216.73.217.22

A look at PolarEdge Adjacent Infrastructure

· Published 01/09/2025 09:30 · Modified 01/09/2025 10:35

Export JSON

Essential information

Published
01/09/2025 09:30
Modified
01/09/2025 10:35
Tags
2025-09-01 CVE-2023-20118 certificate analysis infrastructure iot botnet polaredge proxy management reverse-connect rpx server socks5 trojan-protocol
Related entities
1 vulnerabilities (cve), 4 observables, 1 intrusion sets (apt), 5 techniques (mitre), 1 malware, 2 others

Description

This analysis examines the associated with , an that exploits . The investigation reveals connections between various certificates and services, including a WebRTC e-book certificate and suspicious PolarSSL certificates. A key discovery is the , a proxy gateway system found on a host with multiple suspicious certificates. The manages proxy nodes and provides and services. Technical analysis of the RPX binary reveals its functionality in handling client connections, proxy node registration, and traffic obfuscation. The investigation highlights the potential relationship between the RPX system and the botnet, showcasing the complexity of .

External references