|
|
LANfiltrator RAT Information
| Name: |
LANfiltrator |
| Category: |
RAT |
| Alias: |
- Alias: Backdoor.Netspy.10.b, Backdoor.Netspy.10.c, Backdoor.Netspy.20.b, Backdoor.Netspy.20.d, Trojan.Win32 |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
|
| Signatures:
|
process: client.exe: MD5 Hash: 672d2041d2e86d63207...
process: client.exe: MD5 Hash: a0831b2f86bb012e799...
process: edit server.exe: MD5 Hash: 9bb872da0b5e830ddb0...
process: edtsrv.exe: MD5 Hash: ad6bde07bc7e07cb2c5...
process: lanfiltrator.exe: MD5 Hash: bce30b7e368524b3297...
process: edit server.exe: MD5 Hash: 0e1fcd19e01e3015456...
process: lanfiltrator.exe: MD5 Hash: 4a5be94af9e7d367414...
process: edtsrv.exe: MD5 Hash: 5f57789e61b6db7c3f6...
process: lanfiltrator.exe: MD5 Hash: 089a1d95713f0b814f9...
process: l_server.exe: MD5 Hash: c98eeb24f2e3472ea0a...
process: client.exe: MD5 Hash: adff5051b7a145f78a4...
process: edit server.exe: MD5 Hash: 37f227fd14e650c8602...
process: client.exe: MD5 Hash: a7ea6177a4d0dd3c3dc...
process: edit server.exe: MD5 Hash: 403ea7f4b67265660e9...
process: edtsrv.exe: MD5 Hash: 388f3990956eb624411...
process: edtsrv.exe: MD5 Hash: 85ecb62b179f30a2a20...
process: lanfiltrator.exe: MD5 Hash: bd3eedf7580bc9d2f0e...
process: lanfiltrator.exe: MD5 Hash: 0080eb9652972a6a3c5...
process: l_server.exe: MD5 Hash: 02bba6c8cb514f0d7dd...
process: l_server.exe: MD5 Hash: 6486d4a537a8f913567...
process: l_server.exe: MD5 Hash: ee51b892f7c1a0fd6f1.. |
| Type: |
RAT - A Remote Administration Tool (RAT) is a Trojan type of software that when run, provides an attacker with the capability of remotely controlling a user's computer (victim) over the Internet. The attacker usually has full access to functions on the victim's computer. The victim's computer usually listens on the Internet for the attacker's commands. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 292 visits
NetBus v.1.70 - 207 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 69 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 54 visits
Systray BackDoor - 52 visits
AutoSpY - Alias: Backdoor.AutoSpy - 47 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 46 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 41 visits
Netbus - Alias: Backdoor.Netbus - 41 visits
Random RAT Pages:
Swift Remote - Alias: Backdoor.Swift.106
Evilsocks - Alias: Backdoor.Evilsock
Pizza - Alias: Backdoor-NB, Backdoor.Pizza
D86asm
HRVG2 - Alias: HRVG2
Kid Terror - Alias: BackDoor-DM, Backdoor.Kidterror.10, Kid Terror 1.0
Code_14 - Alias: Backdoor.VB.lv
WWW PW
Retribution - Alias: Backdoor.Retribution.26
NetSpy - Alias: Backdoor.Netspy.10.b, Backdoor.Netspy.10.c, Backdoor.Netspy.20.b, Backdoor.Netspy.20.d, Trojan.Win32
|
|