StreamEX added

pull/33/head
Alexandre Dulaunoy 2017-02-10 10:09:37 +01:00
parent 30d9233db6
commit 5442a262ab
1 changed files with 8 additions and 1 deletions

View File

@ -1289,9 +1289,16 @@
"meta": {
"refs": ["https://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx"]
}
},
{
"value": "StreamEx",
"description": "Cylance dubbed this family of malware StreamEx, based upon a common exported function used across all samples stream, combined with the dropper functionality to append ex to the DLL file name. The StreamEx family has the ability to access and modify the users file system, modify the registry, create system services, enumerate process and system information, enumerate network resources and drive types, scan for security tools such as firewall products and antivirus products, change browser security settings, and remotely execute commands. The malware documented in this post was predominantly 64-bit, however, there are 32-bit versions of the malware in the wild. ",
"meta": {
"refs": ["https://blog.cylance.com/shell-crew-variants-continue-to-fly-under-big-avs-radar"]
}
}
],
"version": 18,
"version": 19,
"uuid": "0d821b68-9d82-4c6d-86a6-1071a9e0f79f",
"description": "threat-actor-tools is an enumeration of tools used by adversaries. The list includes malware but also common software regularly used by the adversaries.",
"author": [