mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update cyclops_blink.yml
This commit is contained in:
@@ -5,7 +5,7 @@ date: '2022-04-07'
|
||||
author: Teoderick Contreras, Splunk
|
||||
description: Leverage searches that allow you to detect and investigate unusual activities
|
||||
that might relate to the cyclopsblink malware including firewall modification, spawning more process, botnet c2 communication, defense evasion and etc.
|
||||
Cyclops Blink is a Linux ELF executable compiled for 32-bit PowerPC architecture that has targeted several network devices.
|
||||
Cyclops Blink is a Linux ELF executable compiled for 32-bit x86 and PowerPC architecture that has targeted several network devices.
|
||||
The complete list of targeted devices is unknown at this time, but WatchGuard FireBox has specifically been listed as a target.
|
||||
The modular malware consists of core components and modules that are deployed as child processes using the Linux API fork.
|
||||
At this point, four modules have been identified that download and upload files, gather system information and contain updating mechanisms for the malware itself.
|
||||
@@ -23,4 +23,4 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
usecase: Advanced Threat Detection
|
||||
|
||||
Reference in New Issue
Block a user