Yay .. the MV for the other single just dropped. Love! Happy Anniversary, Day6!
DAY6(데이식스) "꿈의 버스" (Dream Bus)
https://www.youtube.com/watch?v=hZ6pts6e8dI
🚨 #Cybersecurity Alert: DreamBus Botnet is back and exploiting a new vulnerability in RocketMQ servers (CVE-2023-33246) for remote code execution. Juniper Threat Labs reports multiple attacks installing the DreamBus malware.
Key Points:
Vulnerability Disclosure:
Exploitation by DreamBus Botnet:
Attack Timeline:
Reconnaissance and Malicious Activities:
Technical Details:
Malware Capabilities:
Implications:
The article provides a comprehensive look into the DreamBus botnet's resurgence, its exploitation of the RocketMQ vulnerability, and the technical intricacies involved in the attacks.
Indicators of Compromise (IoCs) for DreamBus Botnet:
IP and Servers:
92[.]204.243.155: Download Serverru6r4inkaf4thlgflg4iqs5mhqwqubols5qagspvya4whp3dgbvmyhad.onion: .onion Download and Control ServerScripts and Miners:
1d0c3e35324273ffeb434f929f834b59dcc6cdd24e9204abd32cc0abefd9f047: Bash script downloader1c49d7da416474135cd35a9166f2de0f8775f21a27cd47d28be48a2ce580d58d: XMRig MinerDreamBus Bot Hashes:
601a2ff4a7244ed41dda1c1fc71b10d3cfefa34e2ef8ba71598f41f73c031443153b0d0916bd3150c5d4ab3e14688140b34fdd34caac725533adef8f4ab621e2e71caf456b73dade7c65662ab5cf55e02963ee3f2bfb47e5cffc1b36c0844b4d9f740c9042a7c3c03181d315d47986674c50c2fca956915318d7ca9d2a086b7f371319cd17a1ab2d3fb2c79685c3814dc24d67ced3e2f7663806e8960ff9334c21a9f094eb65256e0ea2adb5b43a85f5abfbfdf45f855daab3eb6749c6e694170a8779a427aba59a66338d85e28f007c6109c23d6b0a6bd4b251bf0f543a029fIn May 2023, a vulnerability affecting RocketMQ servers (CVE-2023-33246), which allows remote code execution, was publicly disclosed. In a recent blog post, Juniper Threat Labs provided a detailed explanation of
Zscaler’s research team recently spotted a Linux-based malware family, tracked as DreamBus botnet, targeting Linux servers. Researchers at Zscaler’s ThreatLabZ research team recently analyzed a Linux-based malware family, tracked as DreamBus Botnet, which is a variant of SystemdMiner. The bot is composed of a series of Executable and Linkable Format (ELF) binaries and Unix shell scripts. The […]