Slave, Banatrix and ransomware
ID: 015771ed-30be-52c0-95e5-c5b447259c5b
STIX ID: report--015771ed-30be-52c0-95e5-c5b447259c5b
Feed Name: CERT Polska
Threat Score
This report analyzes the 'Slave' Polish e-banking trojan (dropped by Andromeda), describing its email-based delivery, webinject-driven credential theft across Internet Explorer, Firefox and Chrome, stripping of CSP headers to evade bank reporting, Bitcoin-address clipboard hijacking, configuration retrieval behavior, provided sample hashes/VT scores, and likely ties to authors of earlier Polish malware such as Banatrix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
