Banatrix – an indepth look
ID: 54fd87ba-6fa6-5a1e-a341-1c3a449057a7
STIX ID: report--54fd87ba-6fa6-5a1e-a341-1c3a449057a7
Feed Name: CERT Polska
Banatrix is a technologically advanced Polish banking malware that persists via dropped DLL/EXE pairs, communicates with C2 through a TOR-based proxy and a custom DGA, and downloads xor-encrypted libraries that allow arbitrary code execution. Its payloads include browser-memory manipulation to replace bank account numbers and modules to exfiltrate saved Firefox passwords; sinkhole telemetry shows roughly 5,000 unique IPs contacting the C2 daily. The report includes technical details on unpacking, network behavior, DGA logic, and a sample SHA256 for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
