Class: Trojan-Spy
Trojan-Spy programs are used to spy on a user’s actions (to track data entered by keyboard, make screen shots, retrieve a list of running applications, etc.) The harvested information is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request) and other methods can be used to transmit the data.Read more
Platform: Win32
Win32 is an API on Windows NT-based operating systems (Windows XP, Windows 7, etc.) that supports execution of 32-bit applications. One of the most widespread programming platforms in the world.Family: Bobik
No family descriptionExamples
A3637C7C8ABAB5B6352E92B66F942FB0871B78B2BE19E9CFCCF10B327BF52B66
97156EB1F04309A82E806FC8E8C4FD00
A660686DC5A11866DD6EB9DEB709630D
B1D8C946F314AA2885F801DC9229054A
Tactics and Techniques: Mitre*
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port and/or vulnerability scans using tools that are brought onto a system.
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port and/or vulnerability scans using tools that are brought onto a system.
* © 2025 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.