New Asprox Variant Goes Above And Beyond To Hijack Victims
ID: b5dde678-9844-5bcf-a46b-ac7c38d6e2f4
STIX ID: report--b5dde678-9844-5bcf-a46b-ac7c38d6e2f4
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes the Asprox botnet: it lists active download URLs and a C2 IP (88.85.215.129), describes persistence mechanisms (self-deletion, creation of a randomly named Windows Scheduled Task, disabling Safe Mode), outlines C2 phone-home behavior and heavy hidden ad traffic (HTTP POSTs containing '/b/opt/'), and provides network detection guidance to identify infected hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
