|
|
Specrem RAT Information
| Name: |
Specrem |
| Category: |
RAT |
| Alias: |
- Alias: Backdoor.Hellza.110, Backdoor.Hellza.115, Backdoor.Hellza.120 |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
|
| Signatures:
|
process: -1326332206.exe: MD5 Hash: 1d12f2d87ff407bbd17...
process: 1210744949.exe: MD5 Hash: 0ae0e86fe27f38a4b5b...
process: 1343121509.exe: MD5 Hash: 94a00ab374daa4e011e...
process: 1878034568.exe: MD5 Hash: 1cca6a9ef301c36996b...
process: smessage.exe: MD5 Hash: 5ec9b08424c3a491083...
process: SServer.exe: MD5 Hash: becf2b61005ec9b8d77...
process: register.exe: MD5 Hash: da3f420ad26bd0f9f1e...
process: sclient.exe: MD5 Hash: 5d3106981e71fdc1976...
process: servinst.exe: MD5 Hash: fcae6bf761134fbb748...
process: servunst.exe: MD5 Hash: ec81cb928909a9d28af...
process: sinstall.exe: MD5 Hash: 9444040a95d40ec34d2...
process: smessage.exe: MD5 Hash: bd99ae6c0c1c3b81876...
process: sserver.exe: MD5 Hash: 68125d4baf57a93116f...
process: stools.exe: MD5 Hash: 9350a62d0eaf86527de...
process: register.exe: MD5 Hash: 9249aab1bcf1b9a4800...
process: sclient.exe: MD5 Hash: 799734e0b3e092be046...
process: servinst.exe: MD5 Hash: 424803a2c6656ec0ad8...
process: servunst.exe: MD5 Hash: 0dfa656dd1f755647c5...
process: sinstall.exe: MD5 Hash: 9cf11b581f39a50ec52...
process: smessage.exe: MD5 Hash: 964c42550558f0aa014...
process: sserver.exe: MD5 Hash: 361cf7bdab76e372a3b...
process: stools.exe: MD5 Hash: 8aaa85c32847f280992...
process: register.exe: MD5 Hash: 54f05965163639d99a9...
process: sclient.exe: MD5 Hash: c17ddd504ad0aeec2f0...
process: servinst.exe: MD5 Hash: 61664fe670148ca614b...
process: servunst.exe: MD5 Hash: 2665bc0fb50dbfbecc5...
process: sinstall.exe: MD5 Hash: f686542e84962792dc0...
process: sserver.exe: MD5 Hash: f6385d990dc4300b04f...
process: stools.exe: MD5 Hash: 84d32ae0493cfc4e4ff...
process: specrem5.0.exe: MD5 Hash: d9ee5ec7a4f682e517a...
process: register.exe: MD5 Hash: 18a562cb21f5232b84e...
process: sclient.exe: MD5 Hash: e6ea58cfad8d286be7e...
process: sinstall.exe: MD5 Hash: 8d8138a2bd8855661fe...
process: sserver.exe: MD5 Hash: 17d12ff5147f3454497...
process: stools.exe: MD5 Hash: e18141e4cbefb1af80b...
process: updater.exe: MD5 Hash: d3c312f6d14e206e2fa...
process: sbc.exe: MD5 Hash: 7439033ed1deac82a3f...
process: sclient.exe: MD5 Hash: 8aec5092d32a3773d6b...
process: sinstall.exe: MD5 Hash: 3374bacbbe4f28fe018...
process: smessage.exe: MD5 Hash: 6d31a925c230029c7e7...
process: sserver.exe: MD5 Hash: 3d4b21f54f713a68921.. |
| Type: |
RAT - A Remote Administration Tool (RAT) is a Trojan type of software that when run, provides an attacker with the capability of remotely controlling a user's computer (victim) over the Internet. The attacker usually has full access to functions on the victim's computer. The victim's computer usually listens on the Internet for the attacker's commands. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 292 visits
NetBus v.1.70 - 207 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 69 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 54 visits
Systray BackDoor - 52 visits
AutoSpY - Alias: Backdoor.AutoSpy - 47 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 46 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 41 visits
Netbus - Alias: Backdoor.Netbus - 41 visits
Random RAT Pages:
Micro Bot - Alias: Backdoor.Aphexdoor.10, Micro Bot 1.0
Starline - Alias: Backdoor.Starline
Tank Commando Crew
Apdoor BackDoor
Telserver
Psychofiles - Alias: Backdoor.Psyf.171
RAT - Alias: Backdoor.RAT.b
IRC Contact - Alias: Backdoor.IrcContact.10, IRC-Contact
RemoteExec
Hellz Addiction - Alias: Backdoor.Hellza.110, Backdoor.Hellza.115, Backdoor.Hellza.120
|
|