Newest addition to a happy family: KBOT
ID: 5be8a9c2-222e-50b4-9c73-30fd945d8426
STIX ID: report--5be8a9c2-222e-50b4-9c73-30fd945d8426
Feed Name: CERT Polska
Threat Score
This report analyzes a spam campaign that delivers a JavaScript dropper which downloads a modified KBOT/Carberp-derived banking trojan. The malware exhibits Tor support, HMAC-protected messaging, a more complex encryption scheme, and an embedded mongoose HTTP server; the author extracts configuration structure and provides domains, file hashes, and a YARA rule for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
