ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
MDB Signatures For JSSLoader RAT Malware

Joined: 09 Jul 2006
Posts: 4935
Location: USA
Reply with quote
Below are MDB signatures for some new versions of the JSSLoader remote access trojan from the Russian criminal hacking group FIN7. It infects via Excel .XLL add-in files to exfiltrate data , maintain persistence, and download more malware, so its targets are pretty broad. Since they are Russian, targets may include governments and military. If you have a custom list of extensions to scan, be sure it includes the extension *.xll.

Copy the signature(s) to a new Notepad or similar text writer file, and save it in the ClamWin database folder as a file named Sigfile.mdb with a file type of “All Files”. Do not save it as text file. The file name should be Sigfile.mdb and nothing else. The date and time are the last two items in the signature.

For multiple signatures, put each signature on a separate line in ta Notepad file. You can add multiple signatures to the top of an existing MDB signature file (just add one blank line and paste there—any additional lines needed will be added). Adding signatures to the bottom of an existing signature file always gives me a scanning error. Delete any blank lines between signatures in the signature file after pasting and before saving.

After you save the signature file in the ClamWin database folder, scan something with ClamWin to make sure it works. If you get a scan error, delete the signature file from the database folder or delete only the signatures that you just added to an existing MDB file and resave it. Leave no blank lines in the signature file.

Delete signatures after they are 6 weeks old, as the viruses will be updated by then.


View user's profileSend private message
MDB Signatures For JSSLoader RAT Malware
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

 Reply to topic