Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰
📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download
Final payload is hosted on MediaFire 🔥 free file hosting
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️
User-Agent: Embarcadero URI Client/1.0
🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀
📡 Grandoreiro botnet C2s hosted at AWS:
54.80.154.193
54.91.129.132
54.91.223.28
🌐 Payloads URLs:
https://urlhaus.abuse.ch/browse/tag/Grandoreiro/
📄 Malware samples:
https://bazaar.abuse.ch/browse/signature/Grandoreiro/
🦊 Relevant IOCs are available on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.grandoreiro/
You've seen all posts