Names | DNSRat DNSbot | |
Category | Malware | |
Type | Backdoor | |
Description | (Flashpoint) The second new malware sample discovered is a multiprotocol backdoor called DNSbot, which is used to exchange commands and push data to and from compromised machines. Primarily, it operates over DNS traffic, but can also switch to encrypted channels such as HTTPS or SSL, Flashpoint analysts discovered. | |
Information | <https://www.flashpoint-intel.com/blog/fin7-revisited:-inside-astra-panel-and-sqlrat-malware/> | |
Malpedia | <https://malpedia.caad.fkie.fraunhofer.de/details/js.dnsrat> |
Last change to this tool card: 23 April 2020
Download this tool card in JSON format
Previous: DNSpionage
Next: DOGCALL
Changed | Name | Country | Observed | ||
APT groups | |||||
Carbanak, Anunak | 2013-Apr 2023 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |