WatchBog
- First seen
- 2019-05-01 00:00:00
- Malware type
- worm, cryptominer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:30:59
Context
According to Intezer, this is a spreader module used by WatchBog. It is a dynamically linked ELF executable, compiled with Cython. C&C adresses are fetched from Pastebin. C&C communication references unique identification keys per victim. It contains a BlueKeep scanner, reporting positively scanned hosts to the C&C server (RC4 encrypted within SSL/TLS). It contains 5 exploits targeting Jira, Exim, Solr, Jenkins and Nexus Repository Manager 3.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Watchbog (report)
- intezer.com — Watching The Watchbog New Bluekeep Scanner And Linux Exploits (report)