logo

VB2015_Catching_the_silent_whisper

ID: 2ebe5942-6918-4ae2-a373-e4c40dbedc8c

STIX ID: report--2ebe5942-6918-4ae2-a373-e4c40dbedc8c

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2015-10-08

Last Modified Date: 2015-10-08

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Fortinet/Virus Bulletin presentation analyzes the Derusbi DLL-based remote-access trojan family (2008–2015), describing its variants, modular C++ classes, persistence via masqueraded service DLLs, optional embedded drivers, C2 behaviors and sample-specific IOCs; it ties Derusbi to high-profile intrusions (Mitsubishi, CareFirst, Anthem) and actor activity attributed to Deep Panda, and recommends detection points such as class/modular structure, IPS signatures and monitoring of registry/service paths.