diff --git a/galaxy.html b/galaxy.html index 1f5e568..e43bfdf 100755 --- a/galaxy.html +++ b/galaxy.html @@ -445,6 +445,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
A list of backdoor malware..
++ + | ++Backdoor is a cluster galaxy available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
raw-data
+Cross-platform malware written in Golang, compatible with Linux and Windows. Although there are some minor differences, both variants have the same functionality. The malware communicates with a CnC server using HTTP requests and performs functions based on the received commands. Results of command execution are sent in HTTP POST requests data (RSA-encrypted). Main functionalities are: (1) Execute arbitrary shell commands, (2) Upload/Download files. The PE variant of the infection, in addition, executes PowerShell scripts. A .Net version was also observed in the wild.
+Links |
+
+ |
Bebloh is also known as:
+URLZone
+Shiotob
+Links |
+
+ |
https://www.symantec.com/security-center/writeup/2011-041411-0912-99 |
+
Banjori is also known as:
+MultiBanker 2
+BankPatch
+BackPatcher
+Links |
+
+ |
Links |
+
https://www.countercept.com/our-thinking/decrypting-qadars-banking-trojan-c2-traffic/ |
+
Links |
+
+ |
Links |
+
+ |
Links |
+
+ |
Trojan under development and already being distributed through the RIG Exploit Kit. Observed code similarities with other well-known bankers such as Ramnit, Vawtrak and TrickBot. Karius works in a rather traditional fashion to other banking malware and consists of three components (injector32\64.exe, proxy32\64.dll and mod32\64.dll), these components essentially work together to deploy webinjects in several browsers.
Trik Spam Botnet is also known as:
+Trik Trojan
+Links |
+
https://www.bleepingcomputer.com/news/security/trik-spam-botnet-leaks-43-million-email-addresses/ |
+
Madmax is also known as:
+Mad Max
+Links |
+
+ |
Links |
+
https://labs.bitdefender.com/2013/12/in-depth-analysis-of-pushdo-botnet/ |
+
Links |
+
+ |
Links |
+
+ |
Links |
+
+ |
Bamital is also known as:
+Mdrop-CSK
+Agent-OCF
+Links |
+
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Win32%2FBamital |
+
https://www.symantec.com/security-center/writeup/2010-070108-5941-99 |
+