timb-machine / timb-machine/linux-malware

[Intel]: https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/

Open
#95 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

ignore:tag:T1005 ignore:tag:T1027.002 ignore:tag:T1048 ignore:tag:T1057 ignore:tag:T1083 ignore:tag:T1491 ignore:tag:T1567 ignore:tag:T1590 missing:tactics missing:tag:RedirectionToNull missing:tag:T1053.003 missing:tag:T1070.004 missing:tag:T1071.001 missing:tag:T1573
Dominant language
HTML
Stars
1.2k
Forks
95
PR merge metrics
No merged PRs in 30d

Description

Area

Malware reports

Parent threat

Command and Control, Defense Evasion, Persistence, Discovery

Finding

https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/

Industry reference

attack:T1102:Web Service
attack:T1071.001:Web Protocols
attack:T1573.001:Symmetric Cryptography
attack:T1573:Encrypted Traffic
attack:T1053.003:Cron
attack:T1033:System Owner/User Discovery
attack:T1016:System Network Configuration Discovery
attack:T1070.004:File Deletion
uses:RedirectionToNull
delivery:NPM

Malware reference

SysJoker
wltm

Actor reference

No response

Component

Linux

Scenario

No response

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked Intezer report and the SysJoker and wltm references in this issue. Review how this repository records malware reports, then verify that the Linux component and listed ATT&CK references are represented consistently; the issue does not name a file or test.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.