MetaStealer traffic, new DGAs and analyzing the “tracker” backdoor DGA with AI (opens in new tab)
By: Jason Reaves and Joshua PlattIn this blog we simply want to highlight a few new additions to what appears to be related to MetaStealer, one is a new wordlist based DGA used by MetaStealer. We also want to highlight that MetaStealer’s proxies or ‘gates’ don’t actually care what domain gets used as it’s just a config item; they simply pass on the traffic to another server.We also want to highlight a task that was seen delivered to a few bots which is related to MetaStealer but appears to st...
Read the original article