{"id":17753,"date":"2020-02-17T10:52:22","date_gmt":"2020-02-17T18:52:22","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2020\/02\/17\/news-11486\/"},"modified":"2020-02-17T10:52:22","modified_gmt":"2020-02-17T18:52:22","slug":"news-11486","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/02\/17\/news-11486\/","title":{"rendered":"New paper: LokiBot: dissecting the C&amp;C panel deployments"},"content":{"rendered":"<p>First advertised as an information stealer and keylogger when it appeared in underground forums in 2015, LokiBot has added various capabilities over the years and has affected many users worldwide.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"framed\" style=\"display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/www.virusbulletin.com\/files\/4415\/8141\/4602\/Lokibot-fig1.png\" alt=\"Lokibot-fig1.png\" width=\"699\" height=\"546\" \/><span class=\"centered-caption\">LokiBot C&amp;C panel with CAPTCHA.<\/span><\/p>\n<p>In a new paper (published today in both <a title=\"LokiBot: dissecting the C&amp;C panel deployments\" href=\"https:\/\/www.virusbulletin.com\/virusbulletin\/2020\/02\/lokibot-dissecting-cc-panel-deployments\/\">HTML<\/a> and <a href=\"https:\/\/www.virusbulletin.com\/uploads\/pdf\/magazine\/2020\/202002-LokiBot.pdf\" target=\"_blank\">PDF <\/a>format) researcher Aditya Sood analyses the URL structure of the LokiBot C&amp;C panels and how they have evolved over time, concentrating on the C&amp;C panel entry points.<\/p>\n<p>\u00a0<\/p>\n<p><em>If you have some research you&#8217;d like to share with the security community, we&#8217;d love to hear from you: the<a title=\"Call for papers\" href=\"https:\/\/www.virusbulletin.com\/conference\/vb2020\/call-papers\/\"> call for papers<\/a> for VB2020 (Dublin, 30 Sept to 2 Oct 2020) remains open until 15 March and we are always happy to consider papers <a title=\"Submit a Paper to The Bulletin\" href=\"https:\/\/www.virusbulletin.com\/virusbulletin\/submit-paper-bulletin\/\">for publication<\/a> on the Virus Bulletin website.<\/em><\/p>\n<p>outertext<br \/><a href=\"https:\/\/www.virusbulletin.com\/blog\/2020\/02\/new-paper-lokibot-dissecting-cc-panel-deployments\/\" target=\"bwo\" >https:\/\/www.virusbulletin.com\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.virusbulletin.com\/files\/4415\/8141\/4602\/Lokibot-fig1.png\"\/><br \/>                                 First advertised as an information stealer and keylogger when it appeared in underground forums in 2015, LokiBot has added various capabilities over the years and has affected many users worldwide. In a new paper researcher Aditya Sood analyses the URL structure of the LokiBot C&amp;C panels and how they have evolved over time.                <\/p>\n<p>                 <a href=\"https:\/\/www.virusbulletin.com\/blog\/2020\/02\/new-paper-lokibot-dissecting-cc-panel-deployments\/\">Read more<\/a>                                <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[23177,10378,23176],"tags":[],"class_list":["post-17753","post","type-post","status-publish","format-standard","hentry","category-magazine","category-security","category-virusbulletin"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17753","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17753"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17753\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17753"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17753"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17753"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}