Skip to content

Commit

Permalink
Merge pull request #191 from Delta-Sierra/master
Browse files Browse the repository at this point in the history
 add Rovnix
  • Loading branch information
Delta-Sierra authored Apr 11, 2018
2 parents 0eabb83 + 1a18ffb commit ccae073
Show file tree
Hide file tree
Showing 2 changed files with 16 additions and 2 deletions.
3 changes: 2 additions & 1 deletion clusters/banker.json
Original file line number Diff line number Diff line change
Expand Up @@ -514,7 +514,8 @@
"meta": {
"refs": [
"https://www.bleepingcomputer.com/news/security/new-icedid-banking-trojan-discovered/",
"https://securityintelligence.com/new-banking-trojan-icedid-discovered-by-ibm-x-force-research/"
"https://securityintelligence.com/new-banking-trojan-icedid-discovered-by-ibm-x-force-research/",
"http://blog.talosintelligence.com/2018/04/icedid-banking-trojan.html"
],
"date": "Discovered in September 2017"
},
Expand Down
15 changes: 14 additions & 1 deletion clusters/tool.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@
],
"description": "threat-actor-tools is an enumeration of tools used by adversaries. The list includes malware but also common software regularly used by the adversaries.",
"uuid": "0d821b68-9d82-4c6d-86a6-1071a9e0f79f",
"version": 62,
"version": 63,
"values": [
{
"meta": {
Expand Down Expand Up @@ -4126,6 +4126,19 @@
]
},
"uuid": "8c0a7e1e-3cc4-11e8-8f03-2f71e72f737b"
},
{
"value": "Rovnix",
"description": "We recently found that the malware family ROVNIX is capable of being distributed via macro downloader. This malware technique was previously seen in the DRIDEX malware, which was notable for using the same routines. DRIDEX is also known as the successor of the banking malware CRIDEX.",
"meta": {
"refs": [
"https://blog.trendmicro.com/trendlabs-security-intelligence/rovnix-infects-systems-with-password-protected-macros/"
],
"synonyms": [
"ROVNIX"
]
},
"uuid": "a4036a28-3d94-11e8-ad9f-97ada3c6d5fb"
}
]
}

0 comments on commit ccae073

Please sign in to comment.