bigbigfox
PhD student in cybersecurity.
Mastodon: cyberfox@infosec.exchange
中文就是我的故乡
- #Serisbot sbot.geek serisontop.dyn serisbot.geek A and/or TXT records for C2 IPs. It seems that this botnet is still alive
- Chinese national charged with foreign interference offence in Canberra www.afp.gov.au/news-centre/...
- This botnet has been using soooo many domains. 213[.]209[.]143[.]44, 107[.]150[.]0[.]18 www.virustotal.com/gui/ip-addre... www.virustotal.com/gui/ip-addre... #botnet #DDoS #Mirai
- domain "nerd[.]parody" has two A records. It seems innocent. But if we reverse these two IPs to 154[.]81[.]156[.]35 and 154[.]81[.]156[.]54, there will be two malicious IPs (virustotal.com/gui/ip-addre...) (virustotal.com/gui/ip-addre...) #botnet #DDoS (first query detected on 2025-04-18)
- What is this botnet doing? malicious IP: 213.209.143.44 VirusTotal: virustotal.com/gui/ip-addre... Two OpenNIC domain, and two domains registered via *.anondns.net (as screenshot shows). #DDoS #Botnet
- Reposted by bigbigfox[Not loaded yet]