VB2015_Catching_the_silent_whisper
ID: 2ebe5942-6918-4ae2-a373-e4c40dbedc8c
STIX ID: report--2ebe5942-6918-4ae2-a373-e4c40dbedc8c
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2015-10-08
Last Modified Date: 2015-10-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Fortinet/Virus Bulletin presentation analyzes the Derusbi DLL-based remote-access trojan family (2008–2015), describing its variants, modular C++ classes, persistence via masqueraded service DLLs, optional embedded drivers, C2 behaviors and sample-specific IOCs; it ties Derusbi to high-profile intrusions (Mitsubishi, CareFirst, Anthem) and actor activity attributed to Deep Panda, and recommends detection points such as class/modular structure, IPS signatures and monitoring of registry/service paths.
