#PoorWeb
Malware/Tool
2020-03-25 • APT37 复盘分析报告(part2):木马与工具
PoorWeb is a multifunction C++ remote-access Trojan widely used by APT37. It is commonly delivered through malicious HWP documents and gives operators remote file-manipulation capabilities. A variant used in Operation Imitation Game tested a decoy address before resolving its real command-and-control server, which could help probe the execution environment and conceal infrastructure.
-
2
Tagged Reports
-
2
Unique Authors
-
237
Active Days