Search
Keyword: win.trojan.farfrom-1
* indicates a new version of an existing rule Deep Packet Inspection Rules: Alibaba Nacos 1010971 - Alibaba Nacos AuthFilter Authentication Bypass Vulnerability (CVE-2021-29441) DCERPC Services 1010900* - Microsoft Windows SMB I...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Unix Samba 1011294 - Samba AppleDouble Remote Code Execution Vulnerability (CVE-2021-44142) Web Application PHP Based 1011286 - WordPress 'True Rank...
* indicates a new version of an existing rule Deep Packet Inspection Rules: H2 Database 1011316 - H2 Database Remote Code Execution Vulnerability (CVE-2022-23221) Trend Micro ServerProtect EarthAgent 1011312 - Identified Usage ...
* indicates a new version of an existing rule Deep Packet Inspection Rules: DCERPC Services 1011587 - Microsoft Windows Server Service Tampering Vulnerability (CVE-2022-30216) JBoss Remoting Connector Unified Invoker 1011570...
* indicates a new version of an existing rule Deep Packet Inspection Rules: DNS Client 1011875 - Exim Integer Underflow Vulnerability (CVE-2023-42118) Mail Server Exim 1011874 - Exim Remote Code Execution Vulnerability (CVE-2...
* indicates a new version of an existing rule Deep Packet Inspection Rules: GoCD Server 1011758* - GoCD Server Directory Traversal Vulnerability (CVE-2021-43287) Parse Server 1011608* - Parse Server Remote Code Execution Vulne...
* indicates a new version of an existing rule Deep Packet Inspection Rules: Arcserve Unified Data Protection 1012077* - Arcserve Unified Data Protection Remote Code Execution Vulnerability (CVE-2023-26258) Ivanti Endpoint Man...
* indicates a new version of an existing rule Deep Packet Inspection Rules: DCERPC Services - Client 1012183* - Microsoft Windows LNK File UI Misrepresentation Vulnerability Over SMB (ZDI-25-148) Redis Server 1012286 - Redis Us...
* indicates a new version of an existing rule Deep Packet Inspection Rules: DCERPC Services 1007134* - Batch File Uploaded On Network Share (ATT&CK T1021.002, T1204.002) 1007064* - Executable File Uploaded On System32 Folder Thr...
Trend Micro spotted the first OSCARBOT malware in 2007, spreading via the ASN.1 Bitstring Overflow vulnerability found in Windows NT, 2000, and XP systems. Other OSCARBOT malware propagates using any of the following routes: Via IRC Via instant messe...
The MegaCortex ransomware first appeared in January 2019 with few interesting attributes, including the use of a signed executable as part of the payload. It also appeared to offer security consulting services from the malware author. On May 1, 2019...
A denial-of-service vulnerability exists in libtasn1, a component of GnuTLS. The vulnerability is due to a flaw in parsing ASN.1 data that causes libtasn1 to ente...
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It deletes itself after execution.
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It does not have any propagation routine. It does not have any backdoor routine....
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
