Tracking A Botnet Infection
ID: f2911ac4-7f4b-5dc6-af3d-f401e4fc5a52
STIX ID: report--f2911ac4-7f4b-5dc6-af3d-f401e4fc5a52
Feed Name: Zscaler Security Research Blog
Threat Score
Researchers found malicious executables hosted on six compromised legitimate domains that served a botnet payload with changing file signatures. The botnet hides in the Recycle Bin, infects running processes, communicates with >50 changing IPs on UDP/16471 and TCP/16471, and contacts a consistent C2 domain via non-standard HTTP/1.0 requests; weak site configurations (public AWStats and directory listings) enabled distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
