SysGet
Description
(Palo Alto) All of the Sysget files used in this campaign communicate with a single command and control (C2) server, hosted at biosnews[.]info. Sysget communicates with this server using the HTTP protocol.
Names
Name |
---|
SysGet |
HelloBridge |
Category
Malware
Type
- Backdoor
Information
- https://unit42.paloaltonetworks.com/unit-42-identifies-new-dragonok-backdoor-malware-deployed-against-japanese-targets/
- https://unit42.paloaltonetworks.com/unit42-dragonok-updates-toolset-targets-multiple-geographic-regions/
Malpedia
Alienvault Otx
Other Information
Uuid
421f573b-e4bd-4937-848b-47ff4b06cf5b
Last Card Change
2020-04-23