Moose Malware Uses Linux Routers For Social Network Fraud
Posted: 02 Jun 2015, 18:18
From this 15-05-27 article at DarkReading.com
This gives me the impression that the malicious traffic would be coming from a single IP address. Why she would state that and then not provide the IP address I don't know. Based on the description, simply blocking traffic to/from that IP address would defeat the malware.
S.
the article wrote:There is no peer-to-peer protocol, [Moose] uses a hardcoded IP address instead of DNS for C&C, and even though the backdoor is listening on the Internet on port 10073 to offer its proxy service, only IP addresses in a whitelist are allowed to connect. Another reason for our lack of success is the lack of security tools ecosystems (like Anti-Virus) on embedded systems. Finally, the hosting providers where the C&C are located were relunctant to cooperate, which didn’t help.
This gives me the impression that the malicious traffic would be coming from a single IP address. Why she would state that and then not provide the IP address I don't know. Based on the description, simply blocking traffic to/from that IP address would defeat the malware.
S.