GLOOXMAIL

GLOOXMAILGLOOXMAIL

Description

GLOOXMAIL communicates with Google's Jabber/XMPP servers and authenticates with a hard-coded username and password. The malware can accept commands over XMPP that includes file upload and download, provide a remote shell, sending process listings, and terminating specified processes. The malware makes extensive use of the open source gloox library (http://camaya.net/gloox/, version 0.9.9.12) to communicate using the Jabber/XMPP protocol. All communications with the Google XMPP server are encrypted.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
GDOCUPLOAD
Software
Gomme
Software
gh0st
Software
GrodexCrypt
Software
Gootkit
Software
GhosTEncryptor
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.