MalBabble

Your antidote to the cyber-twaddle that is spread about security and malware. Many people research malware and security and the impact of both. Some insights are valuable; others are insanely stupid. MalBabble exists because insisting that conclusions be drawn from data is a coherent idea; that conjecture isn't evidence; and because appealing to conspiracy to validate ideas is intellectually lazy.

Pages

  • Home
  • Mind's Eye

Sunday, February 24, 2019

Rietspoof

Rietspoof

Multiple stage malware that starts in messenger or skype, delivers a script that infects and continues on through 4-5 stages depending on the target.

Community Names:

  • Trojan.YDJX-4
  • Generic.Trojan.Agent.TPE1UM
  • VBA:Rietspoof-A [Trj]


Attack Vector:

  • Links in Skype & Messenger


References:

  • https://www.technadu.com/rietspoof-malware-distribution-skype-messenger/58503/ 
  • https://blog.avast.com/rietspoof-malware-increases-activity
  • https://twitter.com/malwrhunterteam/status/1097568650507284483
  • https://www.hybrid-analysis.com/sample/90813ad836effce0e21843c7db025d56bf1d204af25746578800f09a049ac008?environmentId=100
  • https://twitter.com/James_inthe_box/status/1097569129123311624
  • https://malware.sekoia.fr/results/90813ad836effce0e21843c7db025d56bf1d204af25746578800f09a049ac008
  • https://www.virustotal.com/#/file/90813ad836effce0e21843c7db025d56bf1d204af25746578800f09a049ac008/detection
  • https://www.vmray.com/analyses/90813ad836ef/report/overview.html
Posted by Starric at 7:40 PM
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Blog Archive

  • ▼  2019 (10)
    • ►  April (1)
    • ►  March (4)
    • ▼  February (5)
      • Rietspoof
      • Separ
      • Shlayer
      • Speak Up
      • GoScanSSH
  • ►  2016 (13)
    • ►  January (13)
  • ►  2015 (23)
    • ►  December (16)
    • ►  August (2)
    • ►  July (1)
    • ►  April (1)
    • ►  January (3)

Labels

  • 3102 (1)
  • 9002 (1)
  • Agtid (1)
  • Amisharp (1)
  • APT (18)
  • AspxSpy (1)
  • Backspace (1)
  • Black Energy (1)
  • BlackCoffee (1)
  • Boda (1)
  • Breut (1)
  • Briba (1)
  • c0d0so0 (1)
  • Comfoo (1)
  • Crilok (1)
  • crimeware (2)
  • Crowti (1)
  • Deputy Dog (1)
  • Derusbi (1)
  • Destory (1)
  • Disakil (1)
  • DPD (1)
  • Dyzap (1)
  • Elirks (1)
  • Elise (1)
  • Emissary (1)
  • Emotet (1)
  • Fexel (1)
  • Gameover (1)
  • Gaolmay (1)
  • Gh0st (1)
  • Go (1)
  • GoScanSSH (1)
  • Gulpix (1)
  • Hikit (1)
  • HTTPS (1)
  • Hydraq (1)
  • Kaba (1)
  • Kernelbot (1)
  • KillDisk (1)
  • lancafdo (1)
  • Lecna (1)
  • Linksys Worm (1)
  • Lstudio (1)
  • Malware (27)
  • Matrix (1)
  • McRat (1)
  • MdMBot (1)
  • Miancha (1)
  • Moudoor (1)
  • Naid (1)
  • Nancrat (1)
  • page (1)
  • PE File Header (5)
  • PirateMatryoshka (1)
  • PlugX (1)
  • Poison Ivy (1)
  • Preshin (2)
  • Proxydown (1)
  • sandworm (1)
  • Separ (1)
  • Shade (1)
  • Sharky RAT (1)
  • Shlayer (1)
  • Snefix (1)
  • Sogu (1)
  • sshbeardoor (2)
  • Stealer (1)
  • stscout (1)
  • Tabcteng (1)
  • TheMoon (1)
  • Thoper (1)
  • Tools (2)
  • Troldesh (1)
  • TVT (1)
  • Vasport (1)
  • Wumins (1)
  • Yara (6)
  • Zeus (1)
  • ZoxPNG (1)
  • ZxShell (1)
Simple theme. Powered by Blogger.