So, we published our Fodcha botnet blog two days ago, and the author behind this botnet pushed an updated new sample with the following message inside....🤪
What are the most active P2P based botnets on the internet now, and what are their sizes? We(360netlab) have a tracking system in place for a while and here are some basic information about Pink,Mozi,Hajime,FritzFrog and Panchan.
blog.netlab.360.com/p2p-botnets-re…
New version of Fodcha is bigger and probably better, and attacking various websites like there is no tomorrow. (in previous version, the author left a note saying "Netlab pls leave me alone I surrender", it does not seem so) blog.netlab.360.com/fodcha-is-comi…
We have noticed that some malware authors pay attention to who downloads their malwares from their downloader servers, aka, they do their security data analysis, if a device other than their own bots connect to their downloader, they DDoS these device IPs.
Our latest blog is about a new Monroe coin mining botnet Orchard, among other things, this botnet uses Satoshi Nakamoto's Bitcoin account transaction information to generate DGA domain names to evade detection. blog.netlab.360.com/a-new-botnet-o…
A new updated fbot have been attacking various big names, it is now one of the most active DDos botnets that we have observed recently, more details can be found from our recently published blog blog.netlab.360.com/botnet-group-b… (in Chinese, but google translate will do the trick).
Here at Quad9, we saw fridgexperts[.]cc skyrocket to our top blocked site with a whopping 30M+ blocks in just under 24 hours--starting ~noon UTC on the 14th!
#Fodcha#DDoS#botnet#DNS
Our latest blog, a new DDoS botnet Fodcha, which is big, and very active attacking various targets, some of the victims are the world top popular domains(top 10 companies) blog.netlab.360.com/fodcha-a-new-d…
Our latest blog, blog.netlab.360.com/b1txor20-use-o… B1txor20, a new Linux backdoor rides on the Log4J vulnerability and uses DNS tunnel for C2 communications.
We observed that ripprbot botnet has instructed its bots to attack targets 147.237.0.0, 147.237.64.0 and 147.237.68.0, all belong to Israeli Government Network
A DDoS attack today against Israel reportedly took down the country's government websites.
@kentikinc observed a DDoS attack focused primarily against AS8867 (Israeli E-Government Project) beginning just before 15:30 UTC (5:30pm local).
haaretz.com/israel-news/.p…
Our latest blog about the recent Ukraine and Russia DDoS attacks, takeaway: botnets are actively been recruited for attacks on both sides and Russia actually receives more DDoS than Ukraine does. blog.netlab.360.com/some_details_o…
123K Followers 8K FollowingDepartment of Cyber WAR.
Member of the Counter Spider Collective.
Wielder of AI to defend in Cyber Space.
Ralph Vibe Specialist.
VibeOps Operator!
19K Followers 233 FollowingAnda boleh melakukan segala-galanya dari syurga ke bumi, wanita kecil!!
If you have any questions, please contact me
https://t.co/MkzsavUU9V
22K Followers 315 Following#OSINT treasure hunter, investigator, #CyberThreatIntel analyst. Opinions are my own. Follow me on Telegram https://t.co/i6VBbeUXgd for cyber news.
14K Followers 237 FollowingA random infosec/science enthusiast guy...
This account is personal and only reflects my opinions, not those of my employer...and if it hurts your feelings🖕
37K Followers 3K FollowingSituational Awareness | Threat Intelligence | cybertracker | Hacktivism | Meme Farmer
Digital Owl of the Cyber Realm
Posts and Opinions are my own
774 Followers 948 FollowingSecurity research @GroupIB . Interested in #APT research and targeted #malware. @GroupIB_TI
Opinions are my own not of my employer.