Smart Lightbulb Using Common IRC port found in NMAP – anything to worry about?

UPDATE:

Looking at the product again, I don’t think this even has built in Wi-Fi (it uses bluetooth for the connection).

I don’t know what I am looking for here in Wireshark, but I added the host 192.168.40.59 and ran it for about 15 sec… Continue reading Smart Lightbulb Using Common IRC port found in NMAP – anything to worry about?

Life After IRC – Your Move, Mozilla!

Last year marked the 30th anniversary of the Internet Relay Chat protocol (IRC) and it is hard to imagine that [Jarkko Oikarinen] could have foreseen the impact his invention would one day have on the world as we know it. How it would turn from a simple, decentralized real-time communication …read more

Continue reading Life After IRC – Your Move, Mozilla!

[SANS ISC] Malicious Network Traffic From /bin/bash

I published the following diary on isc.sans.org: “Malicious Network Traffic From /bin/bash“: One of our readers from Germany sent me a malicious shell script captured by our honeypot running on his Raspberry.  It’s a simple UNIX Bash script that performs a bunch of malicious tasks: Kills existing crypto miner processes

[The post [SANS ISC] Malicious Network Traffic From /bin/bash has been first published on /dev/random]

Continue reading [SANS ISC] Malicious Network Traffic From /bin/bash

[SANS ISC] Windows IRC Bot in the Wild

I published the following diary on isc.sans.org: “Windows IRC Bot in the Wild“: Last weekend, I caught on VirusTotal a trojan disguised as Windows IRC bot. It was detected thanks to my ‘psexec’ hunting rule which looks definitively an interesting keyword (see my previous diary). I detected the first occurrence

[The post [SANS ISC] Windows IRC Bot in the Wild has been first published on /dev/random]

Continue reading [SANS ISC] Windows IRC Bot in the Wild

[SANS ISC] CRIMEB4NK IRC Bot

I published the following diary on isc.sans.org: “CRIMEB4NK IRC Bot“: Yesterday, I got my hands on the source code of an IRC bot written in Perl. Yes, IRC (“Internet Relay Chat”) is still alive! If the chat protocol is less used today to handle communications between malware and their C2 servers, it

[The post [SANS ISC] CRIMEB4NK IRC Bot has been first published on /dev/random]

Continue reading [SANS ISC] CRIMEB4NK IRC Bot