Ongoing trojan campaign targeting .

If victim's IP is out of Chile, there is a 403. For Chileans IPs it drops a malicious MSI with a random filename.

Extracted payload ->
28728fc47ec7d920830d036c5a9221ab *Binary.nmpDbaW.dll_1

original MSI: 0bd958b0c88d3614f563ea50f97c2121 *FOSKP89XAE.msi

Tx for the headsup, Ewald!

#grandoreiro #banker #chile

Last updated 2 years ago

Si soy yo · @nuria_imeq
46 followers · 23 posts · Server fosstodon.org


IOC: hxxps://factura11.blob.core.windows.net/es1/factura.html?1486682127689
bazaar.abuse.ch/sample/8f7324a

#grandoreiro #malware

Last updated 2 years ago

Parliamo di news! · @parliamodinews
16 followers · 87685 posts · Server masthead.social
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Overlay Malware Leverages Chrome Browser, Targets Banks and Heads to Spain - The Grandoreiro banking malware uses remote overlay and a fake Chrome browser plugin to steal from... more: threatpost.com/overlay-malware

#url #payload #malspam #malware #grandoreiro #coronavirus #spainmalware #bankingmalware

Last updated 5 years ago