Another Trojan Bamital Pattern
ID: 71b5df61-4a2c-526f-b26e-fb4a97146bce
STIX ID: report--71b5df61-4a2c-526f-b26e-fb4a97146bce
Feed Name: Zscaler Security Research Blog
This report documents detection of Bamital Trojan variants using an alternate HTTP C2 beacon pattern (/message.php?subid=... with parameters &br=,&os=,&flg=,&id=,&ad=,&ver=), enumerates numerous hash-like domains (many under .co.cc/.cz.cc and some .info), lists resolved IP addresses (112.175.243.21–24 and 207.58.177.96), cites open-source confirmation of malicious hosting, and provides Snort rules/signatures and mitigation guidance (use signatures plus domain/IP filtering).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
