Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MALWARE
Malware family identifying win.poslurp. Origin and technical characteristics tracked via Malpedia.
Also known as: PUNCHTRACK
MALWARE
PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement.
PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework. Out-of-the-box PoshC2 comes PowerShell/C# and Python3 implants with payloads written in PowerShell v2 and v4, C++ and C# source code, a variety of executables, DLLs and raw shellcode in addition to a Python3 payload. These enable C2 functionality on a wide range of devices and operating systems, including Windows, *nix and OSX.
poscardstealer
Technical ID: win.poscardstealer
MALWARE
Malware family identifying win.poscardstealer. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.portstarter. Origin and technical characteristics tracked via Malpedia.
portless
Technical ID: win.portless
MALWARE
Malware family identifying win.portless. Origin and technical characteristics tracked via Malpedia.
PortDoor
Technical ID: win.portdoor
MALWARE
Malware family identifying win.portdoor. Origin and technical characteristics tracked via Malpedia.
Popcorn Time
Technical ID: win.popcorn_time
MALWARE
Malware family identifying win.popcorn_time. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →MALWARE
Malware family identifying win.poorweb. Origin and technical characteristics tracked via Malpedia.
POORTRY
Technical ID: win.poortry
MALWARE
According to Mandiant, POORTRY is a malware written as a driver, signed with a Microsoft Windows Hardware Compatibility Authenticode signature. This malware has been observed being used by UNC3944.
MALWARE
Malware family identifying win.poohmilk. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to KnowBe4, Pony Stealer is a password stealer that can decrypt or unlock passwords for over 110 different applications including VPN, FTP, email, instant messaging, web browsers and much more. Pony Stealer is very dangerous and once it infects a PC it will turn the device into a botnet, allowing it to use the PCs it infects to infect other PCs.
Also known as: Siplog • Fareit
PolyVice
Technical ID: win.polyvice
MALWARE
Malware family identifying win.polyvice. Origin and technical characteristics tracked via Malpedia.
Also known as: Chily
Polyglot
Technical ID: win.polyglot_ransom
MALWARE
Malware family identifying win.polyglot_ransom. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.polyglotduke. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.polpo. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.poldat. Origin and technical characteristics tracked via Malpedia.
Also known as: Zlib • KABOB
Poison RAT
Technical ID: win.poison_rat
MALWARE
Malware family identifying win.poison_rat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.poison_ivy. Origin and technical characteristics tracked via Malpedia.
Also known as: SPIVY • pivy • poisonivy
MALWARE
According to FireEye, POISONPLUG is a highly obfuscated modular backdoor with plug-in capabilities. The malware is capable of registry or service persistence, self-removal, plug-in execution, and network connection forwarding. POISONPLUG has been observed using social platforms to host encoded C&C commands.
Also known as: Barlaiy
Poco RAT
Technical ID: win.poco_rat
MALWARE
Malware family identifying win.poco_rat. Origin and technical characteristics tracked via Malpedia.
MALWARE
uses POCO C++ cross-platform library, Xor-based string obfuscation, SSL library code and string overlap with Xtunnel, infrastructure overlap with X-Agent, probably in use since mid-2018
Also known as: Blitz • PocoDownloader
PNGLoad
Technical ID: win.png_load
MALWARE
According to ESET Research, PNGLoad is a second-stage payload deployed by Worok on compromised systems and loaded either by CLRLoad or PowHeartBeat. PNGLoad has capabilities to download and execute additional payloads from a C&C server, which is likely how the attackers have deployed PNGLoad on systems compromised with PowHeartBeat. PNGLoad is a loader that uses bytes from PNG files to create a payload to execute. It is a 64-bit .NET executable - obfuscated with .NET Reactor - that masquerades as legitimate software.
MALWARE
Malware family identifying win.pngdowner. Origin and technical characteristics tracked via Malpedia.
Plurox
Technical ID: win.plurox
MALWARE
Malware family identifying win.plurox. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
RSA describes PlugX as a RAT (Remote Access Trojan) malware family that is around since 2008 and is used as a backdoor to control the victim's machine fully. Once the device is infected, an attacker can remotely execute several kinds of commands on the affected system.
Notable features of this malware family are the ability to execute commands on the affected machine to retrieve:
machine information
capture the screen
send keyboard and mouse events
keylogging
reboot the system
manage processes (create, kill and enumerate)
manage services (create, start, stop, etc.); and
manage Windows registry entries, open a shell, etc.
The malware also logs its events in a text log file.
Also known as: Destroy RAT • Kaba • Korplug • Sogu • TIGERPLUG
ployx
Technical ID: win.ployx
MALWARE
Malware family identifying win.ployx. Origin and technical characteristics tracked via Malpedia.
Ploutus ATM
Technical ID: win.ploutus_atm
MALWARE
Malware family identifying win.ploutus_atm. Origin and technical characteristics tracked via Malpedia.
MALWARE
PLEAD is a RAT used by the actor BlackTech. FireEye uses the synonyms GOODTIMES for the RAT module and DRAWDOWN for the respective downloader.
Also known as: DRAWDOWN • GOODTIMES • Linopid
playwork
Technical ID: win.playwork
MALWARE
Malware family identifying win.playwork. Origin and technical characteristics tracked via Malpedia.
PLAY
Technical ID: win.play
MALWAREfinancialhigh
According to PCrisk, PLAY is the name of a ransomware-type program. Malware categorized as such operates by encrypting data and demanding ransoms for the decryption.
After we executed a sample of this ransomware on our test machine, it encrypted files and appended their filenames with a ".PLAY" extension. For example, a file titled "1.jpg" appeared as "1.jpg.PLAY", "2.png" as "2.png.PLAY", etc. Once the encryption process was completed, PLAY created a text file named "ReadMe.txt" on the desktop.
Also known as: PlayCrypt
MALWARE
Malware family identifying win.plaintee. Origin and technical characteristics tracked via Malpedia.
Pkybot
Technical ID: win.pkybot
MALWARE
Pkybot is a trojan, which has its roots as a downloader dubbed Bublik in 2013 and was seen distributing GameoverZeus in 2014 (ref: fortinet). In the beginning of 2015, webinject capability was added according to /Kleissner/Kafeine/iSight using the infamous ATS.
Also known as: Pykbot • TBag • Bublik
PittyTiger RAT
Technical ID: win.pittytiger_rat
MALWARE
Malware family identifying win.pittytiger_rat. Origin and technical characteristics tracked via Malpedia.
Pitou
Technical ID: win.pitou
MALWARE
According to TG Soft, Pitou has beeen released on April 2014. It maybe an evolution of the rootkit "Srzizbi" developed on 2008. Pitou is a spambot, the main goal is send spam form the computer of victim.
MALWARE
Malware family identifying win.pirpi. Origin and technical characteristics tracked via Malpedia.
Also known as: SHOTPUT • CookieCutter
PirateStealer
Technical ID: win.pirate_stealer
MALWARE
Infostealer
PipeSnoop
Technical ID: win.pipesnoop
MALWARE
Cisco Talos states that PipeSnoop can accept arbitrary shellcode from a named pipe and execute it on the infected endpoint.
Also known as: TOFUPIPE
MALWARE
Malware family identifying win.pipemon. Origin and technical characteristics tracked via Malpedia.
PipeMagic
Technical ID: win.pipemagic
MALWARE
Malware family identifying win.pipemagic. Origin and technical characteristics tracked via Malpedia.
pipcreat
Technical ID: win.pipcreat
MALWARE
Malware family identifying win.pipcreat. Origin and technical characteristics tracked via Malpedia.