Skip to content

Malware

LOWBALL

LOWBALL, uses the legitimate Dropbox cloud-storage service to act as the CnC server.

LOWBALL, uses the legitimate Dropbox cloud-storage service to act as the CnC server. It uses the Dropbox API with a hardcoded bearer access token and has the ability to download, upload, and execute files. The communication occurs via HTTPS over port 443.


Family metadata imported from Malpedia (Fraunhofer FKIE).