Difference between revisions of "Dridex"

From Botnets.fr
Jump to navigation Jump to search
Line 1: Line 1:
{{Botnet
{{Botnet
|Alias=Dyre, Dyreza,
|Alias=Dyre, Dyreza, Dyzap, Dyranges,
|Parent=Feodo,
|Parent=Feodo,
|Vector=Spam,
|Vector=Spam, Cutwail, Dropbox, Cubby, Upatre, Gozi Neverquest,
|CCProtocol=HTTP, SSL, I2P,
|Feature=Banking credential theft, Man in the browser, Backconnect server, Custom C&C encryption algorithm, Domain generation algorithm,
|Status=Active
|BeginYear=2014
|Group=Banking,
|Group=Banking,
}}
}}

Revision as of 15:00, 5 August 2015

(Botnet) Link to the old Wiki page : [1] / Google search: [2]

Dridex
Alias Dyre, Dyreza, Dyzap, Dyranges
Group Banking
Parent Feodo
Sibling
Family
Relations Variants:

Sibling of:
Parent of:
Distribution of:
Campaigns:

Target
Origin
Distribution vector Spam, Cutwail, Dropbox, Cubby, Upatre, Gozi Neverquest
UserAgent
CCProtocol HTTP (Centralized), SSL (), I2P (Decentralized)
Activity 2014 /
Status Active
Language
Programming language
Operation/Working group

Introduction

Features


Associated images

Checksums / AV databases

Publications

 AuthorEditorYear
Banking trojan Dridex uses macros for infectionRhena InocencioTrend Micro2014
Chasing cybercrime: network insights of Dyre and Dridex trojan bankersBluelivBlueliv2015
Dridex learns new trick: P2P over HTTPS21sec EcrimeS21sec2014