Hunting the Remastered Gucci Botnet

ice-wzl
5 min readFeb 20, 2022

I check my honey pots pretty regularly through the Virus Total API to see what volume of activity I am getting. A couple of days ago I noticed that there was an abnormal spike in activity in the South American region.

Curiosity being what it is, I decided to log in and investigate further. Running a quick bash file command inside a for loop over the saved malware I noticed that there was one shell…

--

--

ice-wzl

Reverse Engineer, Red Teamer, CTF fan & creator