So, we published our Fodcha botnet blog two days ago, and the author behind this botnet pushed an updated new sample with the following message inside....🤪
What are the most active P2P based botnets on the internet now, and what are their sizes? We(360netlab) have a tracking system in place for a while and here are some basic information about Pink,Mozi,Hajime,FritzFrog and Panchan.
https://t.co/xfjX4cJ0Xc
New version of Fodcha is bigger and probably better, and attacking various websites like there is no tomorrow. (in previous version, the author left a note saying "Netlab pls leave me alone I surrender", it does not seem so) https://t.co/FMhc4CrNjl
We have noticed that some malware authors pay attention to who downloads their malwares from their downloader servers, aka, they do their security data analysis, if a device other than their own bots connect to their downloader, they DDoS these device IPs.
Our latest blog is about a new Monroe coin mining botnet Orchard, among other things, this botnet uses Satoshi Nakamoto's Bitcoin account transaction information to generate DGA domain names to evade detection. https://t.co/BMaWfu13bT
A new updated fbot have been attacking various big names, it is now one of the most active DDos botnets that we have observed recently, more details can be found from our recently published blog https://t.co/HftSQhZqCW (in Chinese, but google translate will do the trick).
Analysing hundreds of billions of daily DNS queries to produce actionable threat intelligence. #Skidmap and malicious DNS data mining by @360Netlab's Zhang Zaifeng: https://t.co/Ks1om8mxig
#Malware#threatintelligence#Throwback
Here at Quad9, we saw fridgexperts[.]cc skyrocket to our top blocked site with a whopping 30M+ blocks in just under 24 hours--starting ~noon UTC on the 14th!
#Fodcha#DDoS#botnet#DNS
Our latest blog, a new DDoS botnet Fodcha, which is big, and very active attacking various targets, some of the victims are the world top popular domains(top 10 companies) https://t.co/MsKCac1A9q
We observed that ripprbot botnet has instructed its bots to attack targets 147.237.0.0, 147.237.64.0 and 147.237.68.0, all belong to Israeli Government Network
A DDoS attack today against Israel reportedly took down the country's government websites.
@kentikinc observed a DDoS attack focused primarily against AS8867 (Israeli E-Government Project) beginning just before 15:30 UTC (5:30pm local).
https://t.co/cn4NgXoxek
Our latest blog about the recent Ukraine and Russia DDoS attacks, takeaway: botnets are actively been recruited for attacks on both sides and Russia actually receives more DDoS than Ukraine does. https://t.co/KO5UfCroqQ
We also see multiple botnets related DDos targeting Russian websites, for example, https://t.co/4jA5yk54Ls, https://t.co/Hfxi6Ejq2M, https://t.co/ycDM08sh5P, https://t.co/iYXvyI9GOs got attacked about 2 hours ago, and https://t.co/OFm1wJPRCD is being DDosed right now