Golang Bot Starts Targeting WordPress Websites
Tags
attack-pattern: | Data Domains - T1583.001 Domains - T1584.001 Malware - T1587.001 Malware - T1588.001 Software - T1592.002 Web Service - T1481 Vulnerabilities - T1588.006 Web Service - T1102 |
Common Information
Type | Value |
---|---|
UUID | 1280203c-fcef-4efe-b241-1a56f068a7c8 |
Fingerprint | f4a13f1399358e19 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | March 24, 2021, midnight |
Added to db | Sept. 26, 2022, 9:34 a.m. |
Last updated | Sept. 4, 2024, 5 a.m. |
Headline | Golang Bot Starts Targeting WordPress Websites |
Title | Golang Bot Starts Targeting WordPress Websites |
Detected Hints/Tags/Attributes | 32/1/16 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 2 | travelfornamewalking.ga |
|
Details | Domain | 1 | lovegreenpencils.ga |
|
Details | Domain | 1 | linetoadsactive.ga |
|
Details | Domain | 1 | lowerthenskyactive.ga |
|
Details | Domain | 1 | transandfiestas.ga |
|
Details | Domain | 1 | strongcapitalads.ga |
|
Details | Domain | 1 | talkingaboutfirms.ga |
|
Details | Domain | 1 | daryinformtrand.com |
|
Details | Domain | 1 | dontkinhooot.tw |
|
Details | Domain | 1 | declarebusinessgroup.ga |
|
Details | File | 1 | cc4.json |
|
Details | sha256 | 1 | d492dd3608741c9128eb5a8dfc1ae688b63bfe8daf9ecaa3ca784aa654a92ef8 |
|
Details | sha256 | 1 | b8aa5b2d7a9febcbca31a6efd3327319c2efe4857e082e65f1333caf65b4f3be |
|
Details | sha256 | 1 | 4277afc7be775bdad3b7c1be0e793401f79136c120cb667c00b55bec2d23a07e |
|
Details | sha256 | 1 | 15117f2d1783063f26c58d1c0ea755d952facbf12e7fd8efc077a0a2780e5906 |
|
Details | IPv4 | 1 | 195.2.71.173 |