Merge pull request #219 from raw-data/master

[ADD] x2 new entries for banker.json and  rat.json
pull/221/head
Alexandre Dulaunoy 2018-06-01 16:28:05 +02:00 committed by GitHub
commit ceb2322d57
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 107 additions and 87 deletions

View File

@ -1,14 +1,18 @@
{ {
"uuid": "59f20cce-5420-4084-afd5-0884c0a83832",
"name": "Banker",
"source": "Open Sources",
"version": 8,
"values": [ "values": [
{ {
"meta": { "meta": {
"date": "Initally discovered between 2006 and 2007. New bankers with Zeus roots still active today.",
"refs": [ "refs": [
"https://usa.kaspersky.com/resource-center/threats/zeus-virus" "https://usa.kaspersky.com/resource-center/threats/zeus-virus"
], ],
"synonyms": [ "synonyms": [
"Zbot" "Zbot"
], ]
"date": "Initally discovered between 2006 and 2007. New bankers with Zeus roots still active today."
}, },
"description": "Zeus is a trojan horse that is primarily delivered via drive-by-downloads, malvertising, exploit kits and malspam campaigns. It uses man-in-the-browser keystroke logging and form grabbing to steal information from victims. Source was leaked in 2011.", "description": "Zeus is a trojan horse that is primarily delivered via drive-by-downloads, malvertising, exploit kits and malspam campaigns. It uses man-in-the-browser keystroke logging and form grabbing to steal information from victims. Source was leaked in 2011.",
"value": "Zeus", "value": "Zeus",
@ -16,6 +20,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered early 2013",
"refs": [ "refs": [
"https://www.kaspersky.com/blog/neverquest-trojan-built-to-steal-from-hundreds-of-banks/3247/", "https://www.kaspersky.com/blog/neverquest-trojan-built-to-steal-from-hundreds-of-banks/3247/",
"https://www.fidelissecurity.com/threatgeek/2016/05/vawtrak-trojan-bank-it-evolving", "https://www.fidelissecurity.com/threatgeek/2016/05/vawtrak-trojan-bank-it-evolving",
@ -24,8 +29,7 @@
], ],
"synonyms": [ "synonyms": [
"Neverquest" "Neverquest"
], ]
"date": "Discovered early 2013"
}, },
"description": "Delivered primarily by exploit kits as well as malspam campaigns utilizing macro based Microsoft Office documents as attachments. Vawtrak/Neverquest is a modularized banking trojan designed to steal credentials through harvesting, keylogging, Man-In-The-Browser, etc.", "description": "Delivered primarily by exploit kits as well as malspam campaigns utilizing macro based Microsoft Office documents as attachments. Vawtrak/Neverquest is a modularized banking trojan designed to steal credentials through harvesting, keylogging, Man-In-The-Browser, etc.",
"value": "Vawtrak", "value": "Vawtrak",
@ -33,14 +37,14 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovery in 2014, still active",
"refs": [ "refs": [
"https://blog.malwarebytes.com/detections/trojan-dridex/", "https://blog.malwarebytes.com/detections/trojan-dridex/",
"https://feodotracker.abuse.ch/" "https://feodotracker.abuse.ch/"
], ],
"synonyms": [ "synonyms": [
"Feodo Version D" "Feodo Version D"
], ]
"date": "Discovery in 2014, still active"
}, },
"description": " Dridex leverages redirection attacks designed to send victims to malicious replicas of the banking sites they think they're visiting.", "description": " Dridex leverages redirection attacks designed to send victims to malicious replicas of the banking sites they think they're visiting.",
"value": "Dridex", "value": "Dridex",
@ -48,6 +52,7 @@
}, },
{ {
"meta": { "meta": {
"date": "First seen ~ 2007",
"refs": [ "refs": [
"https://www.secureworks.com/research/gozi", "https://www.secureworks.com/research/gozi",
"https://www.gdatasoftware.com/blog/2016/11/29325-analysis-ursnif-spying-on-your-data-since-2007", "https://www.gdatasoftware.com/blog/2016/11/29325-analysis-ursnif-spying-on-your-data-since-2007",
@ -58,8 +63,7 @@
"CRM", "CRM",
"Snifula", "Snifula",
"Papras" "Papras"
], ]
"date": "First seen ~ 2007"
}, },
"description": "Banking trojan delivered primarily via email (typically malspam) and exploit kits. Gozi 1.0 source leaked in 2010", "description": "Banking trojan delivered primarily via email (typically malspam) and exploit kits. Gozi 1.0 source leaked in 2010",
"value": "Gozi", "value": "Gozi",
@ -67,6 +71,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Fall Oct. 2012 - Spring 2013",
"refs": [ "refs": [
"https://krebsonsecurity.com/tag/gozi-prinimalka/", "https://krebsonsecurity.com/tag/gozi-prinimalka/",
"https://securityintelligence.com/project-blitzkrieg-how-to-block-the-planned-prinimalka-gozi-trojan-attack/", "https://securityintelligence.com/project-blitzkrieg-how-to-block-the-planned-prinimalka-gozi-trojan-attack/",
@ -74,8 +79,7 @@
], ],
"synonyms": [ "synonyms": [
"Prinimalka" "Prinimalka"
], ]
"date": "Fall Oct. 2012 - Spring 2013"
}, },
"description": "Banking trojan attributed to Project Blitzkrieg targeting U.S. Financial institutions.", "description": "Banking trojan attributed to Project Blitzkrieg targeting U.S. Financial institutions.",
"value": "Goziv2", "value": "Goziv2",
@ -83,13 +87,13 @@
}, },
{ {
"meta": { "meta": {
"date": "Beginning 2010",
"refs": [ "refs": [
"https://www.govcert.admin.ch/blog/18/gozi-isfb-when-a-bug-really-is-a-feature", "https://www.govcert.admin.ch/blog/18/gozi-isfb-when-a-bug-really-is-a-feature",
"https://blog.malwarebytes.com/threat-analysis/2017/04/binary-options-malvertising-campaign-drops-isfb-banking-trojan/", "https://blog.malwarebytes.com/threat-analysis/2017/04/binary-options-malvertising-campaign-drops-isfb-banking-trojan/",
"https://info.phishlabs.com/blog/the-unrelenting-evolution-of-vawtrak", "https://info.phishlabs.com/blog/the-unrelenting-evolution-of-vawtrak",
"https://lokalhost.pl/gozi_tree.txt" "https://lokalhost.pl/gozi_tree.txt"
], ]
"date": "Beginning 2010"
}, },
"description": "Banking trojan based on Gozi source. Features include web injects for the victims browsers, screenshoting, video recording, transparent redirections, etc. Source leaked ~ end of 2015.", "description": "Banking trojan based on Gozi source. Features include web injects for the victims browsers, screenshoting, video recording, transparent redirections, etc. Source leaked ~ end of 2015.",
"value": "Gozi ISFB", "value": "Gozi ISFB",
@ -97,12 +101,12 @@
}, },
{ {
"meta": { "meta": {
"date": "Since 2014",
"refs": [ "refs": [
"https://blog.malwarebytes.com/threat-analysis/2017/04/binary-options-malvertising-campaign-drops-isfb-banking-trojan/", "https://blog.malwarebytes.com/threat-analysis/2017/04/binary-options-malvertising-campaign-drops-isfb-banking-trojan/",
"https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality", "https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality",
"https://lokalhost.pl/gozi_tree.txt" "https://lokalhost.pl/gozi_tree.txt"
], ]
"date": "Since 2014"
}, },
"description": "Dreambot is a variant of Gozi ISFB that is spread via numerous exploit kits as well as through malspam email attachments and links.", "description": "Dreambot is a variant of Gozi ISFB that is spread via numerous exploit kits as well as through malspam email attachments and links.",
"value": "Dreambot", "value": "Dreambot",
@ -110,11 +114,11 @@
}, },
{ {
"meta": { "meta": {
"date": "Seen Autumn 2014",
"refs": [ "refs": [
"https://lokalhost.pl/gozi_tree.txt", "https://lokalhost.pl/gozi_tree.txt",
"http://archive.is/I7hi8#selection-217.0-217.6" "http://archive.is/I7hi8#selection-217.0-217.6"
], ]
"date": "Seen Autumn 2014"
}, },
"description": "Gozi ISFB variant ", "description": "Gozi ISFB variant ",
"value": "IAP", "value": "IAP",
@ -122,11 +126,11 @@
}, },
{ {
"meta": { "meta": {
"date": "Spring 2016",
"refs": [ "refs": [
"https://securityintelligence.com/meet-goznym-the-banking-malware-offspring-of-gozi-isfb-and-nymaim/", "https://securityintelligence.com/meet-goznym-the-banking-malware-offspring-of-gozi-isfb-and-nymaim/",
"https://lokalhost.pl/gozi_tree.txt" "https://lokalhost.pl/gozi_tree.txt"
], ]
"date": "Spring 2016"
}, },
"description": "GozNym hybrid takes the best of both the Nymaim and Gozi ISFB. From the Nymaim malware, it leverages the droppers stealth and persistence; the Gozi ISFB parts add the banking Trojans capabilities to facilitate fraud via infected Internet browsers.", "description": "GozNym hybrid takes the best of both the Nymaim and Gozi ISFB. From the Nymaim malware, it leverages the droppers stealth and persistence; the Gozi ISFB parts add the banking Trojans capabilities to facilitate fraud via infected Internet browsers.",
"value": "GozNym", "value": "GozNym",
@ -134,14 +138,14 @@
}, },
{ {
"meta": { "meta": {
"date": "First seen in Fall 2016 and still active today.",
"refs": [ "refs": [
"https://blog.threatstop.com/zloader/terdot-that-man-in-the-middle", "https://blog.threatstop.com/zloader/terdot-that-man-in-the-middle",
"https://www.scmagazine.com/terdot-zloaderzbot-combo-abuses-certificate-app-to-pull-off-mitm-browser-attacks/article/634443/" "https://www.scmagazine.com/terdot-zloaderzbot-combo-abuses-certificate-app-to-pull-off-mitm-browser-attacks/article/634443/"
], ],
"synonyms": [ "synonyms": [
"Zeus Terdot" "Zeus Terdot"
], ]
"date": "First seen in Fall 2016 and still active today."
}, },
"description": "Zloader is a loader that loads different payloads, one of which is a Zeus module. Delivered via exploit kits and malspam emails. ", "description": "Zloader is a loader that loads different payloads, one of which is a Zeus module. Delivered via exploit kits and malspam emails. ",
"value": "Zloader Zeus", "value": "Zloader Zeus",
@ -149,14 +153,14 @@
}, },
{ {
"meta": { "meta": {
"date": "First seen ~Feb 2014",
"refs": [ "refs": [
"https://blog.malwarebytes.com/threat-analysis/2014/02/hiding-in-plain-sight-a-story-about-a-sneaky-banking-trojan/", "https://blog.malwarebytes.com/threat-analysis/2014/02/hiding-in-plain-sight-a-story-about-a-sneaky-banking-trojan/",
"https://securityintelligence.com/new-zberp-trojan-discovered-zeus-zbot-carberp/" "https://securityintelligence.com/new-zberp-trojan-discovered-zeus-zbot-carberp/"
], ],
"synonyms": [ "synonyms": [
"VM Zeus" "VM Zeus"
], ]
"date": "First seen ~Feb 2014"
}, },
"description": "Zeus variant that utilizes steganography in image files to retrieve configuration file. ", "description": "Zeus variant that utilizes steganography in image files to retrieve configuration file. ",
"value": "Zeus VM", "value": "Zeus VM",
@ -164,10 +168,10 @@
}, },
{ {
"meta": { "meta": {
"date": "First seen ~Aug 2015",
"refs": [ "refs": [
"https://securityintelligence.com/brazil-cant-catch-a-break-after-panda-comes-the-sphinx/" "https://securityintelligence.com/brazil-cant-catch-a-break-after-panda-comes-the-sphinx/"
], ]
"date": "First seen ~Aug 2015"
}, },
"description": "Sphinx is a modular banking trojan that is a commercial offering sold to cybercriminals via underground fraudster boards.", "description": "Sphinx is a modular banking trojan that is a commercial offering sold to cybercriminals via underground fraudster boards.",
"value": "Zeus Sphinx", "value": "Zeus Sphinx",
@ -175,6 +179,7 @@
}, },
{ {
"meta": { "meta": {
"date": "First seen ~ Spring 2016",
"refs": [ "refs": [
"https://www.proofpoint.com/us/threat-insight/post/panda-banker-new-banking-trojan-hits-the-market", "https://www.proofpoint.com/us/threat-insight/post/panda-banker-new-banking-trojan-hits-the-market",
"https://cyberwtf.files.wordpress.com/2017/07/panda-whitepaper.pdf", "https://cyberwtf.files.wordpress.com/2017/07/panda-whitepaper.pdf",
@ -182,8 +187,7 @@
], ],
"synonyms": [ "synonyms": [
"Zeus Panda" "Zeus Panda"
], ]
"date": "First seen ~ Spring 2016"
}, },
"description": "Zeus like banking trojan that is delivered primarily through malspam emails and exploit kits.", "description": "Zeus like banking trojan that is delivered primarily through malspam emails and exploit kits.",
"value": "Panda Banker", "value": "Panda Banker",
@ -191,6 +195,7 @@
}, },
{ {
"meta": { "meta": {
"date": "First seen 2014",
"refs": [ "refs": [
"https://securityintelligence.com/zeus-maple-variant-targets-canadian-online-banking-customers/", "https://securityintelligence.com/zeus-maple-variant-targets-canadian-online-banking-customers/",
"https://github.com/nyx0/KINS" "https://github.com/nyx0/KINS"
@ -198,8 +203,7 @@
"synonyms": [ "synonyms": [
"Kasper Internet Non-Security", "Kasper Internet Non-Security",
"Maple" "Maple"
], ]
"date": "First seen 2014"
}, },
"description": "Zeus KINS is a modified version of ZeuS 2.0.8.9. It contains an encrypted version of it's config in the registry. ", "description": "Zeus KINS is a modified version of ZeuS 2.0.8.9. It contains an encrypted version of it's config in the registry. ",
"value": "Zeus KINS", "value": "Zeus KINS",
@ -207,14 +211,14 @@
}, },
{ {
"meta": { "meta": {
"date": "First seen fall of 2014",
"refs": [ "refs": [
"https://www.proofpoint.com/us/threat-insight/post/threat-actors-using-legitimate-paypal-accounts-to-distribute-chthonic-banking-trojan", "https://www.proofpoint.com/us/threat-insight/post/threat-actors-using-legitimate-paypal-accounts-to-distribute-chthonic-banking-trojan",
"https://securelist.com/chthonic-a-new-modification-of-zeus/68176/" "https://securelist.com/chthonic-a-new-modification-of-zeus/68176/"
], ],
"synonyms": [ "synonyms": [
"Chtonic" "Chtonic"
], ]
"date": "First seen fall of 2014"
}, },
"description": "Chthonic according to Kaspersky is an evolution of Zeus VM. It uses the same encryptor as Andromeda bot, the same encryption scheme as Zeus AES and Zeus V2 Trojans, and a virtual machine similar to that used in ZeusVM and KINS malware.", "description": "Chthonic according to Kaspersky is an evolution of Zeus VM. It uses the same encryptor as Andromeda bot, the same encryption scheme as Zeus AES and Zeus V2 Trojans, and a virtual machine similar to that used in ZeusVM and KINS malware.",
"value": "Chthonic", "value": "Chthonic",
@ -222,6 +226,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered Fall 2016",
"refs": [ "refs": [
"https://blog.malwarebytes.com/threat-analysis/2016/10/trick-bot-dyrezas-successor/", "https://blog.malwarebytes.com/threat-analysis/2016/10/trick-bot-dyrezas-successor/",
"https://blog.malwarebytes.com/threat-analysis/2017/08/trickbot-comes-with-new-tricks-attacking-outlook-and-browsing-data/", "https://blog.malwarebytes.com/threat-analysis/2017/08/trickbot-comes-with-new-tricks-attacking-outlook-and-browsing-data/",
@ -231,8 +236,7 @@
"synonyms": [ "synonyms": [
"Trickster", "Trickster",
"Trickloader" "Trickloader"
], ]
"date": "Discovered Fall 2016"
}, },
"description": "Trickbot is a bot that is delivered via exploit kits and malspam campaigns. The bot is capable of downloading modules, including a banker module. Trickbot also shares roots with the Dyre banking trojan", "description": "Trickbot is a bot that is delivered via exploit kits and malspam campaigns. The bot is capable of downloading modules, including a banker module. Trickbot also shares roots with the Dyre banking trojan",
"value": "Trickbot", "value": "Trickbot",
@ -240,14 +244,14 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~June 2014",
"refs": [ "refs": [
"https://www.secureworks.com/research/dyre-banking-trojan", "https://www.secureworks.com/research/dyre-banking-trojan",
"https://blog.malwarebytes.com/threat-analysis/2015/11/a-technical-look-at-dyreza/" "https://blog.malwarebytes.com/threat-analysis/2015/11/a-technical-look-at-dyreza/"
], ],
"synonyms": [ "synonyms": [
"Dyreza" "Dyreza"
], ]
"date": "Discovered ~June 2014"
}, },
"description": "Dyre is a banking trojan distributed via exploit kits and malspam emails primarily. It has a modular architectur and utilizes man-in-the-browser functionality. It also leverages a backconnect server that allows threat actors to connect to a bank website through the victim's computer.", "description": "Dyre is a banking trojan distributed via exploit kits and malspam emails primarily. It has a modular architectur and utilizes man-in-the-browser functionality. It also leverages a backconnect server that allows threat actors to connect to a bank website through the victim's computer.",
"value": "Dyre", "value": "Dyre",
@ -255,6 +259,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~Spring 2012",
"refs": [ "refs": [
"https://securityblog.switch.ch/2015/06/18/so-long-and-thanks-for-all-the-domains/", "https://securityblog.switch.ch/2015/06/18/so-long-and-thanks-for-all-the-domains/",
"http://securityintelligence.com/tinba-malware-reloaded-and-attacking-banks-around-the-world/", "http://securityintelligence.com/tinba-malware-reloaded-and-attacking-banks-around-the-world/",
@ -265,8 +270,7 @@
"Zusy", "Zusy",
"TinyBanker", "TinyBanker",
"illi" "illi"
], ]
"date": "Discovered ~Spring 2012"
}, },
"description": "Tinba is a very small banking trojan that hooks into browsers and steals login data and sniffs on network traffic. It also uses Man in The Browser (MiTB) and webinjects. Tinba is primarily delivered via exploit kits, malvertising and malspam email campaigns.", "description": "Tinba is a very small banking trojan that hooks into browsers and steals login data and sniffs on network traffic. It also uses Man in The Browser (MiTB) and webinjects. Tinba is primarily delivered via exploit kits, malvertising and malspam email campaigns.",
"value": "Tinba", "value": "Tinba",
@ -274,6 +278,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~Summer 2014",
"refs": [ "refs": [
"https://feodotracker.abuse.ch/", "https://feodotracker.abuse.ch/",
"http://blog.trendmicro.com/trendlabs-security-intelligence/new-banking-malware-uses-network-sniffing-for-data-theft/" "http://blog.trendmicro.com/trendlabs-security-intelligence/new-banking-malware-uses-network-sniffing-for-data-theft/"
@ -281,8 +286,7 @@
"synonyms": [ "synonyms": [
"Feodo Version C", "Feodo Version C",
"Emotet" "Emotet"
], ]
"date": "Discovered ~Summer 2014"
}, },
"description": "Geodo is a banking trojan delivered primarily through malspam emails. It is capable of sniffing network activity to steal information by hooking certain network API calls.", "description": "Geodo is a banking trojan delivered primarily through malspam emails. It is capable of sniffing network activity to steal information by hooking certain network API calls.",
"value": "Geodo", "value": "Geodo",
@ -290,6 +294,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~September 2011",
"refs": [ "refs": [
"https://securelist.com/dridex-a-history-of-evolution/78531/", "https://securelist.com/dridex-a-history-of-evolution/78531/",
"https://feodotracker.abuse.ch/", "https://feodotracker.abuse.ch/",
@ -298,8 +303,7 @@
"synonyms": [ "synonyms": [
"Bugat", "Bugat",
"Cridex" "Cridex"
], ]
"date": "Discovered ~September 2011"
}, },
"description": "Feodo is a banking trojan that utilizes web injects and is also capable of monitoring & manipulating cookies. Version A = Port 8080, Version B = Port 80 It is delivered primarily via exploit kits and malspam emails.", "description": "Feodo is a banking trojan that utilizes web injects and is also capable of monitoring & manipulating cookies. Version A = Port 8080, Version B = Port 80 It is delivered primarily via exploit kits and malspam emails.",
"value": "Feodo", "value": "Feodo",
@ -307,13 +311,13 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~2010.",
"refs": [ "refs": [
"https://www.cert.pl/en/news/single/ramnit-in-depth-analysis/" "https://www.cert.pl/en/news/single/ramnit-in-depth-analysis/"
], ],
"synonyms": [ "synonyms": [
"Nimnul" "Nimnul"
], ]
"date": "Discovered ~2010."
}, },
"description": "Originally not a banking trojan in 2010, Ramnit became a banking trojan after the Zeus source code leak. It is capable of perforrming Man-in-the-Browser attacks. Distributed primarily via exploit kits.", "description": "Originally not a banking trojan in 2010, Ramnit became a banking trojan after the Zeus source code leak. It is capable of perforrming Man-in-the-Browser attacks. Distributed primarily via exploit kits.",
"value": "Ramnit", "value": "Ramnit",
@ -321,6 +325,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~2007",
"refs": [ "refs": [
"https://securityintelligence.com/qakbot-banking-trojan-causes-massive-active-directory-lockouts/", "https://securityintelligence.com/qakbot-banking-trojan-causes-massive-active-directory-lockouts/",
"https://www.johannesbader.ch/2016/02/the-dga-of-qakbot/", "https://www.johannesbader.ch/2016/02/the-dga-of-qakbot/",
@ -329,8 +334,7 @@
"synonyms": [ "synonyms": [
"Qbot ", "Qbot ",
"Pinkslipbot" "Pinkslipbot"
], ]
"date": "Discovered ~2007"
}, },
"description": "Qakbot is a banking trojan that leverages webinjects to steal banking information from victims. It also utilizes DGA for command and control. It is primarily delivered via exploit kits.", "description": "Qakbot is a banking trojan that leverages webinjects to steal banking information from victims. It also utilizes DGA for command and control. It is primarily delivered via exploit kits.",
"value": "Qakbot", "value": "Qakbot",
@ -338,12 +342,12 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~Fall 2015",
"refs": [ "refs": [
"https://securityintelligence.com/an-overnight-sensation-corebot-returns-as-a-full-fledged-financial-malware/", "https://securityintelligence.com/an-overnight-sensation-corebot-returns-as-a-full-fledged-financial-malware/",
"https://www.arbornetworks.com/blog/asert/wp-content/uploads/2016/02/ASERT-Threat-Intelligence-Brief-2016-02-Corebot-1.pdf", "https://www.arbornetworks.com/blog/asert/wp-content/uploads/2016/02/ASERT-Threat-Intelligence-Brief-2016-02-Corebot-1.pdf",
"https://malwarebreakdown.com/2017/09/11/re-details-malspam-downloads-corebot-banking-trojan/" "https://malwarebreakdown.com/2017/09/11/re-details-malspam-downloads-corebot-banking-trojan/"
], ]
"date": "Discovered ~Fall 2015"
}, },
"description": "Corebot is a modular trojan that leverages a banking module that can perform browser hooking, form grabbing, MitM, webinjection to steal financial information from victims. Distributed primarily via malspam emails and exploit kits.", "description": "Corebot is a modular trojan that leverages a banking module that can perform browser hooking, form grabbing, MitM, webinjection to steal financial information from victims. Distributed primarily via malspam emails and exploit kits.",
"value": "Corebot", "value": "Corebot",
@ -351,6 +355,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~December 2016",
"refs": [ "refs": [
"https://securelist.com/the-nukebot-banking-trojan-from-rough-drafts-to-real-threats/78957/", "https://securelist.com/the-nukebot-banking-trojan-from-rough-drafts-to-real-threats/78957/",
"https://www.arbornetworks.com/blog/asert/dismantling-nuclear-bot/", "https://www.arbornetworks.com/blog/asert/dismantling-nuclear-bot/",
@ -363,8 +368,7 @@
"Nuclear Bot", "Nuclear Bot",
"MicroBankingTrojan", "MicroBankingTrojan",
"Xbot" "Xbot"
], ]
"date": "Discovered ~December 2016"
}, },
"description": "TinyNuke is a modular banking trojan that includes a HiddenDesktop/VNC server and reverse SOCKS 4 server. It's main functionality is to make web injections into specific pages to steal user data. Distributed primarily via malspam emails and exploit kits.", "description": "TinyNuke is a modular banking trojan that includes a HiddenDesktop/VNC server and reverse SOCKS 4 server. It's main functionality is to make web injections into specific pages to steal user data. Distributed primarily via malspam emails and exploit kits.",
"value": "TinyNuke", "value": "TinyNuke",
@ -372,6 +376,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered in 2014",
"refs": [ "refs": [
"https://www.govcert.admin.ch/blog/33/the-retefe-saga", "https://www.govcert.admin.ch/blog/33/the-retefe-saga",
"https://threatpost.com/eternalblue-exploit-used-in-retefe-banking-trojan-campaign/128103/", "https://threatpost.com/eternalblue-exploit-used-in-retefe-banking-trojan-campaign/128103/",
@ -382,8 +387,7 @@
"synonyms": [ "synonyms": [
"Tsukuba", "Tsukuba",
"Werdlod" "Werdlod"
], ]
"date": "Discovered in 2014"
}, },
"description": "Retefe is a banking trojan that is distributed by what SWITCH CERT calls the Retefe gang or Operation Emmental. It uses geolocation based targeting. It also leverages fake root certificate and changes the DNS server for domain name resolution in order to display fake banking websites to victims. It is spread primarily through malspam emails. ", "description": "Retefe is a banking trojan that is distributed by what SWITCH CERT calls the Retefe gang or Operation Emmental. It uses geolocation based targeting. It also leverages fake root certificate and changes the DNS server for domain name resolution in order to display fake banking websites to victims. It is spread primarily through malspam emails. ",
"value": "Retefe", "value": "Retefe",
@ -391,13 +395,13 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~early 2015",
"refs": [ "refs": [
"http://www.malwaredigger.com/2015/06/rovnix-payload-and-plugin-analysis.html", "http://www.malwaredigger.com/2015/06/rovnix-payload-and-plugin-analysis.html",
"https://www.symantec.com/connect/blogs/new-carberp-variant-heads-down-under", "https://www.symantec.com/connect/blogs/new-carberp-variant-heads-down-under",
"http://www.malwaredigger.com/2015/05/rovnix-dropper-analysis.html", "http://www.malwaredigger.com/2015/05/rovnix-dropper-analysis.html",
"http://blog.trendmicro.com/trendlabs-security-intelligence/rovnix-infects-systems-with-password-protected-macros/" "http://blog.trendmicro.com/trendlabs-security-intelligence/rovnix-infects-systems-with-password-protected-macros/"
], ]
"date": "Discovered ~early 2015"
}, },
"description": "ReactorBot is sometimes mistakenly tagged as Rovnix. ReactorBot is a full fledged modular bot that includes a banking module that has roots with the Carberp banking trojan. Distributed primarily via malspam emails.", "description": "ReactorBot is sometimes mistakenly tagged as Rovnix. ReactorBot is a full fledged modular bot that includes a banking module that has roots with the Carberp banking trojan. Distributed primarily via malspam emails.",
"value": "ReactorBot", "value": "ReactorBot",
@ -405,10 +409,10 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~Spring 2017",
"refs": [ "refs": [
"https://www.arbornetworks.com/blog/asert/another-banker-enters-matrix/" "https://www.arbornetworks.com/blog/asert/another-banker-enters-matrix/"
], ]
"date": "Discovered ~Spring 2017"
}, },
"description": "Matrix Banker is named accordingly because of the Matrix reference in it's C2 panel. Distributed primarily via malspam emails.", "description": "Matrix Banker is named accordingly because of the Matrix reference in it's C2 panel. Distributed primarily via malspam emails.",
"value": "Matrix Banker", "value": "Matrix Banker",
@ -416,11 +420,11 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~Sept. 2011",
"refs": [ "refs": [
"https://heimdalsecurity.com/blog/zeus-gameover/", "https://heimdalsecurity.com/blog/zeus-gameover/",
"https://www.us-cert.gov/ncas/alerts/TA14-150A" "https://www.us-cert.gov/ncas/alerts/TA14-150A"
], ]
"date": "Discovered ~Sept. 2011"
}, },
"description": "Zeus Gameover captures banking credentials from infected computers, then use those credentials to initiate or re-direct wire transfers to accounts overseas that are controlled by the criminals. GameOver has a decentralized, peer-to-peer command and control infrastructure rather than centralized points of origin. Distributed primarily via malspam emails and exploit kits.", "description": "Zeus Gameover captures banking credentials from infected computers, then use those credentials to initiate or re-direct wire transfers to accounts overseas that are controlled by the criminals. GameOver has a decentralized, peer-to-peer command and control infrastructure rather than centralized points of origin. Distributed primarily via malspam emails and exploit kits.",
"value": "Zeus Gameover", "value": "Zeus Gameover",
@ -428,12 +432,12 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered early 2011",
"refs": [ "refs": [
"https://www.ioactive.com/pdfs/ZeusSpyEyeBankingTrojanAnalysis.pdf", "https://www.ioactive.com/pdfs/ZeusSpyEyeBankingTrojanAnalysis.pdf",
"https://www.computerworld.com/article/2509482/security0/spyeye-trojan-defeating-online-banking-defenses.html", "https://www.computerworld.com/article/2509482/security0/spyeye-trojan-defeating-online-banking-defenses.html",
"https://www.symantec.com/connect/blogs/spyeye-bot-versus-zeus-bot" "https://www.symantec.com/connect/blogs/spyeye-bot-versus-zeus-bot"
], ]
"date": "Discovered early 2011"
}, },
"description": "SpyEye is a similar to the Zeus botnet banking trojan. It utilizes a web control panel for C2 and can perform form grabbing, autofill credit card modules, ftp grabber, pop3 grabber and HTTP basic access authorization grabber. It also contained a Kill Zeus feature which would remove any Zeus infections if SpyEye was on the system. Distributed primarily via exploit kits and malspam emails.", "description": "SpyEye is a similar to the Zeus botnet banking trojan. It utilizes a web control panel for C2 and can perform form grabbing, autofill credit card modules, ftp grabber, pop3 grabber and HTTP basic access authorization grabber. It also contained a Kill Zeus feature which would remove any Zeus infections if SpyEye was on the system. Distributed primarily via exploit kits and malspam emails.",
"value": "SpyEye", "value": "SpyEye",
@ -441,12 +445,12 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~January 2012",
"refs": [ "refs": [
"https://blog.malwarebytes.com/threat-analysis/2012/11/citadel-a-cyber-criminals-ultimate-weapon/", "https://blog.malwarebytes.com/threat-analysis/2012/11/citadel-a-cyber-criminals-ultimate-weapon/",
"https://krebsonsecurity.com/tag/citadel-trojan/", "https://krebsonsecurity.com/tag/citadel-trojan/",
"https://securityintelligence.com/cybercriminals-use-citadel-compromise-password-management-authentication-solutions/" "https://securityintelligence.com/cybercriminals-use-citadel-compromise-password-management-authentication-solutions/"
], ]
"date": "Discovered ~January 2012"
}, },
"description": "Citadel is an offspring of the Zeus banking trojan. Delivered primarily via exploit kits.", "description": "Citadel is an offspring of the Zeus banking trojan. Delivered primarily via exploit kits.",
"value": "Citadel", "value": "Citadel",
@ -454,11 +458,11 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~spring 2016",
"refs": [ "refs": [
"https://heimdalsecurity.com/blog/security-alert-citadel-trojan-resurfaces-atmos-zeus-legacy/", "https://heimdalsecurity.com/blog/security-alert-citadel-trojan-resurfaces-atmos-zeus-legacy/",
"http://www.xylibox.com/2016/02/citadel-0011-atmos.html" "http://www.xylibox.com/2016/02/citadel-0011-atmos.html"
], ]
"date": "Discovered ~spring 2016"
}, },
"description": "Atmos is derived from the Citadel banking trojan. Delivered primarily via exploit kits and malspam emails.", "description": "Atmos is derived from the Citadel banking trojan. Delivered primarily via exploit kits and malspam emails.",
"value": "Atmos", "value": "Atmos",
@ -466,10 +470,10 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~Fall 2011",
"refs": [ "refs": [
"https://securelist.com/ice-ix-not-cool-at-all/29111/ " "https://securelist.com/ice-ix-not-cool-at-all/29111/ "
], ]
"date": "Discovered ~Fall 2011"
}, },
"description": "Ice IX is a bot created using the source code of ZeuS 2.0.8.9. No major improvements compared to ZeuS 2.0.8.9.", "description": "Ice IX is a bot created using the source code of ZeuS 2.0.8.9. No major improvements compared to ZeuS 2.0.8.9.",
"value": "Ice IX", "value": "Ice IX",
@ -477,10 +481,10 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered ~end of 2010",
"refs": [ "refs": [
"https://securelist.com/zeus-in-the-mobile-for-android-10/29258/" "https://securelist.com/zeus-in-the-mobile-for-android-10/29258/"
], ]
"date": "Discovered ~end of 2010"
}, },
"description": "Zeus in the mobile. Banking trojan developed for mobile devices such as Windows Mobile, Blackberry and Android.", "description": "Zeus in the mobile. Banking trojan developed for mobile devices such as Windows Mobile, Blackberry and Android.",
"value": "Zitmo", "value": "Zitmo",
@ -488,6 +492,7 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered in 2010",
"refs": [ "refs": [
"https://johannesbader.ch/2015/09/three-variants-of-murofets-dga/", "https://johannesbader.ch/2015/09/three-variants-of-murofets-dga/",
"https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/PE_LICAT.A", "https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/PE_LICAT.A",
@ -495,8 +500,7 @@
], ],
"synonyms": [ "synonyms": [
"Murofet" "Murofet"
], ]
"date": "Discovered in 2010"
}, },
"description": "Banking trojan based on Zeus V2. Murofet is a newer version of Licat found ~end of 2011", "description": "Banking trojan based on Zeus V2. Murofet is a newer version of Licat found ~end of 2011",
"value": "Licat", "value": "Licat",
@ -504,10 +508,10 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered end of 2012",
"refs": [ "refs": [
"https://blog.rapid7.com/2012/12/06/skynet-a-tor-powered-botnet-straight-from-reddit/" "https://blog.rapid7.com/2012/12/06/skynet-a-tor-powered-botnet-straight-from-reddit/"
], ]
"date": "Discovered end of 2012"
}, },
"description": "Skynet is a Tor-powered trojan with DDoS, Bitcoin mining and Banking capabilities. Spread via USENET as per rapid7.", "description": "Skynet is a Tor-powered trojan with DDoS, Bitcoin mining and Banking capabilities. Spread via USENET as per rapid7.",
"value": "Skynet", "value": "Skynet",
@ -515,50 +519,48 @@
}, },
{ {
"meta": { "meta": {
"date": "Discovered in September 2017",
"refs": [ "refs": [
"https://www.bleepingcomputer.com/news/security/new-icedid-banking-trojan-discovered/", "https://www.bleepingcomputer.com/news/security/new-icedid-banking-trojan-discovered/",
"https://securityintelligence.com/new-banking-trojan-icedid-discovered-by-ibm-x-force-research/", "https://securityintelligence.com/new-banking-trojan-icedid-discovered-by-ibm-x-force-research/",
"http://blog.talosintelligence.com/2018/04/icedid-banking-trojan.html" "http://blog.talosintelligence.com/2018/04/icedid-banking-trojan.html"
], ]
"date": "Discovered in September 2017"
}, },
"description": "According to X-Force research, the new banking Trojan emerged in the wild in September 2017, when its first test campaigns were launched. Our researchers noted that IcedID has a modular malicious code with modern banking Trojan capabilities comparable to malware such as the Zeus Trojan. At this time, the malware targets banks, payment card providers, mobile services providers, payroll, webmail and e-commerce sites in the U.S. Two major banks in the U.K. are also on the target list the malware fetches.", "description": "According to X-Force research, the new banking Trojan emerged in the wild in September 2017, when its first test campaigns were launched. Our researchers noted that IcedID has a modular malicious code with modern banking Trojan capabilities comparable to malware such as the Zeus Trojan. At this time, the malware targets banks, payment card providers, mobile services providers, payroll, webmail and e-commerce sites in the U.S. Two major banks in the U.K. are also on the target list the malware fetches.",
"value": "IcedID", "value": "IcedID",
"uuid": "9d67069c-b778-486f-8158-53f5dcd05d08" "uuid": "9d67069c-b778-486f-8158-53f5dcd05d08"
}, },
{ {
"value": "GratefulPOS",
"description": "GratefulPOS has the following functions\n1. Access arbitrary processes on the target POS system\n2. Scrape track 1 and 2 payment card data from the process(es)\n3. Exfiltrate the payment card data via lengthy encoded and obfuscated DNS queries to a hardcoded domain registered and controlled by the perpetrators, similar to that described by Paul Rascagneres in his analysis of FrameworkPOS in 2014[iii], and more recently by Luis Mendieta of Anomoli in analysis of a precursor to this sample.",
"meta": { "meta": {
"refs": [ "refs": [
"https://community.rsa.com/community/products/netwitness/blog/2017/12/08/gratefulpos-credit-card-stealing-malware-just-in-time-for-the-shopping-season" "https://community.rsa.com/community/products/netwitness/blog/2017/12/08/gratefulpos-credit-card-stealing-malware-just-in-time-for-the-shopping-season"
] ]
}, },
"description": "GratefulPOS has the following functions\n1. Access arbitrary processes on the target POS system\n2. Scrape track 1 and 2 payment card data from the process(es)\n3. Exfiltrate the payment card data via lengthy encoded and obfuscated DNS queries to a hardcoded domain registered and controlled by the perpetrators, similar to that described by Paul Rascagneres in his analysis of FrameworkPOS in 2014[iii], and more recently by Luis Mendieta of Anomoli in analysis of a precursor to this sample.",
"value": "GratefulPOS",
"uuid": "7d9362e5-e3cf-4640-88a2-3faf31952963" "uuid": "7d9362e5-e3cf-4640-88a2-3faf31952963"
}, },
{ {
"value": "Dok",
"description": "A macOS banking trojan that that redirects an infected user's web traffic in order to extract banking credentials.",
"meta": { "meta": {
"refs": [ "refs": [
"https://objective-see.com/blog/blog_0x25.html#Dok" "https://objective-see.com/blog/blog_0x25.html#Dok"
] ]
}, },
"description": "A macOS banking trojan that that redirects an infected user's web traffic in order to extract banking credentials.",
"value": "Dok",
"uuid": "e159c4f8-3c22-49f9-a60a-16588a9c22b0" "uuid": "e159c4f8-3c22-49f9-a60a-16588a9c22b0"
}, },
{ {
"value": "downAndExec",
"description": "Services like Netflix use content delivery networks (CDNs) to maximize bandwidth usage as it gives users greater speed when viewing the content, as the server is close to them and is part of the Netflix CDN. This results in faster loading times for series and movies, wherever you are in the world. But, apparently, the CDNs are starting to become a new way of spreading malware. The attack chain is very extensive, and incorporates the execution of remote scripts (similar in some respects to the recent “fileless” banking malware trend), plus the use of CDNs for command and control (C&C), and other standard techniques for the execution and protection of malware.",
"meta": { "meta": {
"refs": [ "refs": [
"https://www.welivesecurity.com/2017/09/13/downandexec-banking-malware-cdns-brazil/" "https://www.welivesecurity.com/2017/09/13/downandexec-banking-malware-cdns-brazil/"
] ]
}, },
"description": "Services like Netflix use content delivery networks (CDNs) to maximize bandwidth usage as it gives users greater speed when viewing the content, as the server is close to them and is part of the Netflix CDN. This results in faster loading times for series and movies, wherever you are in the world. But, apparently, the CDNs are starting to become a new way of spreading malware. The attack chain is very extensive, and incorporates the execution of remote scripts (similar in some respects to the recent “fileless” banking malware trend), plus the use of CDNs for command and control (C&C), and other standard techniques for the execution and protection of malware.",
"value": "downAndExec",
"uuid": "bfff538a-89dd-4bed-9ac1-b4faee373724" "uuid": "bfff538a-89dd-4bed-9ac1-b4faee373724"
}, },
{ {
"value": "Smominru",
"description": "Since the end of May 2017, we have been monitoring a Monero miner that spreads using the EternalBlue Exploit (CVE-2017-0144). The miner itself, known as Smominru (aka Ismo) has been well-documented, so we will not discuss its post-infection behavior. However, the miners use of Windows Management Infrastructure is unusual among coin mining malware.\nThe speed at which mining operations conduct mathematical operations to unlock new units of cryptocurrency is referred to as “hash power”. Based on the hash power associated with the Monero payment address for this operation, it appeared that this botnet was likely twice the size of Adylkuzz. The operators had already mined approximately 8,900 Monero (valued this week between $2.8M and $3.6M). Each day, the botnet mined roughly 24 Monero, worth an average of $8,500 this week.",
"meta": { "meta": {
"refs": [ "refs": [
"https://www.proofpoint.com/us/threat-insight/post/smominru-monero-mining-botnet-making-millions-operators" "https://www.proofpoint.com/us/threat-insight/post/smominru-monero-mining-botnet-making-millions-operators"
@ -568,16 +570,24 @@
"lsmo" "lsmo"
] ]
}, },
"description": "Since the end of May 2017, we have been monitoring a Monero miner that spreads using the EternalBlue Exploit (CVE-2017-0144). The miner itself, known as Smominru (aka Ismo) has been well-documented, so we will not discuss its post-infection behavior. However, the miners use of Windows Management Infrastructure is unusual among coin mining malware.\nThe speed at which mining operations conduct mathematical operations to unlock new units of cryptocurrency is referred to as “hash power”. Based on the hash power associated with the Monero payment address for this operation, it appeared that this botnet was likely twice the size of Adylkuzz. The operators had already mined approximately 8,900 Monero (valued this week between $2.8M and $3.6M). Each day, the botnet mined roughly 24 Monero, worth an average of $8,500 this week.",
"value": "Smominru",
"uuid": "f93acc85-8d2c-41e0-b0c5-47795b8c6194" "uuid": "f93acc85-8d2c-41e0-b0c5-47795b8c6194"
},
{
"meta": {
"refs": [
"https://www.proofpoint.com/us/threat-insight/post/danabot-new-banking-trojan-surfaces-down-under-0"
]
},
"description": "It's a Trojan that includes banking site web injections and stealer functions. It consists of a downloader component that downloads an encrypted file containing the main DLL. The DLL, in turn, connects using raw TCP connections to port 443 and downloads additional modules (i.e. VNCDLL.dll, StealerDLL.dll, ProxyDLL.dll)",
"value": "DanaBot",
"uuid": "844417c6-a404-4c4e-8e93-84db596d725b"
} }
], ],
"version": 8,
"uuid": "59f20cce-5420-4084-afd5-0884c0a83832",
"description": "A list of banker malware.",
"authors": [ "authors": [
"Unknown" "Unknown"
], ],
"source": "Open Sources",
"type": "banker", "type": "banker",
"name": "Banker" "description": "A list of banker malware."
} }

View File

@ -1,6 +1,6 @@
{ {
"uuid": "312f8714-45cb-11e7-b898-135207cdceb9", "uuid": "312f8714-45cb-11e7-b898-135207cdceb9",
"description": "remote administration tool or remote access tool (RAT), also called sometimes remote access trojan, is a piece of software or programming that allows a remote \"operator\" to control a system as if they have physical access to that system.", "name": "RAT",
"source": "MISP Project", "source": "MISP Project",
"version": 9, "version": 9,
"values": [ "values": [
@ -2480,11 +2480,21 @@
"uuid": "e9f9d900-4f9a-11e8-bce9-4bfbb0e9ab4c", "uuid": "e9f9d900-4f9a-11e8-bce9-4bfbb0e9ab4c",
"value": "Spymaster Pro", "value": "Spymaster Pro",
"description": "Monitoring Software" "description": "Monitoring Software"
},
{
"meta": {
"refs": [
"https://blog.talosintelligence.com/2018/05/navrat.html"
]
},
"description": "Classic RAT that can download, upload, execute commands on the victim host and perform keylogging. However, the command and control (C2) infrastructure is very specific. It uses the legitimate Naver email platform in order to communicate with the attackers via email",
"value": "NavRAT",
"uuid": "6ea032a0-d54a-463b-b016-2b7b9b9a5b7e"
} }
], ],
"authors": [ "authors": [
"Various" "Various"
], ],
"type": "rat", "type": "rat",
"name": "RAT" "description": "remote administration tool or remote access tool (RAT), also called sometimes remote access trojan, is a piece of software or programming that allows a remote \"operator\" to control a system as if they have physical access to that system."
} }