Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰
📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download
Final payload is hosted on MediaFire 🔥 free file hosting
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️
User-Agent: Embarcadero URI Client/1.0
🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀
📡 Grandoreiro botnet C2s hosted at AWS:
54.80.154.193
54.91.129.132
54.91.223.28
🌐 Payloads URLs:
https://urlhaus.abuse.ch/browse/tag/Grandoreiro/
📄 Malware samples:
https://bazaar.abuse.ch/browse/signature/Grandoreiro/
🦊 Relevant IOCs are available on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.grandoreiro/
A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses:
https://gist.github.com/silence-is-best/48b613e82bf64f1fd8b9a231ccdd590b
#retrohunt
You've seen all posts