원본 언어로만 콘텐츠 제공
class="post-article">

Gootkit2

Gootkit2 (GootLoader) bankacilık trojanı+loader. Akademik site dead drop. RIBA/UK lure. SEO poisoning.

위협 프로필
유형 Loader
프로그래밍 언어JavaScript/Node.js
C2 프로토콜HTTP
첫 감지2014
대상 Finans/UK/Almanya
목적 / 기능
  • Credential Stealer+Loader

C2 서버 1

주소 포트 프로토콜 상태 작업
hex.su
443 HTTPS INACTIVE

⚠ C2 주소는 위협 인텔리전스 및 방어 목적으로만 공유됩니다. 이 주소에 대한 무단 접근은 범죄입니다.

연구 보고서 (1)

Kritik

Gootkit 2 -- RIBA İnşaat Sözleşmesi UK Lure, Stanford + Astron Dead Drop, hex.su C2 | Kritik

Gootkit2 RIBA UK bina sozlesmesi lure. Stanford + astron-soc.in dead drop. hex.su C2. Rotspider APT.

보고서 읽기 →