Welcome back to our Triage Thursday blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Families This Week
- Added detection and extraction for ServStart, Windows backdoor
- ServStart sample:
- Added detection and extraction for GhostPenguin, Linux backdoor
- GhostPenguin sample:
- Added extraction support for CoffLoader, Windows loader
- CoffLoader sample:
- Added detection for PixStealer, Android banking trojan
- PixStealer sample:
- Added detection for PegasusLoader, Windows loader
- PegasusLoader sample:
- Added detection for MicroStealer, Java based stealer
- MicroStealer sample:
- Added detection for DattoRMM, Windows RMM software
- sample:
- Added detection for GobRAT, Linux RAT
- GobRAT sample:
- Added detection for PassCat, Windows hacktool
- PassCat sample:
- Added detection for DOPLUGS, a variant of Plugx
- DOPLUGS sample:
- Added detection for KazakRAT, Windows RAT
- KazakRAT sample:
- Added detection for Farfli family, Windows backdoor
- Farfli sample:
- Added detection for PUBLOAD Loader & Shellcode. Windows APT
- PUBLOAD sample:
- Added detection for ProRat, Windows RAT
- ProRat sample:
- Added detection for Stihat family, Windows worm
- Stihat sample:
Added Detection for Windows Stealer Families
- UnixStelaer sample:
- BRSStealer sample:
- RootTeamStealer sample:
- ScarletStealer sample:
- Zeromax sample:
- QvoidStealer sample:
New Ransomware Detection
- Cactus sample:
- Vohuk sample:
- NominatusCrypto sample:
- AESRT sample:
- Pandora sample:
Updates for Existing Families
- Updated detection for Novablight, Windows stealer
- Novablight sample:
If you have any feedback, questions, or issues about Triage feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.