Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Families This Week
- Added detection and extraction for W1Kstealer, Windows stealer
- W1Kstealer sample:
- Added detection and extraction for StubWorm RAT, Windows RAT
- StubWorm sample:
- Added detection and extraction for AgarthaX family, Windows stealer
- AgarthaX sample:
- Added detection and extraction for Fletchen stealer, Windows stealer
- Fletchen sample:
- Added detection for Shellter trojan, Windows trojan
- Shellter sample:
- 260428-rrgt5aax3w sample:
- Shellter sample:
- Added detection for ApolloShadow, Windows loader
- ApolloShadow sample:
- Added detection for Veletrix malware, Windows loader
- Veletrix sample:
- Added detection for Amonetize family, Windows adware
- Amonetize sample:
- Added detection for DEFENSOR ID, Android banking trojan
- DEFENSORID sample:
- Added detection for DroidKungFu, Android trojan
- DroidKungFu sample:
- Added detection for DawDropper, Android banking dropper
- DawDropper sample:
- Added detection for CometBot, Android banking trojan
- CometBot sample:
- Added detection for Clipper, Android trojan
- Clipper sample:
- Added detection for Catelites, Android trojan
- Added detection for CarbonSteal, Android surveillanceware
- CarbonSteal sample:
- Added detection for Mirax, Android RAT
- Added detection for Perseus, Android banking trojan
- Perseus sample:
- Added detection for ASO, Android RAT
- Added detection for Dvmap, Android rooting malware
- Dvmap sample:
- Added detection for Phoenix, Android RAT
- Phoenix sample:
- Added detection for Shifu, Windows banking trojan
- Shifu sample:
- Added detection for RotaJakiro, Linux backdoor
- RotaJakiro sample:
Detection for suspicious tools
- Added detection for AureliaLoader installer sample:
- Added detection for HeartCrypt packer, Windows PaaS packer sample:
- Added detection for AdFind hacktook, Windows hacktool sample:
Added Ransomware Family This Week
- Clearwater sample:
- 8Base sample:
- Abyss sample:
- Adhubllka
- Charger sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website sample:, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge sample: to register for a free account.