TF-MAL-elf.b1txor20
📛 Threat Title
Malware family: B1txor20
Description
ThreatFox malware family `elf.b1txor20`. Printable name: B1txor20.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netlab.360.com
In short, B1txor20 is a Backdoor for the Linux platform, which uses DNS Tunnel technology to build C2 communication channels. In addition to the traditional backdoor functions, B1txor20 also has functions such as opening Socket5 proxy and remotely downloading and installing Rootkit.
-
web:cirt.gy
A total of four malware samples were captured with backdoor, SOCKS5 proxy, malware downloading, data theft, arbitrary command execution, and rootkit installing functionality. How it works For communication channels with the command-and-control (C2) server, the B1txor20 malware uses DNS tunneling.
-
web:cymulate.com
B1txor20 can be characterized is using DNS Tunnel to establish C2 channel, support direct connection and relay, while using ZLIB compression, RC4 encryption, BASE64 encodingto protect the traffic of the backdoor Trojan, mainly targets ARM, X64 CPU architecture of the Linux platform.
-
web:malpedia.caad.fkie.fraunhofer.de
B1txor20 is a malware that was discovered by 360 Netlab along others exploiting Log4J. the name is derived from using the file name "b1t", the XOR encrpytion algorithm, and the RC4 algorithm key length of 20 bytes.
-
web:securityaffairs.com
Researchers uncovered a new Linux botnet, tracked as B1txor20 , that exploits the Log4J vulnerability and DNS tunnel. Researchers from Qihoo 360's Netlab have discovered a new backdoor used to infect Linux systems and include them in a botnet tracked as B1txor20 . The malware was first spotted on February 9, 2022, when 360Netlab's honeypot system captured an unknown ELF file that was ...
-
web:socradar.io
Since the Log4J vulnerability was discovered, some other malware showed up and exploited it. B1txor20 seems to take its place among the participants in this malware cluster.
-
web:support.trellix.com
The B1txor20 botnet targets Linux devices and conceals command-and-control communication using DNS tunneling. The malware can perform a range of tasks including arbitrary command execution, exfiltrating sensitive data, downloading additional malware , and installing a SOCKS5 proxy, backdoor, or rootkit.
-
web:www.bleepingcomputer.com
However, what makes the B1txor20 malware stand out is the use of DNS tunneling for communication channels with the command-and-control (C2) server, an old but still reliable technique used by ...
-
web:www.dnssense.com
The malware was named B1txor20 because it spreads carrying the b1t filename, the XOR encryption algorithm, and a key length of 20 bytes in the RC4 algorithm. The malware was discovered spreading via the 'Log4j' vulnerability for the first time on February 9, 2022.
-
web:www.quorumcyber.com
Overview Researchers have discovered a new strain of malware named 'B1txor20' which targets Linux devices using the Log4j vulnerability. Impact The backdoor grants the attacker control over the device, read/write access to the file system, and gives them the ability to proxy traffic through the machine.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.