Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Butter distributed via SSH bruteforce

released on 2018-12-07 @ 09:10:59 PM
Over the last few years we’ve seen two common payloads, 80 and samba. 80, the older and more prevalent, is a x64 variant of the well known DDoS payload XOR.DDOS with the filename 80. This is a modern RAT with DDoS functionality that runs itself persistently using cron, kills competitor malware, and installs a Linux kernel rootkit to hide its tracks. Samba, named after one of the file names it disguises itself in, first emerged in July of this year. The core features of this malware are typical along with a RAT functionality that includes downloading files, executing shell commands, an upgrade mechanism, and the capability to join in DDoS attacks. Typical to RATs in the past few years, the malware has a built-in functionality to download and run a miner. Since it first showed up we’ve seen seven versions of this malware.