{"id":4238,"date":"2022-08-16T04:58:49","date_gmt":"2022-08-16T09:58:49","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4238"},"modified":"2022-08-16T04:58:49","modified_gmt":"2022-08-16T09:58:49","slug":"new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/","title":{"rendered":"New Botnet Called Orchard Uses Bitcoin Founder&#8217;s Account to Generate Malicious Domains"},"content":{"rendered":"<p>Orchard is the name of a new botnet leveraging Bitcoin creator Satoshi Nakamoto&#8217;s account transaction information to generate DGA [Domain Generation Algorithms] domain names. This is done to hide the command and control infrastructure of the botnet.<\/p>\n<p>Orchard is said to have undergone three patches since February 2021, with the botnet being used primarily to drop additional payloads onto the victim&#8217;s computer and to execute commands received from the C2 server.<\/p>\n<p>Due to the uncertainty of Bitcoin transactions, this technique is more unpredictable than using common time-generated DGAs, and therefore more difficult to defend against,&#8221; said 360 Netlab Researchers in a recent blog post. The researchers they discovered the technique in a family of botnets they named Orchard. Since February 2021, the botnet has released three versions, changing programming languages \u200b\u200bin between.<\/p>\n<p>In particular, it is designed to charge devices and users as well as infect USB storage devices to spread malware. Netlab&#8217;s analysis shows that more than 3,000 hosts have been enslaved by the malware to date, most of them located in China.<\/p>\n<p>Another change is related to the use of the DGA algorithm used in the attacks. While the first two variants rely solely on date strings to generate domain names, the newer version uses balance information obtained from the cryptocurrency wallet address &#8220;1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa&#8221;. And it is in this wallet address is the Bitcoin miner&#8217;s reward receiving address. Genesis Block which occurred on January 3, 2009 and is believed to be in the hands of Nakamoto.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Orchard es el nombre de un nuevo botnet aprovechando la informaci\u00f3n de transacci\u00f3n de la cuenta del creador de Bitcoin, Satoshi Nakamoto, para generar algoritmos de generaci\u00f3n de dominios&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4239,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4238","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New Botnet Called Orchard Uses Bitcoin Founder&#039;s Account to Generate Malicious Domains - Truxgo Server Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Botnet Called Orchard Uses Bitcoin Founder&#039;s Account to Generate Malicious Domains - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Orchard es el nombre de un nuevo botnet aprovechando la informaci\u00f3n de transacci\u00f3n de la cuenta del creador de Bitcoin, Satoshi Nakamoto, para generar algoritmos de generaci\u00f3n de dominios...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-08-16T09:58:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/New.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"New Botnet Called Orchard Uses Bitcoin Founder&#8217;s Account to Generate Malicious Domains\",\"datePublished\":\"2022-08-16T09:58:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/\"},\"wordCount\":265,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/New.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/\",\"name\":\"New Botnet Called Orchard Uses Bitcoin Founder's Account to Generate Malicious Domains - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/New.jpg\",\"datePublished\":\"2022-08-16T09:58:49+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/New.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/New.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Botnet Called Orchard Uses Bitcoin Founder&#8217;s Account to Generate Malicious Domains\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New Botnet Called Orchard Uses Bitcoin Founder's Account to Generate Malicious Domains - Truxgo Server Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/","og_locale":"es_MX","og_type":"article","og_title":"New Botnet Called Orchard Uses Bitcoin Founder's Account to Generate Malicious Domains - Truxgo Server Blog","og_description":"Orchard es el nombre de un nuevo botnet aprovechando la informaci\u00f3n de transacci\u00f3n de la cuenta del creador de Bitcoin, Satoshi Nakamoto, para generar algoritmos de generaci\u00f3n de dominios...","og_url":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-08-16T09:58:49+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/New.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"New Botnet Called Orchard Uses Bitcoin Founder&#8217;s Account to Generate Malicious Domains","datePublished":"2022-08-16T09:58:49+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/"},"wordCount":265,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/New.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/","url":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/","name":"New Botnet Called Orchard Uses Bitcoin Founder's Account to Generate Malicious Domains - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/New.jpg","datePublished":"2022-08-16T09:58:49+00:00","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/New.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/08\/New.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/new-botnet-called-orchard-uses-bitcoin-founders-account-to-generate-malicious-domains\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"New Botnet Called Orchard Uses Bitcoin Founder&#8217;s Account to Generate Malicious Domains"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4238"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4238\/revisions"}],"predecessor-version":[{"id":4240,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4238\/revisions\/4240"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4239"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}