1=NUM2) with a mozilla/2.0 user agent, decode attempts of embedded base64/XOR data, multiple MD5 sample hashes, and a broad, growing set of C2 domains and IPs — many recently registered or hosted on compromised sites. It highlights low AV detection on submissions and provides registrant/email artifacts and C2 listings to use as IOCs and patrol searches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.