WARP

WARPWARP

Description

The WARP malware family is an HTTP based backdoor written in C++, and the majority of its code base is borrowed from source code available in the public domain. Network communications are implemented using the same WWW client library (w3c.cpp) available from www.dankrusi.com/file_69653F3336383837.html. The malware has system survey functionality (collects hostname, current user, system uptime, CPU speed, etc.) taken directly from the BO2K backdoor available from www.bo2k.com. It also contains the hard disk identification code found at www.winsim.com/diskid32/diskid32.cpp. When the WARP executing remote commands, the malware creates a copy of the ?%SYSTEMROOT%\system32\cmd.exe? file as '%USERPROFILE%\Temp\~ISUN32.EXE'. The version signature information of the duplicate executable is zeroed out. Some WARP variants maintain persistence through the use of DLL search order hijacking.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Wiarp
Software
WEBC2-RAVE
Software
WEBC2-Y21K
Software
WEBC2-ADSPACE
Software
WEBC2-CLOVER
Software
WEBC2-HEAD
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.