Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection and extraction for 751Stealer, Windows stealer
- 751Stealer samples:
- Loader: 260527-trp7lsb14r
- Dll payload: 260527-tr97sad17v
- Injector: 260527-tr4p1ab15r
- 751Stealer samples:
- Added detection and extraction for AntarcidaStealer, Windows stealer
- AntarcidaStealer sample:
- Added detection and extraction for SessionStealer, Windows stealer
- SessionStealer sample:
- Added detection for ApexTraderRAT, Windows stealer
- ApexTraderRAT sample:
- Added detection for HermesStealer, Windows stealer
- HermesStealer sample:
- Added detection for ModeloRAT, Windows RAT written in Python
- ModeloRAT sample:
- Added detection for TransferLoader, Windows loader
- TransferLoader sample:
Detection for Android
- Added detection and extraction for ShadowRAT, Android RAT
- ShadowRAT sample:
- Added detection and extraction for Sparrow, Android RAT
- Sparrow sample:
- Added detection for DevilNFC, Android NFC malware
- DevilNFC sample:
- Added detection for DoubleAgent, Android RAT
- DoubleAgent sample:
- Added detection for DroidWatcher, Android surveillanceware
- DroidWatcher sample:
- Added detection for Goontact, Android spyware
- Goontact sample:
- Added detection for Konni, Android version RAT
- Konni sample:
- Added detection for NotCompatible, Android botnet
- NotCompatible sample:
- Added detection for SonicSpy, Android spyware
- SonicSpy sample:
Detection for APT Groups
- Added detection for GrimBolt backdoor, APT UNC6201
- GrimBolt sample:
- Added detection for SnowLight Loader, APT UNC5174
- SnowLight sample:
Detection for Ransomware
- OscarRansomware sample:
- FuxSocy sample:
- Sfile aka Escal sample:
- FCT sample:
- Firecrypt sample:
- FONIX sample:
- BlackCat (ELF variant, Linux ransomware) sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.