GoldFinder
Description
(Microsoft) Another tool written in Go, GoldFinder was most likely used as a custom HTTP tracer tool that logs the route or hops that a packet takes to reach a hardcoded C2 server. When launched, the malware issues an HTTP request for a hardcoded IP address (e.g., hxxps://185[.]225[.]69[.]69/) and logs the HTTP response to a plaintext log file (e.g., loglog.txt created in the present working directory).
Names
Name |
---|
GoldFinder |
Category
Malware
Type
- Backdoor
Information
Mitre Attack
Other Information
Uuid
6cb4acd2-9c86-4cf4-a037-4107feac5704
Last Card Change
2022-12-30