Rapid new IoT botnet 10-22-2017, 11:23 PM
#1
A new Mirai linked IoT botnet has been spotted in the wild and it's growing rapidly, over 1 million organizations have already been hit while other sources estimate the number to be around 2 million, the vendors affected by this are not limited to the following GoAhead, D-Link, TP-Link, AVTECH, NETGEAR, MikroTik, Linksys, Synology and various others, exploits below.
This tool is also capable of a DNS amplification attack with it's 100 embedded DNS open resolvers.
Name: IoT_Reaper / IoTroop
This maybe linked (Might actually be the same) but Checkpoint have dubbed it IoTroop https://research.checkpoint.com/new-iot-...rm-coming/
Sources:
http://blog.netlab.360.com/iot_reaper-a-...botnet-en/
http://www.securityweek.com/new-mirai-li...et-emerges
https://thehackernews.com/2017/10/iot-bo...ttack.html
Exploits being used:
Dlink https://blogs.securiteam.com/index.php/archives/3364
Goahead https://pierrekim.github.io/blog/2017-03...-0day.html
Jaws https://www.pentestpartners.com/blog/pwn...v-cameras/
Netgear https://blogs.securiteam.com/index.php/archives/3409
Vacron NVR https://blogs.securiteam.com/index.php/archives/3445
Netgear http://seclists.org/bugtraq/2013/Jun/8
Linksys http://www.s3cur1ty.de/m1adv2013-004
Dlink http://www.s3cur1ty.de/m1adv2013-003
Avtech https://github.com/Trietptm-on-Security/AVTECH
Indication you may be compromised:
IP: 119.82.26.157
HOSTNAME: f.hl852.com
IP: 27.102.101.121
HOSTNAME: d.hl852.com
IP: 162.211.183.192
IP: 222.112.82.231
HOSTNAME: e.hl852.com
md5 ca92a3b74a65ce06035fcc280740daf6
URL: http://27.102.101.121/down/1506753086
URL: http://bbk80.com/api/api.php
URL: http://162.211.183.192/sm
URL: http://23.234.51.91/htmpbe
URL: http://198.44.241.220:8080/run.lua
URL: http://cbk99.com:8080/run.lua
URL: http://27.102.101.121/down/1506851514
URL: http://162.211.183.192/xget
URL: http://162.211.183.192/down/server.armel
URL: http://23.234.51.91/control-MIPS32-MSB
URL: http://162.211.183.192/sa5
URL: http://23.234.51.91/control-ARM-LSB
URL: http://23.234.51.91/htam5le
URL: http://162.211.183.192/sa
URL: http://103.1.221.40/63ae01/39xjsda.php
URL: http://162.211.183.192/server.armel
MD5: a3401685d8d9c7977180a5c6df2f646a
MD5: abe79b8e66c623c771acf9e21c162f44
MD5: 9f8e8b62b5adaf9c4b5bdbce6b2b95d1
MD5: 726d0626f66d5cacfeff36ed954dad70
MD5: 6f91694106bb6d5aaa7a7eac841141d9
MD5: 704098c8a8a6641a04d25af7406088e1
MD5: 3182a132ee9ed2280ce02144e974220a
MD5: 95b448bdf6b6c97a33e1d1dbe41678eb
MD5: 4406bace3030446371df53ebbdc17785
MD5: 6587173d571d2a587c144525195daec9
MD5: 4e2f58ba9a8a2bf47bdc24ee74956c73
MD5: 596b3167fe0d13e3a0cfea6a53209be4
MD5: 41ef6a5c5b2fde1b367685c7b8b3c154
MD5: 76be3db77c7eb56825fe60009de2a8f2
MD5: 9ad8473148e994981454b3b04370d1ec
MD5: b2d4a77244cd4f704b65037baf82d897
MD5: 3d680273377b67e6491051abe17759db
MD5: fb7c00afe00eeefb5d8a24d524f99370
MD5: e9a03dbde09c6b0a83eefc9c295711d7
MD5: f9ec2427377cbc6afb4a7ff011e0de77
This tool is also capable of a DNS amplification attack with it's 100 embedded DNS open resolvers.
Name: IoT_Reaper / IoTroop
This maybe linked (Might actually be the same) but Checkpoint have dubbed it IoTroop https://research.checkpoint.com/new-iot-...rm-coming/
Sources:
http://blog.netlab.360.com/iot_reaper-a-...botnet-en/
http://www.securityweek.com/new-mirai-li...et-emerges
https://thehackernews.com/2017/10/iot-bo...ttack.html
Exploits being used:
Dlink https://blogs.securiteam.com/index.php/archives/3364
Goahead https://pierrekim.github.io/blog/2017-03...-0day.html
Jaws https://www.pentestpartners.com/blog/pwn...v-cameras/
Netgear https://blogs.securiteam.com/index.php/archives/3409
Vacron NVR https://blogs.securiteam.com/index.php/archives/3445
Netgear http://seclists.org/bugtraq/2013/Jun/8
Linksys http://www.s3cur1ty.de/m1adv2013-004
Dlink http://www.s3cur1ty.de/m1adv2013-003
Avtech https://github.com/Trietptm-on-Security/AVTECH
Indication you may be compromised:
IP: 119.82.26.157
HOSTNAME: f.hl852.com
IP: 27.102.101.121
HOSTNAME: d.hl852.com
IP: 162.211.183.192
IP: 222.112.82.231
HOSTNAME: e.hl852.com
md5 ca92a3b74a65ce06035fcc280740daf6
URL: http://27.102.101.121/down/1506753086
URL: http://bbk80.com/api/api.php
URL: http://162.211.183.192/sm
URL: http://23.234.51.91/htmpbe
URL: http://198.44.241.220:8080/run.lua
URL: http://cbk99.com:8080/run.lua
URL: http://27.102.101.121/down/1506851514
URL: http://162.211.183.192/xget
URL: http://162.211.183.192/down/server.armel
URL: http://23.234.51.91/control-MIPS32-MSB
URL: http://162.211.183.192/sa5
URL: http://23.234.51.91/control-ARM-LSB
URL: http://23.234.51.91/htam5le
URL: http://162.211.183.192/sa
URL: http://103.1.221.40/63ae01/39xjsda.php
URL: http://162.211.183.192/server.armel
MD5: a3401685d8d9c7977180a5c6df2f646a
MD5: abe79b8e66c623c771acf9e21c162f44
MD5: 9f8e8b62b5adaf9c4b5bdbce6b2b95d1
MD5: 726d0626f66d5cacfeff36ed954dad70
MD5: 6f91694106bb6d5aaa7a7eac841141d9
MD5: 704098c8a8a6641a04d25af7406088e1
MD5: 3182a132ee9ed2280ce02144e974220a
MD5: 95b448bdf6b6c97a33e1d1dbe41678eb
MD5: 4406bace3030446371df53ebbdc17785
MD5: 6587173d571d2a587c144525195daec9
MD5: 4e2f58ba9a8a2bf47bdc24ee74956c73
MD5: 596b3167fe0d13e3a0cfea6a53209be4
MD5: 41ef6a5c5b2fde1b367685c7b8b3c154
MD5: 76be3db77c7eb56825fe60009de2a8f2
MD5: 9ad8473148e994981454b3b04370d1ec
MD5: b2d4a77244cd4f704b65037baf82d897
MD5: 3d680273377b67e6491051abe17759db
MD5: fb7c00afe00eeefb5d8a24d524f99370
MD5: e9a03dbde09c6b0a83eefc9c295711d7
MD5: f9ec2427377cbc6afb4a7ff011e0de77
(This post was last modified: 10-22-2017, 11:38 PM by S3xySmurf.
Edit Reason: Adding info
)
![[Image: YmmIqHV.gif]](https://i.imgur.com/YmmIqHV.gif)
Donations: 1CCR21K2fnu2yAinUTFPsVdY7u4FkjNPs5




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)




















