TARSIP-MOON

TARSIP-MOONTARSIP-MOON

Description

The TARSIP malware family is a backdoor which communicates over encoded information in HTTPS headers. Typical TARSIP malware samples will only beacon out to their C2 servers if the C2 DNS address resolves to a specific address. The capability of TARSIP backdoors includes file uploading, file downloading, interactive command shells, process enumeration, process creation, process termination. The TARSIP-MOON family is distinguished by the presence of 'moon' in .pdb debug strings present in the malware samples. It does not provide a built in mechanism to maintain persistence.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
TARSIP-ECLIPSE
Software
BlackMoon
Software
Darkmoon
Software
TABMSGSQL
Software
MoonCryptor
Software
MoonWind
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.