Tuesday, February 19, 2019

GoScanSSH

GoScanSSH

Community Synonyms
  • None noted at this time.
YARA
  • https://github.com/raw-data/signatures/blob/master/yara/trojan_linux_GoScanSSH.yar
Possible Code
  • https://github.com/ofalk/scanssh

Context of use
  • https://community.ubnt.com/t5/UniFi-Routing-Switching/USG-Pro-High-CPU/td-p/2245371
  • https://searchsecurity.techtarget.com/answer/GoScanSSH-How-does-this-malware-work-and-differ-from-others

Malware References

  • https://threatpost.com/goscanssh-malware-targets-ssh-servers-but-avoids-military-and-gov-systems/130812/
  • https://blog.talosintelligence.com/2018/03/goscanssh-analysis.html
  • https://www.ssh.com/attack/GoScanSSH
  • https://exchange.xforce.ibmcloud.com/collection/GoScanSSH-Malware-078ff9e71f01695186d4a7d10abc1a81/reports
  • https://www.birger.technology/press/emerging-threat-malware-goscanssh-targets-ssh-devices

No comments:

Post a Comment