timb-machine / timb-machine/linux-malware
[Intel]: https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 1.2k
- Forks
- 95
- PR merge metrics
- No merged PRs in 30d
Description
Area
Malware reports
Parent threat
Command and Control, Defense Evasion, Persistence, Discovery
Finding
https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
Industry reference
attack:T1102:Web Service
attack:T1071.001:Web Protocols
attack:T1573.001:Symmetric Cryptography
attack:T1573:Encrypted Traffic
attack:T1053.003:Cron
attack:T1033:System Owner/User Discovery
attack:T1016:System Network Configuration Discovery
attack:T1070.004:File Deletion
uses:RedirectionToNull
delivery:NPM
Malware reference
SysJoker
wltm
Actor reference
No response
Component
Linux
Scenario
No response
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the linked Intezer report and the SysJoker and wltm references in this issue. Review how this repository records malware reports, then verify that the Linux component and listed ATT&CK references are represented consistently; the issue does not name a file or test.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100