Lethic Botnet Returns, Uses "Realtek" Identifier
ID: 86f163df-eec5-53a7-8f98-b9dd8fa0e45e
STIX ID: report--86f163df-eec5-53a7-8f98-b9dd8fa0e45e
Feed Name: Zscaler Security Research Blog
The report documents a Fall 2010 resurgence/variant of the Lethic (Ddox) spam botnet: two recent MD5-sampled binaries and ~91 additional samples include PE Version Info mimicking Realtek Semiconductor Corp. product data. Observed activity includes propagation from multiple IPs on changing ports, connections to newly registered C2 domains (izuhjsn.com, xkihjhx.com) and spam-sending via SMTP proxies/open-relays; the author notes that the Realtek string is not a cryptographic signature but a useful correlation artifact for attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
