-

   rss_drweb_about_virs

 - e-mail

 

 -

 LiveInternet.ru:
: 24.08.2009
: 606
: 0
: 0

:


Spyder

, 04 2021 . 08:00 +

PDF

4 2021

2020 , , . , , Winnti.

Winnti, ShadowPad, . , PlugX, ShadowPad . .

, APT- Winnti.

C:\Windows\System32 oci.dll. , MSDTC (Microsoft Distributed Transaction Coordinator) DLL Hijacking. , 2020 , . , MSDTC, .

Log Name:      System
Source:        Service Control Manager
Date:          23.11.2020 5:45:17
Event ID:      7045
Task Category: None
Level:         Information
Keywords:      Classic
User:          
Computer:      
Description:
A service was installed in the system.
 
Service Name:  IIJVXRUMDIKZTTLAMONQ
Service File Name:  net start msdtc
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem
Log Name:      System
Source:        Service Control Manager
Date:          23.11.2020 5:42:20
Event ID:      7045
Task Category: None
Level:         Information
Keywords:      Classic
User:          
Computer:      
Description:
A service was installed in the system.
 
Service Name:  AVNUXWSHUNXUGGAUXBRE
Service File Name:  net stop msdtc
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

, C:\Windows\Temp\\, random1 random2 . .

, smbexec.py Impacket. .

#drweb

oci.dll Dr.Web BackDoor.Spyder.1. , , , Spyder.

#drweb

. -, oci.dll PE-, . , , . -, , , . . , , , Winnti, ShadowPad PlugX.

Spyder Winnti. , Crosswalk ShadowPad, Positive Technologies, Spyder. .

#drweb

BackDoor.Spyder.1 PDF- Dr.Web.

BackDoor.Spyder.1 , . . , , . ShadowPad PlugX, , , Winnti.

https://news.drweb.ru/show/?i=14154&lng=ru&c=9


: [1] []
 

:
: 

: ( )

:

  URL