Source |
The Hacker News |
Identifiant |
8394707 |
Date de publication |
2023-10-12 16:57:00 (vue: 2023-10-12 12:07:42) |
Titre |
Shellbot utilise des IPS hex ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers (Recyclage) |
Texte |
Les acteurs de la menace derrière Shellbot tirent parti des adresses IP transformés en sa notation hexadécimale pour infiltrer les serveurs Linux SSH mal gérés et déployer les logiciels malveillants DDOS.
"Le flux global reste le même, mais l'URL de téléchargement utilisé par l'acteur de menace pour installer Shellbot est passé d'une adresse IP ordinaire à une valeur hexadécimale", le centre d'intervention d'urgence de sécurité Ahnlab (ASEC)
The threat actors behind ShellBot are leveraging IP addresses transformed into its hexadecimal notation to infiltrate poorly managed Linux SSH servers and deploy the DDoS malware.
"The overall flow remains the same, but the download URL used by the threat actor to install ShellBot has changed from a regular IP address to a hexadecimal value," the AhnLab Security Emergency response Center (ASEC) |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
actor actors address addresses ahnlab are asec attacks behind but center changed ddos deploy detection download emergency evade flow from has hex hexadecimal infiltrate install ips its leveraging linux malware managed notation overall poorly regular remains response same security servers shellbot ssh threat transformed url used uses value |
Tags |
Threat
|
Stories |
|
Move |
|