Wednesday, January 20, 2016

Comfoo

Community Synonyms
  • Tabcteng
  • DPD or backdoor-DPD (McAfee)
  • Wakbot.B (Microsoft)
  •  
Malware References

Nancrat

Community Synonyms
  •  Trojan.Nancrat
Malware References

Breut

Community Synonym
  • Trojan.Breut (Symantec)
  • Breut Trojan
Malware Reference

TheMoon

Community Synonyms
  •  Linksys Worm

Wednesday, January 6, 2016

IExplore RAT

Community Synonyms

  • Sharky RAT (Seth Hardy)
  • Briba (Symantec)
  • c0d0so0 (iSight)
    • file hash: 3D099498CEC9760616437C5265349B83
  • Amisharp 
Malware References

Security Breach Notification Laws

I always end up re-inventing the wheel when I need to find this information.  This stands as a location to find the laws per (US) state and what states actually have an active reporting agency.

General Sites about Data Breach or Loss



Overview of Laws per State

Agency links per State

  1. Alabama - No centralized reporting or online presence. 
  2. Alaska - No centralized reporting or online presence.
  3. Arizona  - No centralized reporting or online presence. 
  4. Arkansas - No centralized reporting or online presence. 
  5. California - Centralized reporting and searchable database:  https://oag.ca.gov/ecrime/databreach/reporting
  6. Colorado - No centralized reporting or online presence. 
  7. Connecticut - No centralized reporting or online presence.  
  8. Delaware - No centralized reporting or online presence. 
  9. Florida - No centralized reporting or online presence.   http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&Search_String=&URL=0500-0599/0501/Sections/0501.171.html
  10. Georgia - No centralized reporting or online presence. 
  11. Hawaii - No centralized agency but reporting generally flows through Dept. of Commerce.  Requires some digging to find. http://cca.hawaii.gov/
  12. Idaho - No centralized reporting or online presence. 
  13. Illinois - No centralized reporting or online presence. 
  14. Indiana - No centralized reporting or online presence. 
  15. Iowa - No centralized reporting or online presence. www.ivrs.iowa.gov/
  16. Kansas - No centralized reporting or online presence. 
  17. Kentucky - No centralized reporting or online presence. 
  18. Louisiana - No centralized reporting or online presence. 
  19. Maine - Maine is even worse and each entity has to be approached and contacted individually.  http://www.maine.gov/foaa/contactlist/index.htm
  20. Maryland - centralized reporting.  http://www.oag.state.md.us/idtheft/breachNotices2015.htm
  21. Massachusetts - Requires a public records request.  http://www.sec.state.ma.us/pre/prereq/reqidx.htm
  22. Michigan - No centralized reporting or online presence. 
  23. Minnesota - No centralized reporting or online presence. 
  24. Mississippi - No centralized reporting or online presence. 
  25. Missouri - No centralized reporting or online presence.  https://www.ago.mo.gov/divisions/consumer/identity-theft-data-security/data-breaches
  26. Montana - No centralized reporting or online presence. 
  27. Nebraska - No centralized reporting or online presence. 
  28. Nevada - No centralized reporting or online presence. 
  29. New Hampshire - No centralized reporting or online presence. 
  30. New Jersey - No centralized reporting or online presence.  http://www.state.nj.us/lps/
  31. New Mexico - No centralized reporting or online presence. 
  32. New York - No centralized reporting or online presence.  http://www.consumer.state.ny.us/
  33. North Carolina - Centralized reporting but no online presence or searchable database.  http://www.ncdoj.com/Protect-Yourself/2-4-3-Protect-Your-Identity/Protect-Your-Business/Security-Breach-Information.aspx
  34. North Dakota - No centralized reporting or online presence. 
  35. Ohio - No centralized reporting or online presence. 
  36. Oklahoma - No centralized reporting or online presence. 
  37. Oregon - Centralized reporting and searchable database https://justice.oregon.gov/consumer/DataBreach/
  38. Pennsylvania - No centralized reporting or online presence. 
  39. Rhode Island - No centralized reporting or online presence. 
  40. South Carolina - Notifications required but no centralized reporting or online presence.  http://www.consumer.sc.gov/Pages/default.aspx
  41. South Dakota - No centralized reporting or online presence. 
  42. Tennessee  - No centralized reporting or online presence. 
  43. Texas - No centralized reporting or online presence. 
  44. Utah - No centralized reporting or online presence. 
  45. Vermont - Reporting doesn't seem centralized but a list of breach notices are accessible online.  http://ago.vermont.gov/focus/consumer-info/privacy-and-data-security1/data-security-breaches.php
  46. Virginia - Centralized reporting but no online presence or searchable database.  http://www.ag.virginia.gov/
  47. Washington - No centralized reporting or online presence. 
  48. West Virginia - No centralized reporting or online presence. 
  49. Wisconsin - No centralized reporting or online presence. 
  50. Wyoming - No centralized reporting or online presence. 

Monday, January 4, 2016

sshbeardoor

Community Synonyms

  • DrpBear-A (Sophos)
Malware References

Black Energy


Community Synonyms
  • Sandworm (via SandWorm usage of BE2; iSight Partners)
  • Kernelbot (malware.dontneedcoffe)
  • Lancafdo (Symantec)
  • Blacken (Sophos)

Malware References

Lstudio

Community Synonyms

  • Wumins
  • Elise
  • Evora
  • Emissary
  • stscout
  • Page


Malware References

Elirks

Community Synonyms

Malware References

Lecna



Community Synonyms

  • Backspace

Malware References

PlugX

Community Synonyms

  • Derusbi
  • Destory RAT
  • Kaba
  • Sogu
  • Thoper
  • TVT
  • Gulpix

Malware References