Elektrine lite

โ† Feed

@abuse_ch@ioc.exchange

Post #4501348

2026-08-11 14:07 UTC

Over the past days, active #malspam campaigns targeting LatAm users ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡ฒ๐Ÿ‡ฝ have been delivering the Grandoreiro banking trojan ๐Ÿฆ๐Ÿ’ฐ ๐Ÿ“ง Email โž” ๐Ÿ“œ JS file โž” ๐Ÿ“‘ Fake PDF download Final payload is hosted on MediaFire ๐Ÿ”ฅ free file hosting C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent ๐Ÿ–ฅ๏ธโคต๏ธ User-Agent: Embarcadero URI Client/1.0 ๐Ÿ”Ž Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com ๐Ÿ‘€ ๐Ÿ“ก Grandoreiro botnet C2s hosted at AWS: 54.80.154.193 54.91.129.132 54.91.223.28 ๐ŸŒ Payloads URLs: https://urlhaus.abuse.ch/browse/tag/Grandoreiro/ ๐Ÿ“„ Malware samples: https://bazaar.abuse.ch/browse/signature/Grandoreiro/ ๐ŸฆŠ Relevant IOCs are available on ThreatFox: https://threatfox.abuse.ch/browse/malware/win.grandoreiro/

Replies (0)

No replies.