SDBbot

Description

(Proofpoint) SDBbot is a new remote access Trojan (RAT) written in C++ that has been delivered by the Get2 downloader in recent TA505 campaigns. Its name is derived from the debugging log file (sdb.log.txt) and DLL name (BotDLL[.]dll) used in the initial analyzed sample. It also makes use of application shimming for persistence. SDBbot is composed of three pieces: an installer, a loader, and a RAT component.

Names

Name
SDBbot

Category

Malware

Type

  • Backdoor
  • Loader
  • Info stealer
  • Tunneling

Information

Mitre Attack

Malpedia

Other Information

Uuid

8b99f47b-f765-4128-8f44-31881f1bd3c0

Last Card Change

2022-12-30