SquirtDanger

First seen
2018-02-01 00:00:00
Malware type
botnet
Family
Malware family
Profile updated
2026-07-07 15:21:08

Context

According to PaloAlto, SquirtDanger is a commodity botnet malware family that comes equipped with a number of characteristics and capabilities. The malware is written in C# (C Sharp) and has multiple layers of embedded code. Once run on the system, it will persist via a scheduled task that is set to run every minute. SquirtDanger uses raw TCP connections to a remote command and control (C2) server for network communications.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Squirtdanger (report)
  • researchcenter.paloaltonetworks.com — Unit42 Squirtdanger Swiss Army Knife Malware Veteran Malware Author Thebottle (report)

External references