Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware AdWind

AdWind

TLP:CLEAR
Family

Also known as: AlienSpy, JSocket, Frutas, UNRECOM, JBifrost, Sockrat

AI Analysis

No AI analysis yet.

Description

Part of Malware-as-service platform Used as a generic name for Java-based RAT Functionality - collect general system and user information - terminate process -log keystroke -take screenshot and access webcam - steal cache password from local or web forms - download and execute Malware - modify registry - download components - Denial of Service attacks - Acquire VPN certificates Initial infection vector 1. Email to JAR files attached 2. Malspam URL to downlaod the malware Persistence - Runkey - HKCU\Software\Microsoft\Windows\current version\run Hiding Uses attrib.exe Notes on Adwind The malware is not known to be proxy aware

Details

Type
Unknown
Platforms
Windows
Linux
Macos
Confidence
80%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.