Thursday, December 31, 2015

ZoxPNG

Community Synonyms

  • BlackCoffee

Malware References

Fexel

Community Synonyms

  • Agtid
  • Deputy Dog


Malware References

Stealer

Community Synonyms

  • Sayad (NCC Group)

Malware References

ZxShell

Community References

  • Sensode (Cisco)

Malware References

AspxSpy

Introduction

Community Synonyms

Malware References

9002

Introduction

The 9002 RAT was first noticed when used in 2009 as part of the Operation Aurora attacks and then the Sunshop Campaign and Operation DeputyDog.

Community References
  • Trojan.Hydraq!gen1 (Symantec)
    • Trojan.Hydraq labeled malware are a different backdoor)
  • HomeUnix (FireEye)
  • Naid (Symantec)
  • Vasport (Symantec)
  • Boda (Symantec)
  • McRat
  • MdMBot
  • Troj/Agent-XAL
  • 3102 (Palo Alto)

Malware References

Poison Ivy

Community Synonyms

  • Darkmoon (Symatec)


Malware References

Hikit

Community Synonyms
  • Matrix RAT
  • Gaolmay

Malware References

Gh0st

Community Synonyms:
Moudoor (Symantec)
HTTPS
Lurk (TrendMicro)

Malware Reference:
https://www.sentinelone.com/blog/the-curious-case-of-gh0st-malware/
https://www.emc.com/collateral/so-ASOC-use-case-gh0st-rat.pdf
http://malware-unplugged.blogspot.com/2015/01/hunting-and-decrypting-communications.html
http://download01.norman.no/documents/ThemanyfacesofGh0stRat.pdf
http://henrybasset.blogspot.com/2014/04/red-sky-weekly-gh0st-rat.html
http://www.mcafee.com/in/resources/white-papers/foundstone/wp-know-your-digital-enemy.pdf
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-detecting-apt-activity-with-network-traffic-analysis.pdf
http://blogs.rsa.com/will-gragido/lions-at-the-watering-hole-the-voho-affair/
http://www.mcafee.com/ca/resources/white-papers/foundstone/wp-know-your-digital-enemy.pdf
http://blog.trendmicro.com/trendlabs-security-intelligence/kunming-attack-leads-to-gh0st-rat-variant/
http://xanalysis.blogspot.com/2009/04/gh0st-rat.html

Proxydown

Community Synonyms

  • Miancha
  • Snefix
  • Preshin

Malware Reference


Preshin

Community Synonyms:

Malware Reference:

http://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_PRESHIN.JTT


Gameover Zeus

Malware References:


http://blogs.microsoft.com/blog/2014/06/02/microsoft-helps-fbi-in-gameover-zeus-botnet-cleanup/

Emotet

Malware References:


https://blogs.technet.microsoft.com/mmpc/2015/01/06/emotet-spam-campaign-targets-banking-credentials/
https://blogs.technet.microsoft.com/mmpc/2015/01/12/msrt-january-2015-dyzap/

Dyzap

Malware References:


https://blogs.technet.microsoft.com/mmpc/2015/01/12/msrt-january-2015-dyzap/

Crowti

Malware References:


https://blogs.technet.microsoft.com/mmpc/2015/01/13/crowti-update-cryptowall-3-0/

Crilok (Cryptolocker)

Malware References:

http://www.symantec.com/security_response/writeup.jsp?docid=2014-061923-2824-99
http://www.symantec.com/security_response/writeup.jsp?docid=2014-061923-2824-99&tabid=2