ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
MDB Signature For Snip3 RAT Loader
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Below is an MDB signature for Snip3, which is a remote access trojan loader that has been rather busy lately. Primary activity has been infecting businesses worldwide, particularly aerospace and travel companies, but it can be quite useful in downloading any malware, so you might see it on your PC sometime.

Copy the MDB signature(s) to a Notepad file and save it in the ClamWin db program data folder, or add the signature to an existing MDB file if you already have one there. Do not save the file with a .txt or .text extension on the end of the name. Save the file as Sigfile.mdb. Select file type All Files to prevent the .txt or .text from being used at the end of the filename. ClamWin is unable to recognize a text file as a signature and will give a corrupt database warning. After saving the file to the ClamWin db program folder, scan something with ClamWin to make sure the signature works--delete the signature file if it does not, or remove the signature from an existing MDB file if you put it there.

Signatures may last up to a week or longer, depending upon how lazy the malware authors are about changing their version(s). MDB signatures are signatures for a section of a malware file, and they can sometimes last up to a month, especially if the section is re-used in another malware. You can delete signatures after about a month--the last section of each signature tells the month/date/time the signature was prepared (such as May 12 2021 at 12:37 pm). I think this signature might last longer. The malware changes, but they have kept this section in the new malware for a couple of months now.

Regards,

148992:5e14e4ede2e2215bc7d72837b9871f8f:Win.Trojan.Snip3-051221.1237
View user's profileSend private message
MDB Signature For Snip3 RAT Loader
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic