TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hunting Russian Intelligence “Snake” Malware

4 pointsby antiviralabout 2 years ago

2 comments

stevenlaflabout 2 years ago
I implemented the Suricata rules and found some positive indicators outbound to 4 different Akamai hosted endpoints on port 80. I forwarded the information to Akamai.<p>104.113.24.20 23.38.164.37 23.63.214.115 23.64.100.151<p>However, the detection techniques on the host machine yielded no results (yara, volatility3) nor were any files found at the common locations on disk or in registry mentioned.<p>It does seem odd that virtually all of these are Akamai, leading me to believe it may be a false positive, which was stated as a possibility in the article. If it is and something suddenly stops working I&#x27;ll report back here.
评论 #35978485 未加载
antiviralabout 2 years ago
More info here: <a href="https:&#x2F;&#x2F;www.cbsnews.com&#x2F;news&#x2F;fbi-takes-down-20-year-old-russian-malware-network&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.cbsnews.com&#x2F;news&#x2F;fbi-takes-down-20-year-old-russ...</a>