Welcome back to our Triage Thursday blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Families This Week
- Added detection for KillMBR, Windows trojan
- KillMBR sample:
- Added detection for GhostBat RAT, Android malware
- GhostBat RAT sample:
- Added detection for SimpleHelp, RMM tool
- SimpleHelp sample:
- Added detection for Iris Stealer, Windows stealer packed with PyInstaller
- Iris Stealer sample:
- Added detection for SoranoStealer, Windows stealer
- SoranoStealer sample:
- Added detection to PillagerStealer, Windows stealer
- PillagerStealer sample:
- Added detection for CerbfyneStealer, Windows stealer
- CerbfyneStealer sample:
- Added detection for Powersploit, Windows post-exploitation framework
- Powersploit sample:
New Ransomware Detection
- Added detection for Nabucur, Windows ransomware
- Nabucur sample:
Updates for Existing Families
- Updated detection for Ghostsocks, Windows proxy
- Ghostsocks sample:
- Updated detection for Nirsoft, Windows EdgeCookiesView tool
- Updated for Vidar obfuscated loader
- Vidar sample:
If you have any feedback, questions, or issues about Triage feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.