遇见数据集

Artifacts for paper "From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet" - Self-Attacks Packet Traces

收藏
Zenodo2025-12-11 更新2026-05-26 收录
官方服务:

资源简介:

Artifacts for the Paper "From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet" Structure of the artifacts gorilla-artifacts/ ├── self-attacks/ # Pcap files of the DDoS attacks against our own infrastructure ├── commands/ # DDoS commands issued by the C2 server(s) to the bots ├── samples/ # Hashes of malware samples analysed ├── telegram/ # Downloaded chat announcements on Telegram marketing channels └── telescope/ # Sampled exploit payloads per identified Gorilla scanners └── videos/ # Some videos from their YouTube channel used for promotion self-attacks/ Each .pcap file represents a different type of attack requested against our controlled infrastructure endpoints. All IP addresses in the data, both in protocol headers and in references within application payloads, have been either redacted to a private range (target addresses) or anonymized through the prefix-preserving Crypto-PAN algorithm. commands/ The file `gorilla_attack_commands.csv` contains one separate DDoS attack command obtained through the C2 Milker `StartTime`, `EndTime`: UTC epochs indicating attack duration `Protocol`: transport protocol of the attack (TCP or UDP) `Vector`: attack method issued by the command `Port`: destination transport port to be targeted `VictimIP,VictimMask`: IPv4 subnet base and mask of where the attack victim IP is located. All victim addresses are anonymized through prefix-preserving anonymization (Crypto-PAN algorithm) `Concurrents,Consecutives`: Counts of command records issued at the same time for attack intensity (`Concurrents`) and of instances of the same attack repeated consecutively (`Consecutives`) samples/ This directory contains the file `sample_hashes.csv`, including the sha256 `hash` value of each Gorilla malware sample analysed, along with its collection time frame (`first_seen`, `last_seen`) telegram/ This directory contains a data export from Telegram, containing the messages shared by the Gorilla authors in their Telegram channel.The `result.json` file is a direct Telegram dump, and the `gorilla_chat` directory contains the media files, as well as a HTML-viewable page with the chat history. telescope/ The file `gorilla-scanners-payloads.json` contains a selected sample of application-layer payloads delivered in exploitation attempts towards our Reactive Telescope. Each index of the file indicates a separate scanner IP that has contributed to Gorilla infections. Each element within the `payloads` field represents the TCP data payload fragments delivered in an individual connection Target IP addresses are redacted as `DST_IP_ADDR` for anonimity and privacy, while loader IP addresses appearing in RCE attempts are marked as `LOADER_IP_ADDR` to avoid duplicates. `tot_exploit_count` indicates the overall amount of connections attempting RCE from the scanner IP videos/ Ths directory contains two videos taken from the Gorilla YouTube channel. One of the videos demonstrates an attack against a DSTAT endpoint. The other video is an attack launched against a live-streamed online gaming session.

提供机构:
Zenodo
创建时间:
2025-12-11
二维码
社区交流群
二维码
科研交流群
商业服务