Drawing the Line between SYS01 and Ducktail through DNS Traces | WhoisXML API

Threat Reports

Drawing the Line between SYS01 and Ducktail through DNS Traces

Morphisec recently discovered SYS01 Stealer,1 a threat that shared Ducktail’s2 penchant for going after Facebook business owners and advertisers. Apart from their shared targets and tactics, though, the malware had varying payloads.

The WhoisXML API team sought to determine what DNS-based commonalities SYS01 and Ducktail shared, if any, through an expansion analysis of 10 SYS01 domains identified as indicators of compromise (IoCs) that found:

  • 20 IP addresses to which the IoCs resolved, two of which turned out to be malicious
  • 3,000+ domains that shared the IoCs’ IP hosts, 20+ of which were confirmed to be malware hosts
  • Two domains that contained the string baglamanotalari. akin to one of the IoCs

Download a sample of the threat research materials now or contact us to access the complete set of research materials.

  • [1] https://blog.morphisec.com/sys01stealer-facebook-info-stealer
  • [2] https://circleid.com/posts/20230102-own-a-facebook-business-beware-of-ducktail
Try our WhoisXML API for free
Get started