TONEINS
Description
(Trend Micro) Trojan.Win32.TONEINS is the installer for TONESHELL backdoors. The installer drops the TONESHELL malware to the %PUBLIC% folder and establishes the persistence for it. TONEINS malware usually comes in the lure archives, and in most cases, the name of the TONEINS DLL is libcef.dll. The malicious routine is triggered via calling its export function cef_api_hash.
Names
Name |
---|
TONEINS |
Category
Malware
Type
- Dropper
- Loader
Information
- https://www.trendmicro.com/en_us/research/22/k/earth-preta-spear-phishing-governments-worldwide.html
Other Information
Uuid
7259ece1-262f-4880-baa1-8a4e0d0f6752
Last Card Change
2022-11-19