Dofloo, also known as AESDDoS, is a botnet malware family first detected in 2014 and used to build large-scale distributed denial-of-service networks. It has been deployed against Linux and Windows servers, and MIPS-based variants occur in IoT malware collections. Its attack capabilities include SYN, LSYN, UDP, UDPS, and TCP floods. After execution, Dofloo collects system information and transmits it to a command-and-control server, allowing operators to select follow-on actions based on the compromised machine’s hardware configuration. Some variants can load cryptocurrency miners onto infected systems.
Dofloo campaigns have abused exposed, unauthenticated Docker APIs. Attackers scan for accessible Docker services, enumerate running containers, and use Docker’s command-execution functionality to deploy the malware inside existing containers. Other campaigns have delivered Dofloo through vulnerabilities in Atlassian Confluence Server, including the unauthenticated OGNL injection vulnerability CVE-2021-26084. These infection routes enable the recruitment of compromised servers and container workloads into attacker-controlled botnets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On August 25, 2021 a security advisory was released for a vulnerability identified in Confluence Server titled “CVE-2021-26084: Atlassian Confluence OGNL Injection”. The vulnerability allows an unauthenticated attacker to perform remote command execution... various POC/Exploits were published online... attempts at executing them were already detected on our systems... attackers’ attempts to exploit this vulnerability in order to install and run the XMRig cryptocurrency miner on affected Confluence servers. | VirusTotal identified the following payloads as: ... Dofloo Trojan
Attackers are actively scanning for exposed Docker APIs on port 2375 and use them to deploy a malicious payload which drops a Dofloo Trojan variant, a malware known as a popular tool for building large scale botnets.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacks begin with an Internet scan for vulnerable Docker hosts by sending TCP SYN packets to port 2375 — the Docker daemon communication port which allows for unencrypted and unauthenticated communication
the data being packed and sent to its command-and-control (C&C) server allowing its masters to decide what the next course of action will be
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
Named only in the sample SHA1 indicator list; its capabilities and relationship to the analyzed variant are not described.
Named trojan payload identified among other exploit attempts against the Confluence vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.