Login Register






Rapid new IoT botnet filter_list
Author
Message
Rapid new IoT botnet #1
A new Mirai linked IoT botnet has been spotted in the wild and it's growing rapidly, over 1 million organizations have already been hit while other sources estimate the number to be around 2 million, the vendors affected by this are not limited to the following GoAhead, D-Link, TP-Link, AVTECH, NETGEAR, MikroTik, Linksys, Synology and various others, exploits below.

This tool is also capable of a DNS amplification attack with it's 100 embedded DNS open resolvers.

Name: IoT_Reaper / IoTroop

This maybe linked (Might actually be the same) but Checkpoint have dubbed it IoTroop https://research.checkpoint.com/new-iot-...rm-coming/

Sources:
http://blog.netlab.360.com/iot_reaper-a-...botnet-en/
http://www.securityweek.com/new-mirai-li...et-emerges
https://thehackernews.com/2017/10/iot-bo...ttack.html

Exploits being used:
Dlink https://blogs.securiteam.com/index.php/archives/3364
Goahead https://pierrekim.github.io/blog/2017-03...-0day.html
Jaws https://www.pentestpartners.com/blog/pwn...v-cameras/
Netgear https://blogs.securiteam.com/index.php/archives/3409
Vacron NVR https://blogs.securiteam.com/index.php/archives/3445
Netgear http://seclists.org/bugtraq/2013/Jun/8
Linksys http://www.s3cur1ty.de/m1adv2013-004
Dlink http://www.s3cur1ty.de/m1adv2013-003
Avtech https://github.com/Trietptm-on-Security/AVTECH

Indication you may be compromised:
IP: 119.82.26.157
HOSTNAME: f.hl852.com
IP: 27.102.101.121
HOSTNAME: d.hl852.com
IP: 162.211.183.192
IP: 222.112.82.231
HOSTNAME: e.hl852.com
md5 ca92a3b74a65ce06035fcc280740daf6
URL: http://27.102.101.121/down/1506753086
URL: http://bbk80.com/api/api.php
URL: http://162.211.183.192/sm
URL: http://23.234.51.91/htmpbe
URL: http://198.44.241.220:8080/run.lua
URL: http://cbk99.com:8080/run.lua
URL: http://27.102.101.121/down/1506851514
URL: http://162.211.183.192/xget
URL: http://162.211.183.192/down/server.armel
URL: http://23.234.51.91/control-MIPS32-MSB
URL: http://162.211.183.192/sa5
URL: http://23.234.51.91/control-ARM-LSB
URL: http://23.234.51.91/htam5le
URL: http://162.211.183.192/sa
URL: http://103.1.221.40/63ae01/39xjsda.php
URL: http://162.211.183.192/server.armel
MD5: a3401685d8d9c7977180a5c6df2f646a
MD5: abe79b8e66c623c771acf9e21c162f44
MD5: 9f8e8b62b5adaf9c4b5bdbce6b2b95d1
MD5: 726d0626f66d5cacfeff36ed954dad70
MD5: 6f91694106bb6d5aaa7a7eac841141d9
MD5: 704098c8a8a6641a04d25af7406088e1
MD5: 3182a132ee9ed2280ce02144e974220a
MD5: 95b448bdf6b6c97a33e1d1dbe41678eb
MD5: 4406bace3030446371df53ebbdc17785
MD5: 6587173d571d2a587c144525195daec9
MD5: 4e2f58ba9a8a2bf47bdc24ee74956c73
MD5: 596b3167fe0d13e3a0cfea6a53209be4
MD5: 41ef6a5c5b2fde1b367685c7b8b3c154
MD5: 76be3db77c7eb56825fe60009de2a8f2
MD5: 9ad8473148e994981454b3b04370d1ec
MD5: b2d4a77244cd4f704b65037baf82d897
MD5: 3d680273377b67e6491051abe17759db
MD5: fb7c00afe00eeefb5d8a24d524f99370
MD5: e9a03dbde09c6b0a83eefc9c295711d7
MD5: f9ec2427377cbc6afb4a7ff011e0de77
(This post was last modified: 10-22-2017, 11:38 PM by S3xySmurf. Edit Reason: Adding info )
[Image: YmmIqHV.gif]
Donations: 1CCR21K2fnu2yAinUTFPsVdY7u4FkjNPs5

Reply

RE: Rapid new IoT botnet #2
That's great, in the midst of all the freak out over KRACK, all the major router providers have to deal with this?

[+] 1 user Likes Drako's post
Reply

RE: Rapid new IoT botnet #3
(10-22-2017, 11:25 PM)Drako Wrote: That's great, in the midst of all the freak out over KRACK, all the major router providers have to deal with this?

It's not just the router providers, it's every single company that could be affected if the attacker decides to begin a DDoS, so far he hasn't launched any attack but if this keeps growing the damage could be bigger than Mirai Notamused
[Image: YmmIqHV.gif]
Donations: 1CCR21K2fnu2yAinUTFPsVdY7u4FkjNPs5

Reply

RE: Rapid new IoT botnet #4
I've actually heard about this. It's probably not going to take very long untill it will get abused by DDosers or will be used for spreading ransomware.
~~ Might be back? ~~

[+] 2 users Like Bish0pQ's post
Reply

RE: Rapid new IoT botnet #5
It can certainly cause widespread damage on quite a large scale.

Thanks for the Info pertaining to being compromised.
[Image: AD83g1A.png]

Reply