|
|
The Thing RAT Information
| Name: |
The Thing |
| Category: |
RAT |
| Alias: |
- Alias: Backdoor.NetTaxi.18 |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
|
| Signatures:
|
process: client.exe: MD5 Hash: 9ca57cb954c63479eee...
process: thing.exe: MD5 Hash: 5b985c71287543bae6e...
process: thing.exe: MD5 Hash: 3b48faaf0ce85be3b1b...
process: client.exe: MD5 Hash: 8d2a3443f427d645ab2...
process: windll32.exe: MD5 Hash: cc4358c5d4c7aad9d69...
process: clspack.exe.bak: MD5 Hash: ce52a5781e5de52f082...
process: server.exe: MD5 Hash: f4aae8d54e01478ae88...
process: client.exe: MD5 Hash: a842fc93eb09cf5e0bf...
process: client.exe: MD5 Hash: a044746004d9ec295f2...
process: client.exe: MD5 Hash: 6eb33d3cf90480738ef...
process: editsrv1.exe: MD5 Hash: b3a6348fc1dea082c08...
process: netxvld.exe: MD5 Hash: 844bc8526a880194d84...
process: server.exe: MD5 Hash: 7dbbc656207fa0b2b58...
process: 592965-3bb.exe: MD5 Hash: 9ac9023f787481c8e74...
process: 849cd7cf.exe: MD5 Hash: 2c97e271a0791306d0a...
process: client.exe: MD5 Hash: b2eafd0a13d7cbbbde3...
process: editsrv1.exe: MD5 Hash: 48e1d58bd077ac32483...
process: hello$.exe: MD5 Hash: b091d3f75ff46d06d15...
process: hello.exe: MD5 Hash: e012378f22f92198200...
process: newclient.exe: MD5 Hash: 29ff0c2dadf263e7a81...
process: onz.exe: MD5 Hash: 6a910f2eae289ad248d...
process: server.exe: MD5 Hash: ab6a41c4e913fcd3d2b...
process: xzip.exe: MD5 Hash: 5b9f06a5288f68b6c5d.. |
| Type: |
RAT - A Remote Administration Tool (RAT) is a Trojan type of software that when run, provides an attacker with the capability of remotely controlling a user's computer (victim) over the Internet. The attacker usually has full access to functions on the victim's computer. The victim's computer usually listens on the Internet for the attacker's commands. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 295 visits
NetBus v.1.70 - 210 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 69 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 55 visits
Systray BackDoor - 53 visits
AutoSpY - Alias: Backdoor.AutoSpy - 49 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 47 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 42 visits
Netbus - Alias: Backdoor.Netbus - 42 visits
Random RAT Pages:
InetSpy - Alias: BackDoor-N, Backdoor.InetSpy.10, Backdoor.InetSpy.10
Serveme - Alias: BackDoor-VV, Backdoor.ServeMe
Backstabb Lite
Controlpanel - Alias: VB-BackDoor1.gen trojan
Whomp Downloader
BLA
Near Mohists - Alias: Backdoor.Jinmoze.105, Backdoor.Jinmoze.106, Backdoor.Jinmoze.180, Backdoor.Jinmoze.181, Backdoor.Jin
Look Spy - Alias: Backdoor.LookSpy, LookSpy
Back Orafice Cast
Net Taxi - Alias: Backdoor.NetTaxi.18
|
|