{"id":37358,"date":"2022-03-16T13:33:59","date_gmt":"2022-03-16T15:33:59","guid":{"rendered":"https:\/\/teknomers.com\/fr\/nouvelle-b1txor20-le-botnet-linux-utilise-le-tunnel-dns-et-exploite-la-faille-log4j\/"},"modified":"2022-03-16T13:34:10","modified_gmt":"2022-03-16T15:34:10","slug":"nouvelle-b1txor20-le-botnet-linux-utilise-le-tunnel-dns-et-exploite-la-faille-log4j","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/nouvelle-b1txor20-le-botnet-linux-utilise-le-tunnel-dns-et-exploite-la-faille-log4j\/","title":{"rendered":"Nouvelle &quot;B1txor20&quot; Le botnet Linux utilise le tunnel DNS et exploite la faille Log4J"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Une porte d\u00e9rob\u00e9e pr\u00e9c\u00e9demment non document\u00e9e a \u00e9t\u00e9 observ\u00e9e ciblant les syst\u00e8mes Linux dans le but de regrouper les machines dans un botnet et d&#8217;agir comme un conduit pour le t\u00e9l\u00e9chargement et l&#8217;installation de rootkits.<\/p>\n<p>L&#8217;\u00e9quipe de s\u00e9curit\u00e9 Netlab de Qihoo 360 l&#8217;a appel\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/blog.netlab.360.com\/b1txor20-use-of-dns-tunneling_en\/\" target=\"_blank\"><strong>B1txor20<\/strong><\/a>  &#8220;sur la base de sa propagation \u00e0 l&#8217;aide du nom de fichier &#8216;b1t&#8217;, de l&#8217;algorithme de chiffrement XOR et de la longueur de cl\u00e9 de l&#8217;algorithme RC4 de 20 octets.&#8221;<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-dm1\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/thehackernews.com\/images\/-_qTKDwXdOnI\/YVHQqMJj85I\/AAAAAAAA4Z4\/RFYOUTwKxUY869ZyUVtFZRcIgVtUMHzAQCLcBGAsYHQ\/s300-e100\/rewind-1-300.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>Observ\u00e9 pour la premi\u00e8re fois se propageant via la vuln\u00e9rabilit\u00e9 Log4j le 9 f\u00e9vrier 2022, le logiciel malveillant exploite une technique appel\u00e9e tunnel DNS pour cr\u00e9er des canaux de communication avec des serveurs de commande et de contr\u00f4le (C2) en encodant les donn\u00e9es dans les requ\u00eates et les r\u00e9ponses DNS.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"R\u00e9seau de zombies Linux\" border=\"0\" data-original-height=\"600\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647444835_324_Nouvelle-quotB1txor20quot-Le-botnet-Linux-utilise-le-tunnel-DNS-et.jpeg\" title=\"R\u00e9seau de zombies Linux\" \/><\/div>\n<p>B1txor20, bien que bogu\u00e9 \u00e0 certains \u00e9gards, prend actuellement en charge la possibilit\u00e9 d&#8217;obtenir un shell, d&#8217;ex\u00e9cuter des commandes arbitraires, d&#8217;installer un rootkit, d&#8217;ouvrir un <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/SOCKS\" target=\"_blank\">Mandataire SOCKS5<\/a>et des fonctions pour t\u00e9l\u00e9charger des informations sensibles vers le serveur C2.<\/p>\n<p>Une fois qu&#8217;une machine est compromise avec succ\u00e8s, le logiciel malveillant utilise le tunnel DNS pour r\u00e9cup\u00e9rer et ex\u00e9cuter les commandes envoy\u00e9es par le serveur.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1647417170_810_Facebook-frappe-dune-amende-de-186-millions-de-dollars-GDPR.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;Le bot envoie les informations sensibles vol\u00e9es, les r\u00e9sultats d&#8217;ex\u00e9cution de la commande et toute autre information devant \u00eatre livr\u00e9e, apr\u00e8s les avoir masqu\u00e9es \u00e0 l&#8217;aide de techniques de codage sp\u00e9cifiques, \u00e0 C2 sous forme de requ\u00eate DNS&#8221;, ont expliqu\u00e9 les chercheurs.<\/p>\n<p>&#8220;Apr\u00e8s avoir re\u00e7u la demande, C2 envoie la charge utile au c\u00f4t\u00e9 Bot en r\u00e9ponse \u00e0 la demande DNS. De cette fa\u00e7on, Bot et C2 parviennent \u00e0 communiquer \u00e0 l&#8217;aide du protocole DNS.&#8221;<\/p>\n<p>Un total de 15 commandes sont impl\u00e9ment\u00e9es, les principales \u00e9tant le t\u00e9l\u00e9chargement d&#8217;informations syst\u00e8me, l&#8217;ex\u00e9cution de commandes syst\u00e8me arbitraires, la lecture et l&#8217;\u00e9criture de fichiers, le d\u00e9marrage et l&#8217;arr\u00eat de services proxy et la cr\u00e9ation de shells invers\u00e9s.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/new-b1txor20-linux-botnet-uses-dns.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Une porte d\u00e9rob\u00e9e pr\u00e9c\u00e9demment non document\u00e9e a \u00e9t\u00e9 observ\u00e9e ciblant les syst\u00e8mes Linux dans le but de regrouper les machines dans un botnet et d&#8217;agir comme un conduit pour le t\u00e9l\u00e9chargement et l&#8217;installation de rootkits. L&#8217;\u00e9quipe de s\u00e9curit\u00e9 Netlab de Qihoo 360 l&#8217;a appel\u00e9 B1txor20 &#8220;sur la base de sa propagation \u00e0 l&#8217;aide du nom [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":37359,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[5464,4168,4158,4165,4161,6016,7727,9048,4157,4159,4171,4170,18088,28860,4167,4160,197,4163,4162,28859,4172,4169,12559,1282,4166,4164],"class_list":["post-37358","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-botnet","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dns","tag-exploite","tag-faille","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-linux","tag-log4j","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelle","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-quotb1txor20quot","tag-securite-informatique","tag-securite-internet","tag-tunnel","tag-utilise","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/37358","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=37358"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/37358\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/37359"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=37358"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=37358"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=37358"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}