PULSE NAME
Mylobot Continues Global Infections
WHITE AlienVault 2018-11-14 Modified: 2019-05-07
2812
IOCs
HIGH VOLUME
CenturyLink Threat Research Labs has been tracking the Mylobot botnet, a sophisticated malware family that is categorized as a downloader. What makes Mylobot dangerous is its ability to download and execute any type of payload after it infects a host. This means at any time it could download any other type of malware the attacker desires. A detailed walkthrough and reverse engineering analysis of Mylobot was first reported in June by Deep Instinct. During the time we have been monitoring Mylobot we have observed it downloading the Khalesi malware as a second stage to infected hosts. Kaspersky Lab reports that the information stealing Khalesi malware is one of the top downloaded malware families in 2018.
Indicators of Compromise (4 / 2812 total)
All domain FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 4ca8ef5d00bde49659ca97faf2a2a47445e6a3e82c151f18f0923392826d5af0 2018-11-14
FileHash-SHA256 9f930b106c1d1ddcb832a86e14c0474d3d2e6c22b0d3408fccfa8347d7f4e7c4 2018-11-14
FileHash-SHA256 b7245ed896cd4199b410a326e1295aafb3e23c3311d301b1cdaf964cf7c008d9 2018-11-14
FileHash-SHA256 f6ac0ea45ccf7faded0fe03c13f356b82d03a9fc13a89194935ad75b8186275c 2018-11-14