Turla__2018__Uroburos_EN.pdf
ID: dfa2f2ac-7434-4b7b-bbb3-1b05fa336b5a
STIX ID: report--dfa2f2ac-7434-4b7b-bbb3-1b05fa336b5a
Threat Score
70/100
Uploaded: 2026-08-19
Published Date: 2018-02-09
Last Modified Date: 2018-02-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes the Uroburos (Turla) kernel-mode rootkit, detailing its 64-bit driver, memory hiding techniques, Windows callback abuse, NetIO callouts, encrypted strings, and covert HTTP communications, along with a PoC for remotely detecting a compromised server and a comparison between the 2014 and 2017 variants.
