Merge pull request #105 from Delta-Sierra/master

add dimnie
pull/107/head
Alexandre Dulaunoy 2017-10-27 11:49:05 +02:00 committed by GitHub
commit 569c07f7e9
1 changed files with 9 additions and 0 deletions

View File

@ -3002,6 +3002,15 @@
"https://www.arbornetworks.com/blog/asert/formidable-formbook-form-grabber/"
]
}
},
{
"value": "Dimnie",
"description": "Dimnie, the commonly agreed upon name for the binary dropped by the PowerShell script above, has been around for several years. Palo Alto Networks has observed samples dating back to early 2014 with identical command and control mechanisms. The malware family serves as a downloader and has a modular design encompassing various information stealing functionalities. Each module is injected into the memory of core Windows processes, further complicating analysis. During its lifespan, it appears to have undergone few changes and its stealthy command and control methods combined with a previously Russian focused target base has allowed it to fly under the radar up until this most recent campaign.",
"meta": {
"refs": [
"https://researchcenter.paloaltonetworks.com/2017/03/unit42-dimnie-hiding-plain-sight/"
]
}
}
]
}