Difference between revisions of "Expiro"

From Botnets.fr
Jump to navigation Jump to search
 
m (Text replacement - "=Unknown" to "=")
 
(4 intermediate revisions by the same user not shown)
Line 1: Line 1:
{{Botnet
{{Botnet
|Introduction=
|Alias=Xpiro,
|Target=Microsoft Windows
|CCProtocol=HTTP
|Feature=Credit card data theft, SOCKS, HTTP proxy, TCP flood, Chrome browser extension, Mozilla browser extension, URL redirection, FileZilla password theft, Outlook password theft, Internet Explorer password theft, Cross-infection,
|Status=
|BeginYear=
|EndYear=
|Group=Stealing, Click frauding,
|Fonctionnalités=* [[feature::Cross-infection]]
|Fonctionnalités=* [[feature::Cross-infection]]
* [[feature::Browser password theft]] (Internet Explorer)
* [[feature::Browser password theft]] (Internet Explorer)
Line 14: Line 21:
|Infrastructure=
|Infrastructure=
|Commercialisation=
|Commercialisation=
|UserAgent=Unknown
|UserAgent2=
|UserAgent2=
|UserAgent3=
|UserAgent3=
Line 23: Line 29:
|Language3=
|Language3=
|Language4=
|Language4=
|CCProtocol=HTTP
|CC2=
|CC2=
|CC3=
|CC3=
|Target=Microsoft Windows
|OS2=
|OS2=
|OS3=
|OS3=
|OS4=
|OS4=
|Status=Unknown
|BeginYear=Unknown
|EndYear=Unknown
|Group=
|Groupe2=
|Groupe2=
|Alias=Xpiro
|Vendor1=Symantec
|Vendor1=Symantec
|Alias=
|Vendor2=
|Vendor2=
|Alias=
|Vendor3=
|Vendor3=
|Alias=
|Vendor4=
|Vendor4=
|Alias=
|Vendor5=
|Vendor5=
|Alias=
|Vendor6=
|Vendor6=
|Alias=
|Vendor7=
|Vendor7=
|Alias=
|Vendor8=
|Vendor8=
|Alias=
|Vendor9=
|Vendor9=
|Alias=
|Vendor10=
|Vendor10=
|Vector=
|Exploitkit2=
|Exploitkit2=
|Exploitkit3=
|Exploitkit3=

Latest revision as of 15:45, 8 August 2015

(Botnet) Link to the old Wiki page : [1] / Google search: [2]

Expiro
Alias Xpiro
Group Stealing, Click frauding
Parent
Sibling
Family
Relations Variants:

Sibling of:
Parent of:
Distribution of:
Campaigns:

Target Microsoft Windows
Origin
Distribution vector
UserAgent
CCProtocol HTTP (Centralized)
Activity /
Status
Language
Programming language
Operation/Working group

Introduction

Features


Associated images

Checksums / AV databases

Publications

 AuthorEditorYear
File infector Expiro hits US, steals FTP credentialsRhena InocencioTrend Micro2013
First widespread virus cross-infectionJeet MorpariaSymantec2013
Versatile and infectious: Win64/Expiro is a cross-platform file infectorArtem I. BaranovESET2013