Difference between revisions of "Clampi"

From Botnets.fr
Jump to navigation Jump to search
m (Text replacement - "=Unknown" to "=")
 
Line 7: Line 7:
|Target=Microsoft Windows, United States,
|Target=Microsoft Windows, United States,
|Feature=VMProtect, Password theft,
|Feature=VMProtect, Password theft,
|Status=Unknown
|Status=
|BeginYear=2005
|BeginYear=2005
|EndYear=Unknown
|EndYear=
|Group=Stealing,
|Group=Stealing,
|Fonctionnalités=* Vol d'identifiants et mots de passe
|Fonctionnalités=* Vol d'identifiants et mots de passe

Latest revision as of 15:45, 8 August 2015

(Botnet) Link to the old Wiki page : [1] / Google search: [2]

Clampi
Alias Ligats, Rscan, Ilomo
Group Stealing
Parent
Sibling
Family
Relations Variants:

Sibling of:
Parent of:
Distribution of:
Campaigns:

Target Microsoft Windows, United States
Origin
Distribution vector
UserAgent
CCProtocol
Activity 2005 /
Status
Language
Programming language
Operation/Working group

Introduction

Le bot derrière le botnet Clampi (ou Ligats, Rscan, Ilomo) est formé par deux exécutables:

Les deux sont souvent détectés séparément par les logiciels antivirus.

Features


Associated images

Checksums / AV databases

Publications

 AuthorEditorYear
A study of the Ilomo / Clampi botnetAlice Decker
Max Goncharov
Robert McArdle
David Sancho
Trend Micro2009
Clampi/Ligats/Ilomo trojanJoe StewartDELL SecureWorks2009
The growing threat to business banking onlineBrian KrebsWashington Post2009