“SIMBAR” in the user-agent field indicates that the same system was being used to attack, but adware is by it’s very nature pervasive, so is that really a good indicator? The assumption that the system was infected with adware was prominent in both reports. The “Simbar” computer was involved in the initial attack and uploaded some tools in both of the incidents. It is possible to think that if you see in two attacks on your machine from same hacking group, the same special user agent doing that same actions, that it might be the same attacker.”]
Source: https://taosecurity.blogspot.com/2006/11/five-blog-posts-you-should-read.html