Background
On October 27, 2021, our Botmon system ided an attacker attacking Edgewater
Networks' devices via CVE-2017-6079 with a relatively unique mount file system
command in its payload, which had our attention, and after analysis, we
confirmed that this was a brand new botnet, and based on it's targeting of
Edgewater producers and its Backdoor feature, we named it EwDoor.
The initial version of EwDoor used a multi-C2 redundancy mechanism, and we
registered the second C2 domain, iunno.se, w