logo

Tracking A Botnet Infection

ID: f2911ac4-7f4b-5dc6-af3d-f401e4fc5a52

STIX ID: report--f2911ac4-7f4b-5dc6-af3d-f401e4fc5a52

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Researchers found malicious executables hosted on six compromised legitimate domains that served a botnet payload with changing file signatures. The botnet hides in the Recycle Bin, infects running processes, communicates with >50 changing IPs on UDP/16471 and TCP/16471, and contacts a consistent C2 domain via non-standard HTTP/1.0 requests; weak site configurations (public AWStats and directory listings) enabled distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.