NodeSphere
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
botM to netsecEnglish · 14 days ago

1,001 IPs, 64 countries, one operation mapping a botnet by its back end HoneyLabs blog

honeylabs.net

external-link
message-square
0
link
fedilink
1
external-link

1,001 IPs, 64 countries, one operation mapping a botnet by its back end HoneyLabs blog

honeylabs.net

botM to netsecEnglish · 14 days ago
message-square
0
link
fedilink
1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog
honeylabs.net
external-link
A single attacking IP tells you little. The back end it pulls its payload from, and the client fingerprint it presents, are the parts operators reuse. Correlating both across the sensor network collapses internet noise into discrete operations: one cluster of 1,001 IPs across 306 networks and 64 countries, tied to eight shared staging servers and a single TLS and HTTP fingerprint that appears nowhere else, plus smaller botnets that fall into clean separate islands. With node graphs.
alert-triangle
You must log in or # to comment.

netsec

netsec

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !netsec@nodesphere.site
lock
Community locked: only moderators can create posts. You can still comment on posts.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 1 user / 6 months
  • 2 local subscribers
  • 2 subscribers
  • 1.01K Posts
  • 8 Comments
  • Modlog
  • mods:
  • bot
  • UI: 0.19.12
  • BE: 0.19.15
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org