Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Wednesday, January 20, 2016

Comfoo

Community Synonyms
  • Tabcteng
  • DPD or backdoor-DPD (McAfee)
  • Wakbot.B (Microsoft)
  •  
Malware References

Nancrat

Community Synonyms
  •  Trojan.Nancrat
Malware References

Breut

Community Synonym
  • Trojan.Breut (Symantec)
  • Breut Trojan
Malware Reference

TheMoon

Community Synonyms
  •  Linksys Worm

Monday, January 4, 2016

sshbeardoor

Community Synonyms

  • DrpBear-A (Sophos)
Malware References

Black Energy


Community Synonyms
  • Sandworm (via SandWorm usage of BE2; iSight Partners)
  • Kernelbot (malware.dontneedcoffe)
  • Lancafdo (Symantec)
  • Blacken (Sophos)

Malware References

Lstudio

Community Synonyms

  • Wumins
  • Elise
  • Evora
  • Emissary
  • stscout
  • Page


Malware References

Elirks

Community Synonyms

Malware References

Lecna



Community Synonyms

  • Backspace

Malware References

PlugX

Community Synonyms

  • Derusbi
  • Destory RAT
  • Kaba
  • Sogu
  • Thoper
  • TVT
  • Gulpix

Malware References

Thursday, December 31, 2015

ZoxPNG

Community Synonyms

  • BlackCoffee

Malware References

Fexel

Community Synonyms

  • Agtid
  • Deputy Dog


Malware References

ZxShell

Community References

  • Sensode (Cisco)

Malware References

AspxSpy

Introduction

Community Synonyms

Malware References

9002

Introduction

The 9002 RAT was first noticed when used in 2009 as part of the Operation Aurora attacks and then the Sunshop Campaign and Operation DeputyDog.

Community References
  • Trojan.Hydraq!gen1 (Symantec)
    • Trojan.Hydraq labeled malware are a different backdoor)
  • HomeUnix (FireEye)
  • Naid (Symantec)
  • Vasport (Symantec)
  • Boda (Symantec)
  • McRat
  • MdMBot
  • Troj/Agent-XAL
  • 3102 (Palo Alto)

Malware References

Poison Ivy

Community Synonyms

  • Darkmoon (Symatec)


Malware References

Hikit

Community Synonyms
  • Matrix RAT
  • Gaolmay

Malware References

Gh0st

Community Synonyms:
Moudoor (Symantec)
HTTPS
Lurk (TrendMicro)

Malware Reference:
https://www.sentinelone.com/blog/the-curious-case-of-gh0st-malware/
https://www.emc.com/collateral/so-ASOC-use-case-gh0st-rat.pdf
http://malware-unplugged.blogspot.com/2015/01/hunting-and-decrypting-communications.html
http://download01.norman.no/documents/ThemanyfacesofGh0stRat.pdf
http://henrybasset.blogspot.com/2014/04/red-sky-weekly-gh0st-rat.html
http://www.mcafee.com/in/resources/white-papers/foundstone/wp-know-your-digital-enemy.pdf
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-detecting-apt-activity-with-network-traffic-analysis.pdf
http://blogs.rsa.com/will-gragido/lions-at-the-watering-hole-the-voho-affair/
http://www.mcafee.com/ca/resources/white-papers/foundstone/wp-know-your-digital-enemy.pdf
http://blog.trendmicro.com/trendlabs-security-intelligence/kunming-attack-leads-to-gh0st-rat-variant/
http://xanalysis.blogspot.com/2009/04/gh0st-rat.html