Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
Named LiquorBot, the botnet was first spotted in May 2019... The most interesting update was, however, recorded in October. The company says the LiquorBot code was expanded with a module that attempted to mine the Monero (XMR) cryptocurrency on infected devices.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
About the only novel detail about LiquorBot is the fact that the malware is a version of the Mirai strain rewritten in the Go programming language
The second command does the same, but also executes the file using “sh -c”.
Uses the following exploits to infect routers and smart devices (mostly routers): CVE-2015-2051, CVE-2016-1555, CVE-2016-6277, CVE-2018-17173, CVE-2017-6884, CVE-2018-10562, CVE-2017-6077, CVE-2017-6334, CVE-2016-5679, CVE-2018-9285, CVE-2013-3568, CVE-2019-12780
Like Mirai, LiquorBot obfuscates its strings and stores them into a map. Each time an entry dis accessed, the string is decrypted by adding the vadlue 0x51 to each character.
Upon execution, the bot relaunches itself, while attempting to disguise the new process as the sshd daemon.
Propagation through SSH brute-forcing and exploitation of unpatched vulnerabilities in select router models ... Most versions use SSH brute-forcing as the sole propagation method. The samples from July 24th include SSH brute-forcing, by using a hardcoded list of 82 username/password combinations
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IoT botnet primarily infecting home routers and other smart devices via known exploits and SSH brute-forcing. It is controlled through a web-based C2 and was later updated with a Monero-mining module, despite the limited mining capability of infected SOHO routers.
A Go-based Mirai-inspired IoT botnet that propagates via SSH brute-forcing and exploitation of unpatched router vulnerabilities, communicates with C2 infrastructure, downloads and executes payloads, and includes Monero cryptocurrency mining functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.