GoldFinder

Description

(Microsoft) Another tool written in Go, GoldFinder was most likely used as a custom HTTP tracer tool that logs the route or hops that a packet takes to reach a hardcoded C2 server. When launched, the malware issues an HTTP request for a hardcoded IP address (e.g., hxxps://185[.]225[.]69[.]69/) and logs the HTTP response to a plaintext log file (e.g., loglog.txt created in the present working directory).

Names

Name
GoldFinder

Category

Malware

Type

  • Backdoor

Information

Mitre Attack

Other Information

Uuid

6cb4acd2-9c86-4cf4-a037-4107feac5704

Last Card Change

2022-12-30