#malspam

2 posts · Last used 3d

Back to Timeline
abuse.ch :verified: @abuse_ch@ioc.exchange · 3d ago
Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰 📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download Final payload is hosted on MediaFire 🔥 free file hosting C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️ User-Agent: Embarcadero URI Client/1.0 🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀 📡 Grandoreiro botnet C2s hosted at AWS: 54.80.154.193 54.91.129.132 54.91.223.28 🌐 Payloads URLs: https://urlhaus.abuse.ch/browse/tag/Grandoreiro/ 📄 Malware samples: https://bazaar.abuse.ch/browse/signature/Grandoreiro/ 🦊 Relevant IOCs are available on ThreatFox: https://threatfox.abuse.ch/browse/malware/win.grandoreiro/
0
0
0

You've seen all posts