TARSIP-ECLIPSE

TARSIP-ECLIPSETARSIP-ECLIPSE

Description

The TARSIP malware family is a backdoor which communicates over encoded information in HTTPS headers. Typical TARSIP malware samples will only beacon out to their C2 servers if the C2 DNS address resolves to a specific address. The capability of TARSIP backdoors includes file uploading, file downloading, interactive command shells, process enumeration, process creation, process termination. The TARSIP-ECLIPSE family is distinguished by the presence of 'eclipse' in .pdb debug strings present in the malware samples. It does not provide a built in mechanism to maintain persistence.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
TARSIP-MOON
Software
TABMSGSQL
Software
Elise Backdoor
Software
ECLIPSEDWING
Software
Epsilon
Software
Elise
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.