SYMBOLCOMMON_NAMEaka. SYNONYMS
elf.mrblack (Back to overview)

MrBlack

aka: AESDDoS, Dofloo

MrBlack, first identified in May 2014 by Russian security firm Dr. Web, is a botnet that targets Linux OS and is designed to conduct distributed denial-of-service (DDoS) attacks. In May 2015, Incapsula clients suffered a large-scale DDoS attack which the company attributed to network traffic generated by tens of thousands of small office/home office (SOHO) routers infected with MrBlack. This massive botnet spans over 109 countries, especially in Thailand and Brazil.

MrBlack scans for and infects routers that have not had their default login credentials changed and that allow remote access to HTTP and SSH via port 80 and port 22, respectively. One of the most impacted router brands is Ubiquiti, a U.S.-based firm that provides bulk network hub solutions for internet service providers to lease to their customers. Once a vulnerable router is compromised and MrBlack is injected into the system, a remote server is contacted and system information from the device is transmitted. This allows the host server to receive commands in order to perform different types of DDoS attacks, download and execute files, and terminate processes.

References
2021-12-19BleepingComputerBleepingComputer
Exposed Docker APIs Abused by DDoS, Cryptojacking Botnet Malware
MrBlack
2017-11-17LloydLabsLloyd Davies
[Part 1] - Analysing the New Linux/AES.DDoS IoT Malware
MrBlack
2015-12-03360 Internet Security CenterYa Liu
Automatically Classifying Unknown Bots by The REGISTER Messages
MrBlack XOR DDoS DarkShell
2015-09-01Virus BulletinJaromír Hořejší, Peter Kálnai
DDOS TROJAN: A MALICIOUS CONCEPT THAT CONQUERED THE ELF FORMAT
Bashlite MrBlack XOR DDoS BillGates
2014-05-15Dr.WebDr. Web
DDoS Trojans attack Linux
MrBlack

There is no Yara-Signature yet.