Blog | G5 Cyber Security

SANS Internet Storm Center

Malware is an ARM binary, indicating that it is targeting devices, not your typical x86 Linux server. The compromised DVR likely happened via an exposed telnet port and a default root password (12345) The malware resides in /dev/cmd.so.so. A number of additional suspect files where located in the /dev directory which we still need to recover / analyze from the test system. The malware is just scanning for vulnerable devices, and the actual exploit will likely come later.”]

Source: https://isc.sans.edu/diary/More+Device+Malware%3A+This+is+why+your+DVR+attacked+my+Synology+Disk+Station+%28and+now+with+Bitcoin+Miner%21%29/17879

Exit mobile version