{"id":2782,"date":"2025-05-24T05:09:54","date_gmt":"2025-05-24T05:09:54","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=2782"},"modified":"2025-05-24T05:09:55","modified_gmt":"2025-05-24T05:09:55","slug":"danabot-analyzing-a-fallen-empire","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=2782","title":{"rendered":"Danabot: Analyzing a fallen empire"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>As introduced by the US Division of Justice \u2013 the FBI and US DoD\u2019s Protection Prison Investigative Service (DCIS) have managed to disrupt the infrastructure of the infamous infostealer, Danabot. ESET is likely one of the many cybersecurity corporations to take part on this long-term endeavor, changing into concerned again in 2018. Our contribution included offering technical analyses of the malware and its backend infrastructure, in addition to figuring out Danabot\u2019s C&amp;C servers. The joint takedown effort additionally led to the identification of people liable for Danabot improvement, gross sales, administration, and extra. ESET took half within the effort alongside with Amazon, CrowdStrike, Flashpoint, Google, Intel471, PayPal, Proofpoint, Staff Cymru, Zscaler, Germany\u2019s Bundeskriminalamt, the Netherlands&#8217; Nationwide Police, and the Australian Federal Police.<\/p>\n<p>These regulation enforcement operations had been performed below <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.operation-endgame.com\/\" target=\"_blank\" rel=\"noopener\">Operation Endgame<\/a> \u2013 an ongoing international initiative aimed toward figuring out, dismantling, and prosecuting cybercriminal networks. Coordinated by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/operation-endgame-strikes-again-ransomware-kill-chain-broken-its-source\" target=\"_blank\" rel=\"noopener\">Europol and Eurojust<\/a>, the operation efficiently took down crucial infrastructure used to deploy ransomware by means of malicious software program.<\/p>\n<p>Since Danabot has largely been disrupted, we&#8217;ll use this chance to share our insights into the workings of this malware-as-a-service (MaaS) operation, masking the options used within the newest variations of the malware, the authors\u2019 enterprise mannequin, and an outline of the toolset provided to associates. Aside from exfiltrating delicate information, we now have noticed that Danabot can also be used to ship additional malware \u2013 together with ransomware \u2013 to an already compromised system.<\/p>\n<blockquote>\n<p><strong>Key factors of the blogpost:<\/strong><\/p>\n<ul>\n<li>ESET Analysis has been monitoring Danabot\u2019s exercise since 2018 as a part of a world effort that resulted in a serious disruption of the malware\u2019s infrastructure.<\/li>\n<li>Whereas primarily developed as an infostealer and banking trojan, Danabot additionally has been used to distribute extra malware, together with ransomware.<\/li>\n<li>Danabot\u2019s authors promote their toolset by means of underground boards and supply varied rental choices to potential associates.<\/li>\n<li>The everyday toolset offered by Danabot\u2019s authors to their associates contains an administration panel software, a backconnect software for real-time management of bots, and a proxy server software that relays the communication between the bots and the precise C&amp;C server.<\/li>\n<li>Associates can select from varied choices to generate new Danabot builds, and it\u2019s their accountability to distribute these builds by means of their very own campaigns.<\/li>\n<\/ul>\n<\/blockquote>\n<h2>Background<\/h2>\n<p>Danabot, which belongs to a gaggle of infostealer and\/or banking malware households coded within the Delphi programming language, gained prominence in 2018 by being utilized in a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/danabot-new-banking-trojan-surfaces-down-under-0\" target=\"_blank\" rel=\"noopener\">spam marketing campaign<\/a> focusing on Australian customers. Since then, Danabot has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2018\/09\/21\/danabot-targeting-europe-adds-new-features\/\" target=\"_blank\" rel=\"noopener\">expanded<\/a> to different markets by means of varied campaigns, undergone a number of main <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2019\/02\/07\/danabot-updated-new-cc-communication\/\">updates<\/a> of its internals and backend infrastructure, and skilled each peaks and downturns in recognition amongst cybercriminals.<\/p>\n<p>All through our monitoring since 2018, ESET has tracked and analyzed a considerable variety of distinct samples and recognized greater than 1,000 distinctive C&amp;C servers. Throughout that interval, ESET analyzed varied Danabot campaigns all around the world, with Poland traditionally being some of the focused nations, as seen in Determine 1.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 1. Worldwide Danabot detections as seen in ESET telemetry since 2018\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-1.png\" alt=\"Figure 1. Worldwide Danabot detections as seen in ESET telemetry since 2018\" width=\"\" height=\"\"\/><figcaption><em>Determine 1. Worldwide Danabot detections as seen in ESET telemetry since 2018<\/em><\/figcaption><\/figure>\n<p>Along with typical cybercrime, Danabot has additionally been utilized in much less typical actions similar to using compromised machines for launching DDoS assaults. For instance, a DDoS assault towards Ukraine\u2019s Ministry of Protection was noticed by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/danabot-launches-ddos-attack-against-ukrainian-ministry-defense\" target=\"_blank\" rel=\"noopener\">Zscaler<\/a> quickly after the Russian invasion of Ukraine. A really related DDoS module to the one utilized in that assault was additionally utilized by a Danabot operator to focus on a Russian website devoted to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.arduino.cc\/\" target=\"_blank\" rel=\"noopener\">Arduino<\/a> improvement. These actions had been in all probability motivated by the affiliate\u2019s personal ambitions and political motivations.<\/p>\n<h2>Danabot group introduction<\/h2>\n<p>The authors of Danabot function as a single group, providing their software for hire to potential associates, who subsequently make use of it for their very own malicious functions by establishing and managing their very own botnets. The authors have even arrange a assist web page on the Tor community with detailed details about the capabilities of their software, as depicted in Determine 2.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 2. Danabot\u2019s features as promoted on its support site\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-2.png\" alt=\"Figure 2. Danabot\u2019s features as promoted on its support site\" width=\"\" height=\"\"\/><figcaption><em>Determine 2. Danabot\u2019s options as promoted on its assist website<\/em><\/figcaption><\/figure>\n<p>To accumulate new prospects, Danabot is ceaselessly promoted in underground boards by the consumer JimmBee, who acts as one of many predominant builders and directors of the Danabot malware and its toolset. One other noteworthy particular person from the Danabot group is a consumer recognized in underground boards as Onix, who coadministers the Danabot infrastructure and can also be liable for gross sales operations.<\/p>\n<h2>Function overview<\/h2>\n<p>Danabot\u2019s authors have developed an enormous number of options to help prospects with their malevolent goals. Probably the most outstanding options provided by Danabot embody:<\/p>\n<ul>\n<li>the power to steal varied information from browsers, mail purchasers, FTP purchasers, and different common software program,<\/li>\n<li>keylogging and display recording,<\/li>\n<li>real-time distant management of the victims\u2019 techniques,<\/li>\n<li>a FileGrabber command, generally used for stealing cryptocurrency wallets,<\/li>\n<li>assist for <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Zeus_(malware)\" target=\"_blank\" rel=\"noopener\">Zeus-like<\/a> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2014\/10\/23\/evolution-webinject\/\">webinjects<\/a> and type grabbing, and<\/li>\n<li>arbitrary payload add and execution.<\/li>\n<\/ul>\n<p>Apart from using its stealing capabilities, we now have noticed a wide range of payloads being distributed by means of Danabot through the years, similar to:<\/p>\n<ul>\n<li>SystemBC,<\/li>\n<li>Rescoms,<\/li>\n<li>Ursnif,<\/li>\n<li>Smokeloader,<\/li>\n<li>Zloader,<\/li>\n<li>Lumma Stealer,<\/li>\n<li>RecordBreaker,<\/li>\n<li>Latrodectus, and<\/li>\n<li>NetSupportManager distant administration software.<\/li>\n<\/ul>\n<p>Moreover, we now have encountered cases of Danabot getting used to obtain ransomware onto already compromised techniques. We are able to identify LockBit, Buran, Disaster, and a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2019\/danabot-demands-a-ransom-payment\/\" target=\"_blank\" rel=\"noopener\">NonRansomware variant<\/a> being pushed on a number of events.<\/p>\n<p>Danabot\u2019s means to obtain and execute arbitrary payloads will not be the one characteristic used to distribute extra malware. Danabot was additionally noticed getting used as a software at hand off management of the botnet to a ransomware operator, as reported by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/MsftSecIntel\/status\/1730383711437283757\" target=\"_blank\" rel=\"noopener\">Microsoft Menace Intelligence<\/a> in late 2023.<\/p>\n<h2>Distribution strategies<\/h2>\n<p>All through its existence, in line with our monitoring, Danabot has been a software of selection for a lot of cybercriminals and every of them has used totally different technique of distribution. Danabot\u2019s builders even partnered with the authors of a number of malware cryptors and loaders, and provided particular pricing for a distribution bundle to their prospects, serving to them with the method. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/details\/win.matanbuchus\" target=\"_blank\" rel=\"noopener\">Matanbuchus<\/a> is an instance of such a promoted loader.<\/p>\n<p>Over time, we now have seen all kinds of distribution strategies being utilized by Danabot associates, together with:<\/p>\n<ul>\n<li>quite a few variants of e mail spam campaigns,<\/li>\n<li>different malware similar to Smokeloader, DarkGate, and Matanbuchus, and<\/li>\n<li>misuse of Google Adverts.<\/li>\n<\/ul>\n<p>Lately, out of all distribution mechanisms we noticed, the misuse of Google Adverts to show seemingly related, however really malicious, web sites among the many sponsored hyperlinks in Google search outcomes stands out as some of the outstanding strategies to lure victims into downloading Danabot. The preferred ploy is packing the malware with professional software program and providing such a package deal by means of bogus software program websites (Determine 3) or web sites falsely promising customers to assist them discover unclaimed funds (Determine 4).<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 3. Fake Advanced IP Scanner website leading to Danabot compromise\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-3.png\" alt=\"Figure 3. Fake Advanced IP Scanner website leading to Danabot compromise\" width=\"\" height=\"\"\/><figcaption><em>Determine 3. Pretend Superior IP Scanner web site resulting in Danabot compromise<\/em><\/figcaption><\/figure>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 4. Fake unclaimed money search site\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-4.png\" alt=\"Figure 4. Fake unclaimed money search site\" width=\"\" height=\"\"\/><figcaption><em>Determine 4. Pretend unclaimed cash search website<\/em><\/figcaption><\/figure>\n<p>The newest addition to those social engineering methods: misleading web sites providing options for fabricated laptop points, whose solely goal is to lure the sufferer into execution of a malicious command secretly inserted into the consumer\u2019s clipboard. An instance of such an internet site resulting in downloading of Danabot in Determine 5.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 5. Website luring the victim into execution of malicious command stored in the user\u2019s clipboard\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-5.png\" alt=\"Figure 5. Website luring the victim into execution of malicious command\" width=\"\" height=\"\"\/><figcaption><em>Determine 5. Web site luring the sufferer into execution of malicious command saved within the consumer\u2019s clipboard<\/em><\/figcaption><\/figure>\n<h2>Infrastructure<\/h2>\n<h3>Overview<\/h3>\n<p>Initially, Danabot\u2019s authors relied on a single centralized server to handle all bots\u2019 connections and all associates\u2019 information, similar to command configurations and information collected from their victims. This centralized method definitely had a detrimental influence on that server\u2019s efficiency and was extra susceptible to potential disruptions. That is in all probability one of many the reason why we noticed a shift within the enterprise and infrastructure fashions in newer variations. Along with renting locations on their very own infrastructure, Danabot\u2019s authors now supply set up of a personal server, as marketed on their assist website, to be operated by the affiliate (Determine 6).<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 6. Basic offering on Danabot\u2019s support site\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-6.png\" alt=\"Figure 6. Basic offering on Danabot\u2019s support site\" width=\"\" height=\"\"\/><figcaption><em>Determine 6. Fundamental providing on Danabot\u2019s assist website<\/em><\/figcaption><\/figure>\n<p>The rental choices, as provided by means of an underground discussion board in July 2023, are illustrated in Determine\u00a07.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 7. Price list for potential Danabot customers\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-7.png\" alt=\"Figure 7. Price list for potential Danabot customers\" width=\"\" height=\"\"\/><figcaption><em>Determine 7. Value checklist for potential Danabot prospects<\/em><\/figcaption><\/figure>\n<p>It&#8217;s value mentioning that, based mostly on our monitoring, the rental of an account on the shared infrastructure managed by Danabot\u2019s authors appears to be the most well-liked selection for risk actors.<\/p>\n<p>When associates buy a rental of one of many choices, they&#8217;re given instruments and credentials to hook up with the C&amp;C server and handle their very own botnet by means of an administration panel. Within the following sections, we cowl the totally different components of the everyday toolset.<\/p>\n<h3>C&amp;C server software<\/h3>\n<p>The standalone server software comes within the type of a DLL file and acts because the mind of the botnet. It&#8217;s put in on a Home windows server and makes use of a MySQL database for information administration. Bots connect with this server to transmit stolen information and obtain instructions issued by associates. Associates connect with this server through the administration panel software to handle their botnet. This C&amp;C server software is offered for native set up just for associates paying for the upper tier private server possibility. Associates who select to function their botnets on Danabot\u2019s infrastructure as a substitute are given connection particulars to the C&amp;C server already arrange there, and don&#8217;t have to host their very own C&amp;C server.<\/p>\n<h3>Administration panel<\/h3>\n<p>The administration panel, displayed in Determine 8, is within the type of a GUI software, and represents crucial software from the botnet operator\u2019s perspective. It permits the affiliate to hook up with the C&amp;C server and carry out duties similar to:<\/p>\n<ul>\n<li>handle bots and retrieve statistics of the botnet,<\/li>\n<li>concern varied instructions and superior configuration for bots,<\/li>\n<li>conveniently view and export information gathered from victims,<\/li>\n<li>handle the notification system and arrange alerts on occasions triggered by bots,<\/li>\n<li>generate new Danabot builds, and<\/li>\n<li>arrange a series of proxy servers for communication between the bots and the C&amp;C server.<\/li>\n<\/ul>\n<p>We offer extra particulars and examples of essentially the most fascinating capabilities of the administration panel within the upcoming sections.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 8. Administration panel overview\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-8.png\" alt=\"Figure 8. Administration panel overview\" width=\"\" height=\"\"\/><figcaption><em>Determine 8. Administration panel overview<\/em><\/figcaption><\/figure>\n<h3>Backconnect software<\/h3>\n<p>One other essential software for administration is the standalone utility that permits botnet operators to remotely connect with and management their on-line bots. Out there actions for distant management, as seen within the software, are illustrated in Determine 9. In all probability essentially the most fascinating options for cybercriminals are the power to see and management the sufferer\u2019s laptop through a distant desktop connection and to carry out reconnaissance of the file system utilizing the built-in file supervisor.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 9. Features of the backconnect utility\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-9.png\" alt=\"Figure 9. Features of the backconnect utility\" width=\"\" height=\"\"\/><figcaption><em>Determine 9. Options of the backconnect utility<\/em><\/figcaption><\/figure>\n<h3>Proxy server software<\/h3>\n<p>Bots sometimes don&#8217;t connect with the principle C&amp;C server immediately, however relatively use a series of proxies to relay the site visitors and conceal the placement of the true backend C&amp;C. To facilitate this technique, Danabot\u2019s authors present a proxy server software, accessible for each Home windows and Linux techniques. Determine 10 exhibits the utilization message from the Linux model of this easy proxy server software. Apart from utilizing proxies, bots will be configured to speak with the server by means of the Tor community in case all proxy chains grow to be unavailable. An elective downloadable Tor module is then used for such communication.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 10. Usage message from the Linux version of the proxy server application\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-10.png\" alt=\"Figure 10. Usage message from the Linux version of the proxy server application\" width=\"\" height=\"\"\/><figcaption><em>Determine 10. Utilization message from the Linux model of the proxy server software<\/em><\/figcaption><\/figure>\n<p>Associates additionally ceaselessly make the most of this proxy server software as an middleman between their administration panel and the C&amp;C server to additional improve their anonymity. When the whole lot is put collectively, the everyday infrastructure could look as proven in Determine 11.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 11. Example of typical Danabot infrastructure\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-11.png\" alt=\"Figure 11. Example of typical Danabot infrastructure\" width=\"\" height=\"\"\/><figcaption><em>Determine 11. Instance of typical Danabot infrastructure<\/em><\/figcaption><\/figure>\n<h2>Internals<\/h2>\n<h3>Communication<\/h3>\n<p>Danabot employs its personal proprietary C&amp;C communication protocol with its information encrypted utilizing AES-256. Generated AES session keys, distinctive for each message, are then additional encrypted utilizing RSA key pairs, securing the entire communication. It\u2019s value mentioning that there have been a number of updates to the communication protocol and the packet construction over time.<\/p>\n<p>The present packet information construction of the everyday command, earlier than it&#8217;s encrypted, appears to be like as proven in Desk 1 . We wish to level out that many of the fields are solely used through the first request within the communication loop to authenticate the bot, and are left unset within the subsequent instructions.<\/p>\n<p style=\"break-after: avoid; text-align: center;\"><em>Desk 1. Packet construction utilized in Danabot communication<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"85\"><strong>Offset<\/strong><\/td>\n<td width=\"95\"><strong>Dimension\u00a0(bytes)<\/strong><\/td>\n<td width=\"463\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x00<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Dimension of the packet.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x08<\/span><\/td>\n<td width=\"463\">Random worth.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x0C<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x08<\/span><\/td>\n<td width=\"463\">Sum of the 2 values above.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x14<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Account ID used to distinguish associates within the earlier variations. This discipline comprises a random worth in newer variations.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x18<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Command.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x1C<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Subcommand.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x20<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Danabot model.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x24<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\"><span style=\"font-family: courier new, courier, monospace;\">IsUserAdmin<\/span> flag.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x28<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Course of integrity stage.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x2C<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">OS structure x86\/x64.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x30<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Encoded Home windows model.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x34<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Time zone bias as a DWORD worth.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x38<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Unknown bytes; set to <span style=\"font-family: courier new, courier, monospace;\">0<\/span> within the present variations.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x3C<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Tor energetic flag.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x40<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x04<\/span><\/td>\n<td width=\"463\">Unknown bytes; set to <span style=\"font-family: courier new, courier, monospace;\">0<\/span> within the present variations.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x44<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x18<\/span><\/td>\n<td width=\"463\">Padding null bytes.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x5C<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x21<\/span><\/td>\n<td width=\"463\">Bot ID Delphi string (a string preceded by a size byte).<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x7D<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x21<\/span><\/td>\n<td width=\"463\">Construct ID hardcoded Delphi string.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0x9E<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x21<\/span><\/td>\n<td width=\"463\">MD5 checksum of concatenated Account ID, Bot ID, and Construct ID strings.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0xBF<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0x29<\/span><\/td>\n<td width=\"463\">Command dependent string utilized in some instructions complemented by its CRC-32 and a string dimension.<\/td>\n<\/tr>\n<tr>\n<td width=\"85\"><span style=\"font-family: courier new, courier, monospace;\">0xE8<\/span><\/td>\n<td width=\"95\"><span style=\"font-family: courier new, courier, monospace;\">0xDF<\/span><\/td>\n<td width=\"463\">Padding null bytes.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The most recent variations of Danabot additionally add, to additional disguise its communication, a random quantity of seemingly junk bytes to the top of the packet construction earlier than it&#8217;s encrypted. It\u2019s value mentioning that Danabot authors don&#8217;t at all times observe the very best coding practices and the addition of this random variety of bytes was performed by resizing of the unique reminiscence buffer allotted to carry the packet construction as a substitute of clearing or initializing this newly acquired area. This led to unintentionally together with surrounding reminiscence areas of the method into the info packet being despatched from the bot to the server and, extra importantly, vice versa. These appended reminiscence areas captured and decrypted from the server-to-bot communication generally contained fascinating info from the server\u2019s course of reminiscence and gave researchers invaluable perception into Danabot\u2019s infrastructure and its customers. This bug was launched in 2022 and was fastened within the newest variations of Danabot in February 2025.<\/p>\n<p>Additional particulars in regards to the communication and its encryption had been already coated by varied <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/new-year-new-version-danabot\" target=\"_blank\" rel=\"noopener\">researchers<\/a>, and we received\u2019t dive into it extra on this blogpost.<\/p>\n<h3>Builds<\/h3>\n<p>Botnet operators have a number of choices for producing new Danabot builds to distribute to their victims. To the very best of our information, whereas the operator could configure the construct course of and desired output by means of the administration panel software, the construct course of itself is carried out on the Danabot authors\u2019 servers. After producing the chosen construct, the operator receives obtain hyperlinks for the builds and turns into liable for their distribution in a marketing campaign.<\/p>\n<p>Determine 12 exhibits an instance of a construct configuration window and accessible choices, such because the C&amp;C server checklist to be configured within the last binary file, varied obfuscation strategies, construct bitness, and so on.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 12. Build options menu from the Administration panel application\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-12.png\" alt=\"Figure 12. Build options menu from the Administration panel application\" width=\"\" height=\"\"\/><figcaption><em>Determine 12. Construct choices menu from the Administration panel software<\/em><\/figcaption><\/figure>\n<p>Danabot presently provides 4 primary payload varieties, described in Desk 2.<\/p>\n<p style=\"break-after: avoid; text-align: center;\"><em>Desk 2. Variants of obtainable builds<\/em><\/p>\n<h3><span style=\"font-size: medium; font-weight: 400;\"><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"155\"><strong>Payload sort<\/strong><\/td>\n<td width=\"466\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"155\"><span style=\"font-family: courier new, courier, monospace;\">Important.dll<\/span><\/td>\n<td width=\"466\">Generates a sole predominant part within the type of a DLL to be distributed and loaded through <span style=\"font-family: courier new, courier, monospace;\">rundll32.exe<\/span> or <span style=\"font-family: courier new, courier, monospace;\">regsvr32.exe<\/span>.<\/td>\n<\/tr>\n<tr>\n<td width=\"155\"><span style=\"font-family: courier new, courier, monospace;\">Important.exe<\/span><\/td>\n<td width=\"466\">Generates a loader within the type of an EXE that will comprise the abovementioned predominant part DLL or obtain it from one of many configured C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"155\"><span style=\"font-family: courier new, courier, monospace;\">Drop.exe<\/span><\/td>\n<td width=\"466\">Generates a dropper with an embedded predominant part DLL to be dropped to disk.<\/td>\n<\/tr>\n<tr>\n<td width=\"155\"><span style=\"font-family: courier new, courier, monospace;\">Drop.msi<\/span><\/td>\n<td width=\"466\">Generates an MSI package deal with an embedded predominant part DLL to be loaded.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/span><\/h3>\n<h3>Instructions configuration<\/h3>\n<p>A botnet operator can concern a complicated configuration to the bots by means of the administration panel. Bots are then ordered to carry out varied instructions in line with the directions obtained. Determine 13 exhibits an instance of such a command configuration.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 13. Dynamic configuration options for the FileGrabber command\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-13.png\" alt=\"Figure 13. Dynamic configuration options for the FileGrabber command\" width=\"\" height=\"\"\/><figcaption><em>Determine 13. Dynamic configuration choices for the <\/em><span style=\"font-family: courier new, courier, monospace;\">FileGrabber<\/span> <em>command<\/em><\/figcaption><\/figure>\n<p>Desk 3 lists the accessible instructions that may be issued. Every process has its personal particular choices to additional accommodate the operator\u2019s wants.<\/p>\n<p style=\"break-after: avoid; text-align: center;\"><em>Desk 3. Out there instructions<\/em><\/p>\n<h3><span style=\"font-size: medium; font-weight: 400;\"><\/p>\n<table style=\"height: 1072px;\" border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><strong>Command<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"490\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Video<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Report a video of the chosen software or web site.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">KeyLogger<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Seize keystrokes from the chosen software.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">PostFilter<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Seize info from sure web sites\u2019 types.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">WebInject<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Permit Zeus-like webinjects on sure loaded web sites to change their perform.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Redirect<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Permit redirection of sure URLs.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Block<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Block entry to configured URLs.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Screens<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Take screenshots of a specific software or web site at sure intervals.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Alerts<\/span><\/td>\n<td style=\"height: 68px;\" width=\"490\">Permit notifications to be despatched to a specific Jabber account on a configurable occasion.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Uninstall<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Uninstall the bot from the system.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">UAC<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Present assist for privilege escalation.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">FileGrabber<\/span><\/td>\n<td style=\"height: 68px;\" width=\"490\">Permit sure information to be uploaded to the C&amp;C if discovered on the sufferer\u2019s onerous disk.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">TorActive<\/span><\/td>\n<td style=\"height: 68px;\" width=\"490\">Allow loading of a Tor module and permit connection through the Tor community if all C&amp;C servers are inaccessible.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Stealer<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Allow\/disable the stealer performance and set its replace interval.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">TimeOut<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Set interval for the bot to contact its C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Set up<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Configure the bot\u2019s set up on the system and its persistence.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">Exclusion<\/span><\/td>\n<td style=\"height: 68px;\" width=\"490\">Set exclusions in Home windows Defender or Home windows Firewall for a specific course of.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">ConfigSave<\/span><\/td>\n<td style=\"height: 50px;\" width=\"476\">Save the bot\u2019s configuration earlier than its termination.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">HideProcess<\/span><\/td>\n<td style=\"height: 50px;\" width=\"490\">Conceal the bot\u2019s course of.<\/td>\n<\/tr>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"131\"><span style=\"font-family: courier new, courier, monospace;\">CoreProtect<\/span><\/td>\n<td style=\"height: 50px;\" width=\"476\">Permit the principle part to be injected into a further course of.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/span><\/h3>\n<h3>Further payloads<\/h3>\n<p>Danabot additionally gives the aptitude to obtain and execute additional executable information. This characteristic permits the botnet operator to configure the set up of extra malware to the compromised system, as talked about earlier. Determine 14 exhibits accessible choices for this characteristic within the administration panel software.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 14. Options for an additional payload configuration\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/danabot\/figure-14.png\" alt=\"Figure 14. Options for an additional payload configuration\" width=\"\" height=\"\"\/><figcaption><em>Determine 14. Choices for a further payload configuration<\/em><\/figcaption><\/figure>\n<h2>Conclusion<\/h2>\n<p>Danabot is a large-scale MaaS operation distributing a wide selection of instruments for the malware associates\u2019 disposal. Our investigation of this infostealer, which began in 2018, resulted within the evaluation of Danabot\u2019s toolset offered on this blogpost. The efforts of the authorities and several other cybersecurity corporations, ESET included, led to the disruption of the malware\u2019s infrastructure. It stays to be seen whether or not Danabot can get better from the takedown. The blow will, nevertheless, absolutely be felt, since regulation enforcement managed to unmask a number of people concerned within the malware\u2019s operations.<\/p>\n<blockquote>\n<div><em>For any inquiries about our analysis printed on WeLiveSecurity, please contact us at <a rel=\"nofollow\" target=\"_blank\" style=\"background-color: #f4f4f4;\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/danabot-analyzing-fallen-empire\/mailto:threatintel@eset.com?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=eset-research&amp;utm_term=en\">threatintel@eset.com<\/a>.\u00a0<\/em><\/div>\n<div><em>ESET Analysis provides personal APT intelligence stories and information feeds. For any inquiries about this service, go to the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=danabot-analyzing-fallen-empire&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\">ESET Menace Intelligence<\/a> web page.<\/em><\/div>\n<\/blockquote>\n<h2>IoCs<\/h2>\n<h3>Information<\/h3>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"179\"><strong>SHA-1<\/strong><\/td>\n<td width=\"113\"><strong>Filename<\/strong><\/td>\n<td width=\"151\"><strong>Detection<\/strong><\/td>\n<td width=\"199\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">6D361CD9ADBF1630AF7B<wbr\/>323584168E0CBD9315FB<\/span><\/td>\n<td width=\"113\">N\/A<\/td>\n<td width=\"151\">Win32\/Spy.Danabot.X<\/td>\n<td width=\"199\">Loader of the principle part (model 4006).<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">A7475753CB865AEC8DC4<wbr\/>A6CEA27F2AA594EE25E8<\/span><\/td>\n<td width=\"113\">N\/A<\/td>\n<td width=\"151\">Win32\/Spy.Danabot.O<\/td>\n<td width=\"199\">Important part (model 4006).<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">787EAB54714F76099EC3<wbr\/>50E029154ADFD5EDF079<\/span><\/td>\n<td width=\"113\">N\/A<\/td>\n<td width=\"151\">Win32\/Spy.Danabot.AC<\/td>\n<td width=\"199\">Dropper part (model 3272).<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">17B78AD12B1AE1C037C5<wbr\/>D39DBE7AA0E7DE4EC809<\/span><\/td>\n<td width=\"113\"><span style=\"font-family: courier new, courier, monospace;\">1c0e7316.<wbr\/>exe<\/span><\/td>\n<td width=\"151\">MSIL\/Kryptik.AMBV<\/td>\n<td width=\"198\">Lockbit payload (variant Black) distributed by Danabot.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Community<\/h3>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"148\"><strong>IP<\/strong><\/td>\n<td width=\"111\"><strong>Area<\/strong><\/td>\n<td width=\"102\"><strong>Internet hosting supplier<\/strong><\/td>\n<td width=\"93\"><strong>First seen<\/strong><\/td>\n<td width=\"190\"><strong>Particulars<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"148\"><span style=\"font-family: courier new, courier, monospace;\">212.18.104[.]245<\/span><\/td>\n<td width=\"111\">N\/A<\/td>\n<td width=\"102\">GLOBAL CONNECTIVITY SOLUTIONS LLP<\/td>\n<td width=\"93\">2025\u201103\u201125<\/td>\n<td width=\"190\">Danabot proxy C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td width=\"148\"><span style=\"font-family: courier new, courier, monospace;\">212.18.104[.]246<\/span><\/td>\n<td width=\"111\">N\/A<\/td>\n<td width=\"102\">GLOBAL CONNECTIVITY SOLUTIONS LLP<\/td>\n<td width=\"93\">2025\u201103\u201125<\/td>\n<td width=\"190\">Danabot proxy C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td width=\"148\"><span style=\"font-family: courier new, courier, monospace;\">34.16.215[.]110<\/span><\/td>\n<td width=\"111\">N\/A<\/td>\n<td width=\"102\">Google LLC<\/td>\n<td width=\"93\">2024\u201110\u201110<\/td>\n<td width=\"190\">Danabot proxy C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td width=\"148\"><span style=\"font-family: courier new, courier, monospace;\">34.65.116[.]208<\/span><\/td>\n<td width=\"111\">N\/A<\/td>\n<td width=\"102\">Google LLC<\/td>\n<td width=\"93\">2024\u201110\u201110<\/td>\n<td width=\"190\">Danabot proxy C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td width=\"148\"><span style=\"font-family: courier new, courier, monospace;\">34.168.100[.]35<\/span><\/td>\n<td width=\"111\">N\/A<\/td>\n<td width=\"102\">Google LLC<\/td>\n<td width=\"93\">2024\u201111\u201127<\/td>\n<td width=\"190\">Danabot proxy C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td width=\"148\">N\/A<\/td>\n<td width=\"111\"><span style=\"font-family: courier new, courier, monospace;\">advanced-ip-scanned.com<\/span><\/td>\n<td width=\"102\">N\/A<\/td>\n<td width=\"93\">2023\u201108\u201121<\/td>\n<td width=\"190\">Misleading web site utilized in Danabot distribution<\/td>\n<\/tr>\n<tr>\n<td width=\"148\">N\/A<\/td>\n<td width=\"111\"><span style=\"font-family: courier new, courier, monospace;\">gfind.org<\/span><\/td>\n<td width=\"102\">N\/A<\/td>\n<td width=\"93\">2022\u201106\u201115<\/td>\n<td width=\"190\">Misleading web site utilized in Danabot distribution<\/td>\n<\/tr>\n<tr>\n<td width=\"148\">N\/A<\/td>\n<td width=\"111\"><span style=\"font-family: courier new, courier, monospace;\">mic-tests.com<\/span><\/td>\n<td width=\"102\">N\/A<\/td>\n<td width=\"93\">2024\u201112\u201107<\/td>\n<td width=\"190\">Misleading web site utilized in Danabot distribution<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>MITRE ATT&amp;CK methods<\/h2>\n<p style=\"page-break-after: avoid;\"><em>This desk was constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/resources\/versions\/\" target=\"_blank\" rel=\"noopener\">model 17<\/a> of the MITRE ATT&amp;CK framework<strong>.<\/strong><\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"113\"><strong>Tactic<\/strong><\/td>\n<td width=\"113\"><strong>ID<\/strong><\/td>\n<td width=\"151\"><strong>Title<\/strong><\/td>\n<td width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td rowspan=\"5\" width=\"113\"><strong>Useful resource Growth<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1583\/003\" target=\"_blank\" rel=\"noopener\">T1583.003<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure: Digital Non-public Server<\/td>\n<td width=\"265\">Danabot operators use VPS of their infrastructure.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1583\/004\" target=\"_blank\" rel=\"noopener\">T1583.004<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure: Server<\/td>\n<td width=\"265\">Danabot operators purchase a number of servers for C&amp;C communication.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1587\/001\" target=\"_blank\" rel=\"noopener\">T1587.001<\/a><\/td>\n<td width=\"151\">Develop Capabilities: Malware<\/td>\n<td width=\"265\">Danabot authors have developed customized malware instruments.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1608\/001\" target=\"_blank\" rel=\"noopener\">T1608.001<\/a><\/td>\n<td width=\"151\">Stage Capabilities: Add Malware<\/td>\n<td width=\"265\">Danabot operators add different malware to their infrastructure for additional spreading.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1583\/008\" target=\"_blank\" rel=\"noopener\">T1583.008<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure: Malvertising<\/td>\n<td width=\"265\">Malvertising is a well-liked technique of Danabot distribution.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Preliminary Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1566\/001\" target=\"_blank\" rel=\"noopener\">T1566.001<\/a><\/td>\n<td width=\"151\">Phishing: Spearphishing Attachment<\/td>\n<td width=\"265\">Phishing is a standard technique used for distribution.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Execution<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1106\" target=\"_blank\" rel=\"noopener\">T1106<\/a><\/td>\n<td width=\"151\">Native API<\/td>\n<td width=\"265\">Dynamic Home windows API decision is utilized by Danabot.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1204\/001\" target=\"_blank\" rel=\"noopener\">T1204.001<\/a><\/td>\n<td width=\"151\">Consumer Execution: Malicious Hyperlink<\/td>\n<td width=\"265\">Luring customers into downloading Danabot through a malicious hyperlink is a well-liked distribution selection.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1204\/002\" target=\"_blank\" rel=\"noopener\">T1204.002<\/a><\/td>\n<td width=\"151\">Consumer Execution: Malicious File<\/td>\n<td width=\"265\">Danabot is usually distributed as a file to be opened by the consumer.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Privilege Escalation<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1548\/002\" target=\"_blank\" rel=\"noopener\">T1548.002<\/a><\/td>\n<td width=\"151\">Abuse Elevation Management Mechanism: Bypass Consumer Account Management<\/td>\n<td width=\"265\">A number of strategies are utilized by Danabot to bypass Consumer Account Management.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"6\" width=\"113\"><strong>Protection Evasion<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1027\/007\" target=\"_blank\" rel=\"noopener\">T1027.007<\/a><\/td>\n<td width=\"151\">Obfuscated Information or Info: Dynamic API Decision<\/td>\n<td width=\"265\">Danabot makes use of hashing for dynamic API decision.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1055\/001\" target=\"_blank\" rel=\"noopener\">T1055.001<\/a><\/td>\n<td width=\"151\">Course of Injection: Dynamic-link Library Injection<\/td>\n<td width=\"265\">Danabot has the power to inject itself into different processes.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1218\/007\" target=\"_blank\" rel=\"noopener\">T1218.007<\/a><\/td>\n<td width=\"151\">System Binary Proxy Execution: Msiexec<\/td>\n<td width=\"265\">An MSI package deal is likely one of the potential distribution strategies.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1218\/010\" target=\"_blank\" rel=\"noopener\">T1218.010<\/a><\/td>\n<td width=\"151\">System Binary Proxy Execution: Regsvr32<\/td>\n<td width=\"265\"><span style=\"font-family: courier new, courier, monospace;\">regsvr32.exe<\/span> can be utilized to execute the principle Danabot module.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1218\/011\" target=\"_blank\" rel=\"noopener\">T1218.011<\/a><\/td>\n<td width=\"151\">System Binary Proxy Execution: Rundll32<\/td>\n<td width=\"265\"><span style=\"font-family: courier new, courier, monospace;\">rundll32.exe<\/span> can be utilized to execute the principle Danabot module.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1656\" target=\"_blank\" rel=\"noopener\">T1656<\/a><\/td>\n<td width=\"151\">Impersonation<\/td>\n<td width=\"265\">Danabot makes use of impersonation in its phishing campaigns.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Credential Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1555\/003\" target=\"_blank\" rel=\"noopener\">T1555.003<\/a><\/td>\n<td width=\"151\">Credentials from Password Shops: Credentials from Net Browsers<\/td>\n<td width=\"265\">Danabot has the power to steal varied information from browsers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1539\" target=\"_blank\" rel=\"noopener\">T1539<\/a><\/td>\n<td width=\"151\">Steal Net Session Cookie<\/td>\n<td width=\"265\">Danabot can steal cookies.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Discovery<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1010\" target=\"_blank\" rel=\"noopener\">T1010<\/a><\/td>\n<td width=\"151\">Software Window Discovery<\/td>\n<td width=\"265\">Danabot will be configured to steal information based mostly on the energetic window.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1217\" target=\"_blank\" rel=\"noopener\">T1217<\/a><\/td>\n<td width=\"151\">Browser Info Discovery<\/td>\n<td width=\"265\">Information, similar to shopping historical past, will be gathered by Danabot.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1083\" target=\"_blank\" rel=\"noopener\">T1083<\/a><\/td>\n<td width=\"151\">File and Listing Discovery<\/td>\n<td width=\"265\">Danabot will be configured to assemble sure information from the compromised file system.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1057\" target=\"_blank\" rel=\"noopener\">T1057<\/a><\/td>\n<td width=\"151\">Course of Discovery<\/td>\n<td width=\"265\">Danabot can enumerate operating processes on a compromised system.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Lateral Motion<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1021\/001\" target=\"_blank\" rel=\"noopener\">T1021.001<\/a><\/td>\n<td width=\"151\">Distant Providers: Distant Desktop Protocol<\/td>\n<td width=\"265\">Danabot operators can use the distant desktop module to entry compromised techniques.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1021\/005\" target=\"_blank\" rel=\"noopener\">T1021.005<\/a><\/td>\n<td width=\"151\">Distant Providers: VNC<\/td>\n<td width=\"265\">VNC is likely one of the supported options for controlling a compromised system.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"9\" width=\"113\"><strong>Assortment<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1056\/001\" target=\"_blank\" rel=\"noopener\">T1056.001<\/a><\/td>\n<td width=\"151\">Enter Seize: Keylogging<\/td>\n<td width=\"265\">Keylogging is considered one of Danabot\u2019s options.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1560\/002\" target=\"_blank\" rel=\"noopener\">T1560.002<\/a><\/td>\n<td width=\"151\">Archive Collected Information: Archive through Library<\/td>\n<td width=\"265\">Danabot can use zlib and ZIP to compress collected information.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1560\/003\" target=\"_blank\" rel=\"noopener\">T1560.003<\/a><\/td>\n<td width=\"151\">Archive Collected Information: Archive through Customized Technique<\/td>\n<td width=\"265\">Collected information is additional encrypted utilizing AES and RSA cyphers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1119\" target=\"_blank\" rel=\"noopener\">T1119<\/a><\/td>\n<td width=\"151\">Automated Assortment<\/td>\n<td width=\"265\">Danabot will be configured to gather varied information routinely.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1185\/\" target=\"_blank\" rel=\"noopener\">T1185<\/a><\/td>\n<td width=\"151\">Browser Session Hijacking<\/td>\n<td width=\"265\">Danabot can carry out AitB assaults through webinjects.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1115\" target=\"_blank\" rel=\"noopener\">T1115<\/a><\/td>\n<td width=\"151\">Clipboard Information<\/td>\n<td width=\"265\">Danabot can acquire info saved within the clipboard.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1005\" target=\"_blank\" rel=\"noopener\">T1005<\/a><\/td>\n<td width=\"151\">Information from Native System<\/td>\n<td width=\"265\">Danabot will be configured to seek for delicate information on an area file system.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1113\" target=\"_blank\" rel=\"noopener\">T1113<\/a><\/td>\n<td width=\"151\">Display screen Seize<\/td>\n<td width=\"265\">Danabot will be configured to seize screenshots of functions and internet pages.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1125\" target=\"_blank\" rel=\"noopener\">T1125<\/a><\/td>\n<td width=\"151\">Video Seize<\/td>\n<td width=\"265\">Danabot can seize video from the compromised system.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"9\" width=\"113\"><strong>Command and Management<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1132\/001\" target=\"_blank\" rel=\"noopener\">T1132.001<\/a><\/td>\n<td width=\"151\">Information Encoding: Normal Encoding<\/td>\n<td width=\"265\">Visitors between bot and C&amp;C server is compressed utilizing ZIP and zlib.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1001\/001\" target=\"_blank\" rel=\"noopener\">T1001.001<\/a><\/td>\n<td width=\"151\">Information Obfuscation: Junk Information<\/td>\n<td width=\"265\">Junk bytes are added to information to be despatched between bot and C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1573\/001\" target=\"_blank\" rel=\"noopener\">T1573.001<\/a><\/td>\n<td width=\"151\">Encrypted Channel: Symmetric Cryptography<\/td>\n<td width=\"265\">AES-256 is used as one of many encryption strategies of C&amp;C communication.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1573\/002\" target=\"_blank\" rel=\"noopener\">T1573.002<\/a><\/td>\n<td width=\"151\">Encrypted Channel: Uneven Cryptography<\/td>\n<td width=\"265\">RSA is used as one of many encryption strategies of C&amp;C communication.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1008\" target=\"_blank\" rel=\"noopener\">T1008<\/a><\/td>\n<td width=\"151\">Fallback Channels<\/td>\n<td width=\"265\">The Tor module can be utilized as a fallback channel in case all common C&amp;C servers should not responding.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1095\" target=\"_blank\" rel=\"noopener\">T1095<\/a><\/td>\n<td width=\"151\">Non-Software Layer Protocol<\/td>\n<td width=\"265\">Danabot makes use of its personal customized TCP protocol for communication.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1571\" target=\"_blank\" rel=\"noopener\">T1571<\/a><\/td>\n<td width=\"151\">Non-Normal Port<\/td>\n<td width=\"265\">Danabot can talk on any port.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1090\/003\" target=\"_blank\" rel=\"noopener\">T1090.003<\/a><\/td>\n<td width=\"151\">Proxy: Multi-hop Proxy<\/td>\n<td width=\"265\">A sequence of proxy servers is used to cover the placement of the true C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1219\" target=\"_blank\" rel=\"noopener\">T1219<\/a><\/td>\n<td width=\"151\">Distant Entry Software program<\/td>\n<td width=\"265\">Danabot has assist for distant entry.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Exfiltration<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1020\" target=\"_blank\" rel=\"noopener\">T1020<\/a><\/td>\n<td width=\"151\">Automated Exfiltration<\/td>\n<td width=\"265\">Danabot will be configured to assemble varied information from a compromised system.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1030\" target=\"_blank\" rel=\"noopener\">T1030<\/a><\/td>\n<td width=\"151\">Information Switch Dimension Limits<\/td>\n<td width=\"265\">Danabot will be configured to keep away from sending massive information from a compromised system.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1041\" target=\"_blank\" rel=\"noopener\">T1041<\/a><\/td>\n<td width=\"151\">Exfiltration Over C2 Channel<\/td>\n<td width=\"265\">Gathered information is exfiltrated by means of commonplace C&amp;C communication.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Impression<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1498\" target=\"_blank\" rel=\"noopener\">T1498<\/a><\/td>\n<td width=\"151\">Community Denial of Service<\/td>\n<td width=\"265\">Danabot employed a module to carry out varied DDoS assaults.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=danabot-analyzing-fallen-empire&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/eti-eset-threat-intelligence.png\" alt=\"\" width=\"915\" height=\"296\"\/><\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>As introduced by the US Division of Justice \u2013 the FBI and US DoD\u2019s Protection Prison Investigative Service (DCIS) have managed to disrupt the infrastructure of the infamous infostealer, Danabot. ESET is likely one of the many cybersecurity corporations to take part on this long-term endeavor, changing into concerned again in 2018. Our contribution included [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2784,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2693,2666,2517,2669],"class_list":["post-2782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-analyzing","tag-danabot","tag-empire","tag-fallen"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2782"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2782\/revisions"}],"predecessor-version":[{"id":2783,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2782\/revisions\/2783"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/2784"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-05 01:36:05 UTC -->