Brad · @malware_traffic
2051 followers · 79 posts · Server infosec.exchange

2023-01-03 (Tuesday) and 01-04 (Wednesday): Doing this as a separate post as well...

Follow-up on activity reported in today's (2023-01-05) ISC diary at: isc.sans.edu/diary/More%20Braz

A more complete list of indicators, files, and () malware samples now available at: malware-traffic-analysis.net/2

On the first pcap, I opened the banco.bradesco site in a web browser after letting the infection run overnight. So that particular traffic was -not- caused by the malware.

After opening that banking website, the infected host immediately generated more HTTP POST requests, sending encoded data to the C2 server.

#pcap #astaroth #guildma

Last updated 2 years ago

Brad · @malware_traffic
2054 followers · 79 posts · Server infosec.exchange

@sans_isc A more complete list of indicators, files, and () malware samples from this diary are now available at: malware-traffic-analysis.net/2

#pcap #astaroth #guildma

Last updated 2 years ago

Brad · @malware_traffic
2054 followers · 79 posts · Server infosec.exchange

@SebastianWalla @sans_isc This /#Guildma malware has consistently used AutoIt for the past year or two, every time I've seen it.

I've generated 10 infections in my lab environment since July 2022 (including one in November and one in December). They all look similar, and they all use AutoIt, which is one of the ways I identitfy this as Astaroth/Guildma.

You might be right about other malware families, though. And AutoIt isn't the only method I've seen for other campaigns targeting Brazil.

Unfortunately for me, this Brazil-targeted Astaroth malware is the only one I personally see using AutoIt.

#astaroth

Last updated 2 years ago

ISC diary: @malware_traffic finds more pushing () in January 2023 i5c.us/d29404

#malspam #astaroth #guildma

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Astaroth’s New Evasion Tactics Make It ‘Painful to Analyze’ - The infostealer has gone above and beyond in its new anti-analysis and obfuscation tactics. more: threatpost.com/astaroths-evasi

#youtube #malware #astaroth #obfuscation #infostealer #evasiontactics #malwaredetection

Last updated 4 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Threat Spotlight: Astaroth — Maze of obfuscation and evasion reveals dark stealer - By Nick Biasini, Edmund Brumaghin and Nick Lister.

Cisco Talos is detailing an information stealer... more: feedproxy.google.com/~r/feedbu -analysis -sandbox

#brazil #astaroth #anti #malwareanalysis #informationstealers

Last updated 4 years ago

SollyzSundyz · @SollyzSundyz
979 followers · 1196 posts · Server pawoo.net

Astaroth (Shinrabansho) nsfw nudist April 2017 Reward
patreon.com/sollyz_haruz
support get reward

-SFW and NSFW (Nudist)____5$
-all SFW ,NSFW and SFW animated version____10$
-all work & .psd file____20$

**only this month , have nsfw(Nudist) animated!**
**will be sent after the payment has been processed.**
**around 1th-5th May 2017 **

pawoo.net/media/D74wjMCNBkCONo

#astaroth #shinrabansho #神羅万象 #アスタロット #animated #gif #nudist #r18 #nsfw

Last updated 8 years ago

SollyzSundyz · @SollyzSundyz
1058 followers · 1295 posts · Server pawoo.net

Astaroth (Shinrabansho) nsfw nudist April 2017 Reward
patreon.com/sollyz_haruz
support get reward

-SFW and NSFW (Nudist)____5$
-all SFW ,NSFW and SFW animated version____10$
-all work & .psd file____20$

**only this month , have nsfw(Nudist) animated!**
**will be sent after the payment has been processed.**
**around 1th-5th May 2017 **

pawoo.net/media/D74wjMCNBkCONo

#astaroth #shinrabansho #神羅万象 #アスタロット #animated #gif #nudist #r18 #nsfw

Last updated 8 years ago

SollyzSundyz · @SollyzSundyz
979 followers · 1196 posts · Server pawoo.net
SollyzSundyz · @SollyzSundyz
1058 followers · 1295 posts · Server pawoo.net