IoC Extractor

This IoC extractor identifies Indicators of Compromise (IoCs) by matching patterns, without analyzing the context of the surrounding text. Manual Review and Validation of the extracted IoCs are essential before any action is used.

Enemybot: A Look into Keksec’s Latest DDoS Botnet | FortiGuard Labs

DATE : 2022-04-04T07:00:00
SOURCE : fortinet.com

CVE:
cve-2020-17456
cve-2018-10823
cve-2022-27226
cve-2022-25075
cve-2021-44228
cve-2021-41773
cve-2021-42013
cve-2018-20062
cve-2017-18368
cve-2016-6277
cve-2015-2051
cve-2014-9118

FILE_HASH_SHA256:
fec09b614d67e8933e2c09671e042ce74b40048b5f0feed49ba81a2c18d4f473

Url:
http://198.12.116.254/folder/dnsamp.txthttp://198.12.116.254/folder/enemybotarmhttp://198.12.116.254/folder/enemybotarm5http://198.12.116.254/folder/enemybotarm64http://198.12.116.254/folder/enemybotarm7http://198.12.116.254/folder/enemybotbsdhttp://198.12.116.254/folder/enemybotdarwinhttp://198.12.116.254/folder/enemyboti586http://198.12.116.254/folder/enemyboti686http://198.12.116.254/folder/enemybotm68khttp://198.12.116.254/folder/enemybotmipshttp://198.12.116.254/folder/enemybotmpslhttp://198.12.116.254/folder/enemybotppchttp://198.12.116.254/folder/enemybotppc-440fphttp://198.12.116.254/folder/enemybotsh4http://198.12.116.254/folder/enemybotspchttp://198.12.116.254/folder/enemybotx64http://198.12.116.254/folder/enemybotx86http://198.12.116.254/folder/enemybotx64http://198.12.116.254/update.sh