logo

ThreatLabz

ID: 8eee0da4-d1c0-5204-b1b7-e3b8ff672058

STIX ID: report--8eee0da4-d1c0-5204-b1b7-e3b8ff672058

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz provides a technical analysis of the DreamBus botnet, describing recently added exploit modules for Metabase (CVE-2023-38646) and Apache RocketMQ (CVE-2023-33246). The report documents scanning behavior across internal RFC1918 and public ranges, exploit request/response patterns, staged JSON and binary payloads, bash scripts that fetch the main DreamBus module and deploy XMRig for Monero mining, and multiple indicators (domains, IP 92.204.243.155, lockfile /tmp/.systemd.3, temporary filenames and script fragments) useful for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.