Spyder |
4 2021
Winnti, ShadowPad, . , PlugX, ShadowPad . .
, APT- Winnti.
C:\Windows\System32 oci.dll. , MSDTC (Microsoft Distributed Transaction Coordinator) DLL Hijacking. , 2020 , . , MSDTC, .
Log Name: System
Source: Service Control Manager
Date: 23.11.2020 5:45:17
Event ID: 7045
Task Category: None
Level: Information
Keywords: Classic
User:
Computer:
Description:
A service was installed in the system.
Service Name: IIJVXRUMDIKZTTLAMONQ
Service File Name: net start msdtc
Service Type: user mode service
Service Start Type: demand start
Service Account: LocalSystem
Log Name: System
Source: Service Control Manager
Date: 23.11.2020 5:42:20
Event ID: 7045
Task Category: None
Level: Information
Keywords: Classic
User:
Computer:
Description:
A service was installed in the system.
Service Name: AVNUXWSHUNXUGGAUXBRE
Service File Name: net stop msdtc
Service Type: user mode service
Service Start Type: demand start
Service Account: LocalSystem
, C:\Windows\Temp\
, smbexec.py Impacket. .
oci.dll Dr.Web BackDoor.Spyder.1. , , , Spyder.
. -, oci.dll PE-, . , , . -, , , . . , , , Winnti, ShadowPad PlugX.
Spyder Winnti. , Crosswalk ShadowPad, Positive Technologies, Spyder. .
BackDoor.Spyder.1 PDF- Dr.Web.
BackDoor.Spyder.1 , . . , , . ShadowPad PlugX, , , Winnti.