Darkness

From Botnets.fr
(Redirected from Optima)
Jump to navigation Jump to search

(Botnet) Link to the old Wiki page : [1] / Google search: [2]

Darkness
Alias
Group DDoSing
Parent
Sibling
Family
Relations Variants:

Sibling of:
Parent of:
Distribution of:
Campaigns:

Target
Origin
Distribution vector
UserAgent [[user_agent::Mozilla/4.0 (compatible; MSIE 5.0; Windows 2000) Opera 6.03 [en]]]
CCProtocol HTTP (Centralized)
Activity /
Status
Language
Programming language
Operation/Working group

Introduction

Autrement appelé Destination Darkness Outlaw System, c'est un botnet développé pour réaliser des attaques en déni de service distribué. Il est aussi connu sous les alias Optima et Votwup.

Features

Associated images

Checksums / AV databases

Publications

 AuthorEditorYear
A peek inside the Darkness (Optima) DDoS BotDancho DanchevWebroot2012
BlackEnergy competitor – The 'Darkness' DDoS botMila Parkour
André M. DiMino
Shadowserver Foundation2010
Darkness DDoS bot version identification guideMila Parkour
André M. DiMino
Shadowserver Foundation2011
It’s 2012 and Armageddon has arrivedJeff EdwardsArbor SERT2012
Spread of Darkness...Details on the public release of the Darkness DDoS botMila Parkour
André M. DiMino
Shadowserver Foundation2011

User Agent utilisé pour le ddosing en complément de ceux déjà cités :

  • Mozilla/5.0 (X11; U; Linux i686 (x86_64); en-US; rv:1.8.1.6) Gecko/2007072300

Iceweasel/2.0.0.6 (Debian-2.0.0.6-0etch1+lenny1)

  • Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
  • Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.15-1.2054_FC5; X11; i686; en_US)

KHTML/3.5.4 (like Gecko)

  • Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.8.1.19) Gecko/20081201

Firefox/2.0.0.19

  • Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.2) Gecko/20060308 Firefox/1.5.0.2
  • Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident/4.0; SLCC1; .NET

CLR 2.0.50727; .NET CLR 3.5.21022; .NET CLR 3.5.30729; .NET CLR 3.0.30618)