Showing posts with label APT. Show all posts
Showing posts with label APT. Show all posts

Monday, January 4, 2016

Black Energy


Community Synonyms
  • Sandworm (via SandWorm usage of BE2; iSight Partners)
  • Kernelbot (malware.dontneedcoffe)
  • Lancafdo (Symantec)
  • Blacken (Sophos)

Malware References

Lstudio

Community Synonyms

  • Wumins
  • Elise
  • Evora
  • Emissary
  • stscout
  • Page


Malware References

Elirks

Community Synonyms

Malware References

Lecna



Community Synonyms

  • Backspace

Malware References

PlugX

Community Synonyms

  • Derusbi
  • Destory RAT
  • Kaba
  • Sogu
  • Thoper
  • TVT
  • Gulpix

Malware References

Thursday, December 31, 2015

ZoxPNG

Community Synonyms

  • BlackCoffee

Malware References

Fexel

Community Synonyms

  • Agtid
  • Deputy Dog


Malware References

Stealer

Community Synonyms

  • Sayad (NCC Group)

Malware References

ZxShell

Community References

  • Sensode (Cisco)

Malware References

AspxSpy

Introduction

Community Synonyms

Malware References

9002

Introduction

The 9002 RAT was first noticed when used in 2009 as part of the Operation Aurora attacks and then the Sunshop Campaign and Operation DeputyDog.

Community References
  • Trojan.Hydraq!gen1 (Symantec)
    • Trojan.Hydraq labeled malware are a different backdoor)
  • HomeUnix (FireEye)
  • Naid (Symantec)
  • Vasport (Symantec)
  • Boda (Symantec)
  • McRat
  • MdMBot
  • Troj/Agent-XAL
  • 3102 (Palo Alto)

Malware References

Poison Ivy

Community Synonyms

  • Darkmoon (Symatec)


Malware References

Hikit

Community Synonyms
  • Matrix RAT
  • Gaolmay

Malware References

Gh0st

Community Synonyms:
Moudoor (Symantec)
HTTPS
Lurk (TrendMicro)

Malware Reference:
https://www.sentinelone.com/blog/the-curious-case-of-gh0st-malware/
https://www.emc.com/collateral/so-ASOC-use-case-gh0st-rat.pdf
http://malware-unplugged.blogspot.com/2015/01/hunting-and-decrypting-communications.html
http://download01.norman.no/documents/ThemanyfacesofGh0stRat.pdf
http://henrybasset.blogspot.com/2014/04/red-sky-weekly-gh0st-rat.html
http://www.mcafee.com/in/resources/white-papers/foundstone/wp-know-your-digital-enemy.pdf
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-detecting-apt-activity-with-network-traffic-analysis.pdf
http://blogs.rsa.com/will-gragido/lions-at-the-watering-hole-the-voho-affair/
http://www.mcafee.com/ca/resources/white-papers/foundstone/wp-know-your-digital-enemy.pdf
http://blog.trendmicro.com/trendlabs-security-intelligence/kunming-attack-leads-to-gh0st-rat-variant/
http://xanalysis.blogspot.com/2009/04/gh0st-rat.html

Proxydown

Community Synonyms

  • Miancha
  • Snefix
  • Preshin

Malware Reference


Preshin

Community Synonyms:

Malware Reference:

http://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_PRESHIN.JTT