|
|
Phoenix RAT Information
| Name: |
Phoenix |
| Category: |
RAT |
| Alias: |
- Alias: BackDoor-EC, Backdoor.Cheeser |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
|
| Signatures:
|
process: your_identification_string.phserver.exe: MD5 Hash: fcd4bf231e43a81062a...
process: phclient.exe: MD5 Hash: 1e25fae127ae25f5f75...
process: phserver.exe: MD5 Hash: 0a681ae1ce4d9da5a50...
process: 1696282770.exe: MD5 Hash: 7e4b5b6d589c222c841...
process: 1735424613.exe: MD5 Hash: 85a3282befc5ac6779b...
process: srvrcfg.exe: MD5 Hash: 9a6f8610c4c29d8471d...
process: phclient.exe: MD5 Hash: 155db012abddafd251b...
process: phserver.exe: MD5 Hash: 245a6112356c9f01f6e...
process: srvrcfg.exe: MD5 Hash: 0f6c1c6c1381f4a6ecb...
process: phclient.exe: MD5 Hash: f6d4ec0a3011c941c32...
process: phserver.exe: MD5 Hash: e1c3e3a53e0c02ee7d3...
process: srvrcfg.exe: MD5 Hash: f8f78881298fdb513f8...
process: phclient.exe: MD5 Hash: 0bd44cbfd729e6cd322...
process: phserver.exe: MD5 Hash: 0dcfc0367afb61fe0b1...
process: srvrcfg.exe: MD5 Hash: 7af3e75dd5635c1af5e...
process: the very young nudist video sample.exe: MD5 Hash: 8a2dd9a32f889b6dc69...
process: phclient.exe: MD5 Hash: 546e76c60e7f11e99a1...
process: phserver.exe: MD5 Hash: 58c8447c8068160306a...
process: srvrcfg.exe: MD5 Hash: 7f7728c4486bebe537c...
process: phclient.exe: MD5 Hash: 66ec165d4b115418f32...
process: servermaker.exe: MD5 Hash: 459459d40adfd7a2371...
process: phclient.exe: MD5 Hash: 1e46c5d09442a35508e...
process: servermaker.exe: MD5 Hash: bc9aee091e7c4580772...
process: phclient.exe: MD5 Hash: 128f836dd482aad456f...
process: servermaker.exe: MD5 Hash: 39f075894c79e021d9d...
process: phclient.exe: MD5 Hash: 3ba462cff10a093b9b0...
process: servermaker.exe: MD5 Hash: b7cee379f373d6f03d4...
process: phcleaner.exe: MD5 Hash: aea49290aec79f628e2...
process: phclient.exe: MD5 Hash: 2eceec3c2664f0c67d2...
process: servermaker.exe: MD5 Hash: 0f4548b2e36492d37dc...
process: phcleaner.exe: MD5 Hash: 466a8ab17c37611eb0a...
process: phclient.exe: MD5 Hash: ac5637edfa6111bab29...
process: servermaker.exe: MD5 Hash: 788fabe92708418d2dc...
process: phcleaner.exe: MD5 Hash: 5bb0f9f62394f850005...
process: phclient.exe: MD5 Hash: 830e74eedb69bdcd768...
process: servermaker.exe: MD5 Hash: 86d7a3937bb6b78619e...
process: phclient.exe: MD5 Hash: dfa92c077c6abfec68f...
process: phserver.exe: MD5 Hash: f428cc6fcc65e675d2f.. |
| Type: |
RAT - A Remote Administration Tool (RAT) is a Trojan type of software that when run, provides an attacker with the capability of remotely controlling a user's computer (victim) over the Internet. The attacker usually has full access to functions on the victim's computer. The victim's computer usually listens on the Internet for the attacker's commands. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 295 visits
NetBus v.1.70 - 210 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 69 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 55 visits
Systray BackDoor - 53 visits
AutoSpY - Alias: Backdoor.AutoSpy - 49 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 47 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 42 visits
Netbus - Alias: Backdoor.Netbus - 42 visits
Random RAT Pages:
Glacier - Alias: Backdoor.Delf.ax, Backdoor.G_Door.20, Backdoor.G_Door.b, Backdoor.G_Door.c, Backdoor.G_Door.d, Backd
Apdoor BackDoor
Remote Boot Tool - Alias: Backdoor.RBT.10, Backdoor.RTB.10
Hawk
KnightSeven - Alias: Backdoor.Knightseven.10
Cyber Takeover - Alias: BackDoor-JE, Backdoor.CyberTake, Backdoor.CyberTake, Cyber Takeover
SystemDebug - Alias: BackDoor-JU
Mosucker - Alias: BackDoor-EE.svr, Backdoor.Mosuck.11, Backdoor.Mosuck.20, Backdoor.Mosuck.21
Badbot
AOL Admin - Alias: BackDoor-EC, Backdoor.Cheeser
|
|