Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
A dozen US web servers are spreading 10 malware families, Necurs link suspected
#1
Quote:Researchers have uncovered over a dozen servers, unusually registered in the United States, which are hosting ten different malware families spread through phishing campaigns potentially tied to the Necurs botnet.
 
On Thursday, researchers from Bromium said they have monitored scams connected to this infrastructure during the May 2018 to March 2019 time period.
 
Five families of banking Trojans -- Dridex, Gootkit, IcedID, Nymaim, and Trickbot -- two ransomware variants, Gandcrab and Hermes, as well as three information stealers, Fareit, Neutrino, and Azorult, were all found on the servers.

It is unusual for such malware to be found on infrastructure hosted in the US, given the country's law enforcement agencies are generally quick off the mark to seize and take down malicious infrastructure when informed of its existence.

One of the servers belongs to a single autonomous system and is a so-called "bulletproof" hosting service, which generally turns a blind eye to the subject material hosted, whether or not it is malicious or illegal. Another 11 servers involved belong to a company which is based in Nevada and sells virtual private server (VPS) hosting.

SOURCE: https://www.zdnet.com/article/a-dozen-us...suspected/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Thunderbird Supernova 115.11.0
Thunderbird Supern...harlan4096 — 09:41
Google Chrome 125.0.6422.60/.61
Google Chrome 125....harlan4096 — 09:35
AdGuard for Mac 2.14.1
AdGuard for Mac 2....harlan4096 — 09:21
AdGuard VPN for Windows 2.3.1
AdGuard VPN for Wi...harlan4096 — 09:20
Vivaldi Stable 6.7 (3329.31)
Vivaldi Stable 6.7...harlan4096 — 09:15

[-]
Birthdays
Today's Birthdays
avatar (47)contjrat
Upcoming Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
avatar (37)axuben
avatar (38)ihijudu
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (38)GregoryRog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>