PandaZeuS’s Christmas Gift: Change in the Encryption scheme
ID: e721f569-e892-5a60-9351-25bb775fa8e4
STIX ID: report--e721f569-e892-5a60-9351-25bb775fa8e4
Feed Name: The Spamhaus Project
Threat Score
Spamhaus Malware Labs observed a Christmas-season wave of PandaZeuS (Panda Banker) banking trojan samples updated to version 2.6.1 that introduce a modified RC4-based base-config encryption routine (additional state-array mixing) likely intended to break malware extractors; sinkhole data shows the botnet targets primarily English-speaking users and associated botnet domains are poorly detected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
