Tinba Banking Trojan Variant
ID: 12b51434-403f-5587-8a8a-9db2b4af311d
STIX ID: report--12b51434-403f-5587-8a8a-9db2b4af311d
Feed Name: Zscaler Security Research Blog
**Executive Summary:** Tinba is a small banking Trojan that injects into system and browser processes to harvest browsing data, login credentials and banking information; it persists by copying itself to a hidden folder under %APPDATA% and adding an autorun registry entry, uses a domain-generation algorithm (DGA) with fast-flux C2 infrastructure and simple XOR-based encryption for C2 communications, and is delivered via spam, drive-by downloads and exploit kits—this report provides behavioral analysis, unpacking details, TTPs and IOCs (domains and IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
