Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
A SANS Internet Storm Center guest diary details the analysis of a RedTail Linux payload, focusing on Run 002, executed with root privileges. The malware, recovered from a DShield honeypot, employs various techniques to evade detection, including process masquerading (disguising itself as PHP-FPM), terminating monitoring processes, and establishing persistence through a reboot-based crontab modification. The analysis reveals that RedTail actively attempts to use DNS-over-TLS resolvers, and it uses a dynamic port for its listener. The research highlights RedTail's sophisticated evasion techniques and persistence mechanisms, demonstrating how it can operate undetected on compromised systems.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
