logo

New MDBotnet Unleashes DDoS Attacks – Cyble

ID: 4539a04d-183f-5a31-b458-676ddc9a4348

STIX ID: report--4539a04d-183f-5a31-b458-676ddc9a4348

Feed Name: Cyble Blog

Threat Score
65/100

Date Published: 2023-10-31

Date Updated: 2026-07-20

...
...

MDBotnet is a .NET-based DDoS bot (sample SlavaRussia.exe) sold on a Russian cybercrime forum as DDoS-as-a-service; analysis shows it connects to C2 at 212.109.199.128:4202, persists via a registry Run key, auto-updates through Updater.exe/svhost.exe, and implements HTTP GET flooding (SYN flood code exists but appears disabled). The report includes multiple file hashes and the C2 IP:Port as IOCs and recommends standard mitigation and monitoring controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.