Thứ Tư, Tháng Hai 8, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

New version of Botnet XLoader uses probability theory to hide its C&C servers

2 Tháng Sáu, 2022
in Tech
0
New version of Botnet XLoader uses probability theory to hide its C&C servers
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

XLoader Botnet

According to the latest research, an enhanced version of malware XLoader has been found to take a probability-based approach to camouflage its command and control (C&C) infrastructure, according to the latest research.

Israeli cybersecurity firm Check Point said: “Now it’s become a smokescreen to separate the wheat from the pods and discover the real C&C servers among the thousands of legitimate domains used by Xloader as a smokescreen. make it significantly more difficult.”

First discovered in October 2020, XLLoader is a successor to Formbook and a cross-platform credential stealer capable of stealing login credentials from web browsers, capturing keystrokes and screenshots, and execute arbitrary commands and payloads.

More recently, the ongoing geopolitical conflict between Russia and Ukraine has proven to be a hotbed for the distribution of XLLoader with phishing emails aimed at high-ranking government officials in Ukraine.

The latest findings from Check Point build on an earlier report by Zscaler in January 2022, which revealed the inner workings of the communication protocol and encode ‘s C&C (or C2) network malwarenote the use of dummy servers to disguise the legitimate server and avoid system malware analysis.

XLoader Botnet

“C2 communication occurs with decoy domains and real C2 servers, including sending stolen data from the victim,” the researchers explain. “Therefore, there is a possibility that a backup C2 could be hidden in decoy C2 domains and used as a backup communication channel in the event that the primary C2 domain is taken down.”

The stealth comes from the fact that the domain name for the real C&C server is hidden along with a configuration containing 64 fake domains, from which 16 are randomly selected, then replacing two of those 16. with a fake C&C address and a valid one.

What has changed in newer versions of XLLoader is that after selecting 16 decoy domains from the configuration, the first eight domains are overwritten with new random values ​​before each communication cycle while taking steps to ignore the real domain.

Additionally, XLLoader 2.5 replaces the three domains in the generated list with two decoy server addresses and the actual C&C server domain. The ultimate goal is to prevent detection by the real C&C server, based on the latency between hits to the domains.

The fact that malware authors used principles of probability theory to gain access to a legitimate server demonstrates once again how threat actors are constantly adjusting their tactics to continue their attacks. continue their nefarious goals.

“These modifications achieve two goals at once: each node in the botnet maintains a stable retyping rate while fooling automated scripts and preventing retyping,” the Check Point researchers said. discover real C&C servers”.

.

Previous Post

How to create a bootable usb with the latest DLC Boot 2022 very fast 1 click

Next Post

The most beautiful kitchen island models in 2022

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
The most beautiful kitchen island models in 2022

The most beautiful kitchen island models in 2022

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem