Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection and extraction for DarthVader, Windows stealer
- DarthVader sample:
- Added detection and extraction for ArtemisRAT, Windows RAT
- ArtemisRAT sample:
- Added detection and extraction for XVClipper, Windows clipper
- XVClipper sample:
- Added detection for Gazer, Windows backdoor
- Gazer sample:
- Added detection for Gomet, Windows backdoor
- Gomet sample:
- Added detection for GraphWorm, Windows backdoor
- GraphWorm sample:
- Added detection for WormHole, Windows proxy
- WormHole sample:
- Added detection for BLUEWIPE, Windows wiper
- BLUEWIPE sample:
- Added detection for BrushLogger, Windows keylogger
- BrushLogger sample:
Detection for Android
- Added detection for Dendroid, Android RAT
- Dendroid sample:
- Added detection for Koler, Android ransomware
- Koler sample:
- Added detection for MouaBad, Android trojan
- MouaBad sample:
- Added detection for Ashas, Android adware
- Ashas sample:
- Added detection for ATANK, Android ransomware
- ATANK sample:
- Added detection for Titan, Android surveillanceware
- Titan sample:
- Added detection for BADBOX, Android botnet
- BADBOX sample:
- Added detection for BADCALL, Android RAT
- BADCALL sample:
- Added detection for Basbanke, Android banking trojan
- Basbanke sample:
- Added detection for Connic, Android banking trojan
- Connic sample:
- Added detection for Cpuminer, Android miner
- Cpuminer sample:
- Added detection for Cloud Atlas (Inception Framework), Android RAT
- CloudAtlas sample:
- Added detection for BoneSpy, Android surveillanceware
- BoneSpy sample:
- Added detection for ANDROSNATCH, Android Chrome stealer (ELF)
- ANDROSNATCH sample:
Detection for Ransomware
- Global sample:
- GoCryptoLocker sample:
- HardBit sample:
- Heda sample:
- Hermes sample:
- HexaLocker sample:
- Horsedeal sample:
- Intercobros sample:
Updates for Existing Families
- Updated detection and extractor for Vidar 1.8 variant
- Vidar samples:
- Updated detection and extraction for StealC new variant
- StealC sample:
- Updated detection and extraction for xtinyloader
- xtinyloader sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.