From 6ec5e586085ccd405e0ef7db2cd20c8022edcd2a Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Fri, 8 Apr 2022 09:49:46 +0200 Subject: [PATCH] Update cyclops_blink.yml --- stories/cyclops_blink.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/stories/cyclops_blink.yml b/stories/cyclops_blink.yml index 829fb20db8..eeecaf6bc0 100644 --- a/stories/cyclops_blink.yml +++ b/stories/cyclops_blink.yml @@ -5,7 +5,7 @@ date: '2022-04-07' author: Teoderick Contreras, Splunk description: Leverage searches that allow you to detect and investigate unusual activities that might relate to the cyclopsblink malware including firewall modification, spawning more process, botnet c2 communication, defense evasion and etc. - Cyclops Blink is a Linux ELF executable compiled for 32-bit PowerPC architecture that has targeted several network devices. + Cyclops Blink is a Linux ELF executable compiled for 32-bit x86 and PowerPC architecture that has targeted several network devices. The complete list of targeted devices is unknown at this time, but WatchGuard FireBox has specifically been listed as a target. The modular malware consists of core components and modules that are deployed as child processes using the Linux API fork. At this point, four modules have been identified that download and upload files, gather system information and contain updating mechanisms for the malware itself. @@ -23,4 +23,4 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - usecase: Advanced Threat Detection \ No newline at end of file + usecase: Advanced Threat Detection