SDBbot
Description
(Proofpoint) SDBbot is a new remote access Trojan (RAT) written in C++ that has been delivered by the Get2 downloader in recent TA505 campaigns. Its name is derived from the debugging log file (sdb.log.txt) and DLL name (BotDLL[.]dll) used in the initial analyzed sample. It also makes use of application shimming for persistence. SDBbot is composed of three pieces: an installer, a loader, and a RAT component.
Names
Name |
---|
SDBbot |
Category
Malware
Type
- Backdoor
- Loader
- Info stealer
- Tunneling
Information
- https://www.proofpoint.com/us/threat-insight/post/ta505-distributes-new-sdbbot-remote-access-trojan-get2-downloader
- https://www.cyber.gov.au/acsc/view-all-content/alerts/sdbbot-targeting-health-sector
Mitre Attack
Malpedia
Other Information
Uuid
8b99f47b-f765-4128-8f44-31881f1bd3c0
Last Card Change
2022-12-30