4 ms·
Very interesting! A tutorial to check if kimwolf is running on your network would be nice
by ConorSheehan1 9mo ago
Very interesting! A tutorial to check if kimwolf is running on your network would be nice
- nubinetwork 9mo agoBased on the article, try looking for android devices with adb running on the network.
- thenthenthen 9mo agoThis article[0] includes a link to a online checker: https://synthient.com/check https://synthient.com/check Have not tested it myself ymmv. [0] https://synthient.com/blog/a-broken-system-fueling-botnets https://synthient.com/blog/a-broken-system-fueling-botnets
- nubinetwork 9mo agoIt only references a database of publicly scanned IPs, it won't help you if the device is behind a nat router.
- HappyPanacea 9mo agoDoes someone know if the port must be 5555 for this botnet?
- tgv 9mo agoIt's the Android debugger port, and it's used for infection, but the article doesn't exclude other methods nor mentions ports used by the malware.
- pamcake 9mo agoNot exactly the answer but if you have one of the affected mentioned devices it should be listening on TCP port 5555. You can do a port scan for that. nmap -Pn 192.168.0.0/16 -p 5555 Replace netmask as appropriate. Now that it's publicly known I guess it's possible that they will close the door post-infection to avoid detecton. And it won't detect any other devices it's spread further to. If you have a cheapo Android-based TV box or stick like the ones mentioned, throw it out or reflash it with Armbian after forensics. I'm sure there are HN readers out there who have one of these. They were very popular a couple of years back.
- BloodyIron 9mo agoWell the first thing to check is, do you own and operate any of these janky Android "TV" boxes sold by companies nobody has heard of? If yes? Then there's probably your answer.