![]() |
|
Rapid new IoT botnet - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: World News (https://sinister.li/Forum-World-News) +--- Thread: Rapid new IoT botnet (/Thread-Rapid-new-IoT-botnet) |
Rapid new IoT botnet - S3xySmurf - 10-22-2017 A new Mirai linked IoT botnet has been spotted in the wild and it's growing rapidly, over 1 million organizations have already been hit while other sources estimate the number to be around 2 million, the vendors affected by this are not limited to the following GoAhead, D-Link, TP-Link, AVTECH, NETGEAR, MikroTik, Linksys, Synology and various others, exploits below. This tool is also capable of a DNS amplification attack with it's 100 embedded DNS open resolvers. Name: IoT_Reaper / IoTroop This maybe linked (Might actually be the same) but Checkpoint have dubbed it IoTroop https://research.checkpoint.com/new-iot-botnet-storm-coming/ Sources: http://blog.netlab.360.com/iot_reaper-a-rappid-spreading-new-iot-botnet-en/ http://www.securityweek.com/new-mirai-linked-iot-botnet-emerges https://thehackernews.com/2017/10/iot-botnet-malware-attack.html Exploits being used: Dlink https://blogs.securiteam.com/index.php/archives/3364 Goahead https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html Jaws https://www.pentestpartners.com/blog/pwning-cctv-cameras/ Netgear https://blogs.securiteam.com/index.php/archives/3409 Vacron NVR https://blogs.securiteam.com/index.php/archives/3445 Netgear http://seclists.org/bugtraq/2013/Jun/8 Linksys http://www.s3cur1ty.de/m1adv2013-004 Dlink http://www.s3cur1ty.de/m1adv2013-003 Avtech https://github.com/Trietptm-on-Security/AVTECH Indication you may be compromised: IP: 119.82.26.157 HOSTNAME: f.hl852.com IP: 27.102.101.121 HOSTNAME: d.hl852.com IP: 162.211.183.192 IP: 222.112.82.231 HOSTNAME: e.hl852.com md5 ca92a3b74a65ce06035fcc280740daf6 URL: http://27.102.101.121/down/1506753086 URL: http://bbk80.com/api/api.php URL: http://162.211.183.192/sm URL: http://23.234.51.91/htmpbe URL: http://198.44.241.220:8080/run.lua URL: http://cbk99.com:8080/run.lua URL: http://27.102.101.121/down/1506851514 URL: http://162.211.183.192/xget URL: http://162.211.183.192/down/server.armel URL: http://23.234.51.91/control-MIPS32-MSB URL: http://162.211.183.192/sa5 URL: http://23.234.51.91/control-ARM-LSB URL: http://23.234.51.91/htam5le URL: http://162.211.183.192/sa URL: http://103.1.221.40/63ae01/39xjsda.php URL: http://162.211.183.192/server.armel MD5: a3401685d8d9c7977180a5c6df2f646a MD5: abe79b8e66c623c771acf9e21c162f44 MD5: 9f8e8b62b5adaf9c4b5bdbce6b2b95d1 MD5: 726d0626f66d5cacfeff36ed954dad70 MD5: 6f91694106bb6d5aaa7a7eac841141d9 MD5: 704098c8a8a6641a04d25af7406088e1 MD5: 3182a132ee9ed2280ce02144e974220a MD5: 95b448bdf6b6c97a33e1d1dbe41678eb MD5: 4406bace3030446371df53ebbdc17785 MD5: 6587173d571d2a587c144525195daec9 MD5: 4e2f58ba9a8a2bf47bdc24ee74956c73 MD5: 596b3167fe0d13e3a0cfea6a53209be4 MD5: 41ef6a5c5b2fde1b367685c7b8b3c154 MD5: 76be3db77c7eb56825fe60009de2a8f2 MD5: 9ad8473148e994981454b3b04370d1ec MD5: b2d4a77244cd4f704b65037baf82d897 MD5: 3d680273377b67e6491051abe17759db MD5: fb7c00afe00eeefb5d8a24d524f99370 MD5: e9a03dbde09c6b0a83eefc9c295711d7 MD5: f9ec2427377cbc6afb4a7ff011e0de77 RE: Rapid new IoT botnet - Drako - 10-22-2017 That's great, in the midst of all the freak out over KRACK, all the major router providers have to deal with this? RE: Rapid new IoT botnet - S3xySmurf - 10-22-2017 (10-22-2017, 11:25 PM)Drako Wrote: That's great, in the midst of all the freak out over KRACK, all the major router providers have to deal with this? It's not just the router providers, it's every single company that could be affected if the attacker decides to begin a DDoS, so far he hasn't launched any attack but if this keeps growing the damage could be bigger than Mirai
RE: Rapid new IoT botnet - Bish0pQ - 10-23-2017 I've actually heard about this. It's probably not going to take very long untill it will get abused by DDosers or will be used for spreading ransomware. RE: Rapid new IoT botnet - mothered - 10-23-2017 It can certainly cause widespread damage on quite a large scale. Thanks for the Info pertaining to being compromised. |