|
|
Helios RAT Information
| Name: |
Helios |
| Category: |
RAT |
| Alias: |
- Alias: Backdoor.Subroot.13 |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
|
| Signatures:
|
process: hs-edit.exe: MD5 Hash: 344bff12d2298dccb82...
process: client.exe: MD5 Hash: 827cc71bc802f89e5e6...
process: editserver.exe: MD5 Hash: 2294c801ecc44ad335e...
process: client.exe: MD5 Hash: 1aae53a8e31da4c8676...
process: client.exe: MD5 Hash: 164aa79e9a152e03cb2...
process: editserver.exe: MD5 Hash: 48e14bcee205123491b...
process: client.exe: MD5 Hash: 0d7504ec8b3fe7016b6...
process: editserver.exe: MD5 Hash: c7c78e594fb260bff66...
process: client.exe: MD5 Hash: f8eae91e1db978b295a...
process: editserver.exe: MD5 Hash: 4a5b5ba887c1b1fa2be...
process: client.exe: MD5 Hash: 5ab5376383d632d3b09...
process: editserver.exe: MD5 Hash: e305bda7e653d343242...
process: client1.7.exe: MD5 Hash: 891c5c0f132c942c44c...
process: editserver1.7.exe: MD5 Hash: 1b6f47c169f4591f554...
process: client1.8.exe: MD5 Hash: 5683895306bc6075b02...
process: editserver1.8.exe: MD5 Hash: c17c56c595f713ad6e8...
process: client-v2.1.exe: MD5 Hash: 89392efed4d140649a7...
process: editserver-v2.1.exe: MD5 Hash: 5ea955c9bbffe5717b2...
process: client-v2.2.exe: MD5 Hash: 9c236fece24a529d1fd...
process: editserver-v2.2.exe: MD5 Hash: 9d6eb691a9ae9244722...
process: client-v2.4.exe: MD5 Hash: ec1ce14c259b9d10fa4...
process: editserver-v2.4.exe: MD5 Hash: b7eac40101579745a6a...
process: new-server.exe: MD5 Hash: cf9ad835fed904ec929...
process: client-v2.5.exe: MD5 Hash: 86ee64093c62fd5389d...
process: editserver-v2.5.exe: MD5 Hash: 2c08376e685211e4923...
process: new-server.exe: MD5 Hash: 679f0873201537f88ed...
process: client-v2.6.exe: MD5 Hash: b07a0bf03827440273b...
process: editserver-v2.6.exe: MD5 Hash: 1c69aed9c3fc85aa02f...
process: new-server.exe: MD5 Hash: 7d5a97c96c89aa598e8...
process: client-v3.0.exe: MD5 Hash: 3f007b48b1bd8d255af...
process: editserver-v3.0.exe: MD5 Hash: c10303d10dd2796c32e...
process: new-server.exe: MD5 Hash: 8a9d416b7f2482c783e...
process: helios-client-le.exe: MD5 Hash: 1ed388ba55497027b01...
process: helios-editserver-le.exe: MD5 Hash: 5bc3a69b34701b9da79...
process: scanstartup.exe: MD5 Hash: ...
process: hs-bot.exe: MD5 Hash: ...
process: hs-bot.exe: MD5 Hash: ...
process: scanstartup.exe: MD5 Hash: .. |
| Type: |
RAT - A Remote Administration Tool (RAT) is a Trojan type of software that when run, provides an attacker with the capability of remotely controlling a user's computer (victim) over the Internet. The attacker usually has full access to functions on the victim's computer. The victim's computer usually listens on the Internet for the attacker's commands. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 291 visits
NetBus v.1.70 - 207 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 69 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 54 visits
Systray BackDoor - 52 visits
AutoSpY - Alias: Backdoor.AutoSpy - 47 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 46 visits
Netbus - Alias: Backdoor.Netbus - 41 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 40 visits
Random RAT Pages:
Alicia version d - Alias: Backdoor.Alicia
Eurosol - Alias: Eurosol, Trojan.Win32.Eurosol.60
Koko Trojan - Alias: Backdoor.Kokodoor.10.a, Backdoor.Kokodoor.10.b, Backdoor.Kokodoor.20.b, TrojanDropper.Win32.Juntador
Remote XS - Alias: Backdoor.RemoteXS
Eagle Boy - Alias: Backdoor.VB.gg, TrojanDropper.Win32.FC.a
Guangwai Girl - Alias: Backdoor.GWGirl.10, Backdoor.GWGirl.12, Backdoor.GWGirl.15, Backdoor.GWGirl.151, Backdoor.GWGirl.152
Clandestine - Alias: Backdoor.Clindestine.10, Backdoor.RSC.151, TrojanDropper.Win32.Small.f
Holzpferd
Butt Trumpet
SubRoot - Alias: Backdoor.Subroot.13
|
|