Difference between revisions of "Andromeda"

From Botnets.fr
Jump to navigation Jump to search
m (Text replacement - "CC1=" to "CCProtocol=")
 
(9 intermediate revisions by the same user not shown)
Line 7: Line 7:
* SOCKS4 proxy module
* SOCKS4 proxy module
* Rootkits
* Rootkits
 
|Alias=Gamarue,
 
|Target=Microsoft Windows
|Vector=Smoke Bot,
|UserAgent=Mozilla/4.0
|CCProtocol=HTTP
|Feature=File download,
|BeginYear=2011-09
|Group=Downloading,
|Fonctionnalités=* Anti-VM/Anti-Debugging
|Fonctionnalités=* Anti-VM/Anti-Debugging
* Sandbox Detection
* Sandbox Detection
Line 17: Line 23:
     ZwResumeThread
     ZwResumeThread
     ZwUnmapViewOfSection
     ZwUnmapViewOfSection
|Commercialisation=* v 01.x : 300$
|Commercialisation=* v 01.x : 300$
* v 02.x : 500$
* v 02.x : 500$
Line 24: Line 29:
  * Keylogger : 200$
  * Keylogger : 200$
  * Ring3 Rootkit : 300$
  * Ring3 Rootkit : 300$
|UserAgent=Mozilla/4.0
|Etat=
|CCProtocol=HTTP
|OS1=Microsoft Windows
|Etat=Inconnu
|AnnéeDébut=09/2011
|AnnéeFin=Inconnu
|Groupe=Banking
|Alias1=Gamarue
|Alias1=Gamarue
|Vendor1=Microsoft
|Vendor1=Microsoft
|Victime4=
|Victime4=
}}
}}

Latest revision as of 16:02, 19 August 2015