MDNC | Malware don't need Coffee
Navigation
Search
FAQ
Contact
Blog
External
References
Actors
Authors
CVEs
EKs (Exploit Kits)
Malware
TDS (Traffic Distribution Systems)
Archive
References
Actors
TA554
References:
sLoad and Ramnit pairing in sustained campaigns against UK and Italy
- 2018-10-23 - Proofpoint -
Proofpoint Staff
TA554
sLoad
Ramnit
PsiXBot
Gootkit
Snatch
More Reading:
SnatchLoader Reloaded
- 2017-10-27 - Arbor -
Dennis Schwarz
Snatch
Ramnit
TA554
Malicious Powershell Targeting UK Bank Customers
- 2018-05-18 - SANS ISC -
Xavier Mertens
TA554
sLoad
Hello, internal name of this loader is sLoad. Appeared May 1st. Payload is the UK focused Ramnit ( fB1oN5frGqf )
- 2018-05-19 - Twitter -
Kafeine
sLoad
Ramnit
TA554
For the records, sLoad is still dropping Ramnit "fB1oN5frGqf" in Italy.
- 2019-11-07 - Twitter -
Kafeine
sLoad
Ramnit
TA554