timb-machine / timb-machine/linux-malware

[Intel]: https://www.akamai.com/blog/security-research/kmdsbot-the-attack-and-mine-malware

Open
#586 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

confirmed ignore:tag:T1005 ignore:tag:T1057 ignore:tag:T1070.003 ignore:tag:T1070.004 ignore:tag:T1071.001 ignore:tag:T1083 ignore:tag:T1205 ignore:tag:T1491 ignore:tag:T1552.003 ignore:tag:T1567 ignore:tag:T1573 ignore:tag:T1590
Dominant language
HTML
Stars
1.2k
Forks
95
PR merge metrics
No merged PRs in 30d

Description

Area

Malware reports

Parent threat

Reconnaissance, Initial Access, Defense Evasion, Lateral Movement, Command and Control, Exfiltration, Impact

Finding

https://www.akamai.com/blog/security-research/kmdsbot-the-attack-and-mine-malware

Industry reference

uses:Go
attack:T1133:External Remote Services
attack:T1021:Remote Services
attack:T1021.004:SSH
attack:T1078.001:Default Accounts
attack:T1110:Brute Force
attack:T1095:Non-Application Layer Protocol
attack:T1048:Exfiltration Over Alternative Protocol
attack:T1567:Exfiltration Over Web Service
attack:T1499:Endpoint Denial of Service
attack:T1498:Network Denial of Service
attack:T1496:Resource Hijacking
uses:CrossCompiled

Malware reference

Kmsdbot

Actor reference

No response

Component

Linux, IOT

Scenario

No response

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the linked Akamai Kmsdbot report and reviewing existing malware-report entries in the repository for its expected structure. Use the issue's listed Go, Linux/IoT, and ATT&CK references as the record's source data; done means Kmsdbot is represented consistently with those details.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, linux
Domain
embedded-iot, operating-systems, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.