Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection and extraction for PhantomGate, Windows trojan
- PhantomGate sample:
- Added extraction for AllahcanStealer
- AllahcanStealer sample:
- Added detection for BTMOB (Windows version), Windows RAT
- BTMOB sample:
- Added detection for PotemkinLoader, Windows loader
- PotemkinLoader sample:
- Added detection for EclipseRAT, Windows RAT
- EclipseRAT sample:
Detection for Android
- Added detection for Gaganode, Android botnet
- Gaganode sample:
- Added detection for UltimaSMS, Android trojan
- UltimaSMS sample:
- Added detection for CyberAzov, Android trojan
- CyberAzov sample:
- Added detection for FakeDefend, Android infostealer
- FakeDefend sample:
- Added detection for Ghimob, Android banking trojan
- Ghimob sample:
Detection for Linux Families
- Added detection for Bifrost, Linux RAT
- Bifrost samples:
- Added detection for Apex2, cross-platform botnet (Linux/Windows/IoT)
- Apex2 sample:
Detection for Ransomware
- ESXiArgs (Linux ransomware) sample:
- Luna (Linux ransomware) sample:
- RansomExx2 (Linux ransomware) sample:
- Slam sample:
Updates for Existing Families
- Updated detection and extraction for Mirai, multi-architecture (x86, ARM, MIPS, PowerPC, Renesas, SPARC)
- Mirai samples:
- x86: 260720-lt3lqagt5w
- ARM: 260720-pcvfkahv6k
- MIPS: 260720-ltws6sdx3p
- PowerPC: 260720-lt4h1sgt6s
- Renesas: 260720-lt1gcsgt4z
- SPARC: 260720-ltyyjagt4v
- Mirai samples:
- Updated detection and extraction for RatonRAT v2.1.0
- RatonRAT sample:
- Updated detection and extractor for Xbinder
- Xbinder sample:
- Update extraction support for SentinelStealer
- SentinelStealer sample:
- Updated detection and extraction for NeptuneRAT
- NeptuneRAT sample:
- Updated detection and extractor for SheetRAT obfuscated variants
- SheetRAT sample:
- Updated detection and extraction for PhantomStealer v4.0.0
- PhantomStealer sample:
- Updated detection and extraction for DarkCloud, versions 4.9 and higher
- DarkCloud sample:
- Updated detection for MilleniumRAT
- MilleniumRAT sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.