Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Block Dark Utilities C2-as-a-Service cryptojacking service #444

Closed
summercms opened this issue Aug 30, 2022 · 2 comments
Closed

Block Dark Utilities C2-as-a-Service cryptojacking service #444

summercms opened this issue Aug 30, 2022 · 2 comments

Comments

@summercms
Copy link

summercms commented Aug 30, 2022

Website with example

https://github.com/Cisco-Talos/IOCs/blob/main/2022/08/dark-utilities.txt

Domain causing the CPU spike

dark-utilities.xyz
dark-utilities.pw
dark-utilities.me
ijfcm7bu6ocerxsfq56ka3dtdanunyp4ytwk745b54agtravj2wr2qqd.onion.pet
bafybeidravcab5p3acvthxtwosm4rfpl4yypwwm52s7sazgxaezfzn5xn4.ipfs.infura-ipfs.io

Screenshot

Dark Utilities emerged in early 2022 and offers full-blown C2 capabilities both on the Tor network and on the clear web. It hosts payloads in the Interplanetary File System (IPFS - https://ipfs.tech/) - a decentralized network system for storing and sharing data.

The administrative panel comes with multiple modules for various types of attack, including distributed denial-of-service (DDoS) and cryptojacking.

@smed79
Copy link
Collaborator

smed79 commented Aug 31, 2022

Do you have an example of cryptojacked site or where is embed unbeknownst to the user?

@summercms
Copy link
Author

@smed79 @hoshsadiq

You can read the technical paper here: http://blog.talosintelligence.com/2022/08/dark-utilities.html

  • Software has over around 3,000 active hackers using it.
  • It's using Monero to crypto jack.
  • Endpoints that you can block are as follows:

Normal domains

dark-utilities.xyz
dark-utilities.pw
dark-utilities.me

Tor domains

ijfcm7bu6ocerxsfq56ka3dtdanunyp4ytwk745b54agtravj2wr2qqd.onion.pet

IPFS domains

bafybeidravcab5p3acvthxtwosm4rfpl4yypwwm52s7sazgxaezfzn5xn4.ipfs.infura-ipfs.io

@smed79 smed79 closed this as completed in 5362cb5 Sep 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants