䯥䵗鼺䰀鑤
325 posts



Our latest blog, a new DDoS botnet Fodcha, which is big, and very active attacking various targets, some of the victims are the world top popular domains(top 10 companies) blog.netlab.360.com/fodcha-a-new-d…

Our latest blog about the recent Ukraine and Russia DDoS attacks, takeaway: botnets are actively been recruited for attacks on both sides and Russia actually receives more DDoS than Ukraine does. blog.netlab.360.com/some_details_o…







Same ip address...☝️ That's one hell of a lucky coincidence, don' t you think? Ref: Mirai_ptea_Rimasuta variant is exploiting a new RUIJIE router 0 day to spread blog.netlab.360.com/rimasuta-sprea… Cc: @xuy1202 @TuringAlex @360Netlab






1) file-file-host4[.]com <-- #Arkei sample : tria.ge/211116-jr5besc… 2) 185.231.70[.]207:24867 <-- #Redline sample. 3) #Tofsee sample: 185.215.113[.]71:416 185.244.41[.]146:416 185.7.214[.]171:416 185.7.214[.]210:416 185.7.214[.]212:416 91.243.44[.]11:416 4) Not found on VT.











