ThreatLabz
ID: 1e0067b6-eb19-5d74-9be2-4d3f073baa6f
STIX ID: report--1e0067b6-eb19-5d74-9be2-4d3f073baa6f
Feed Name: Zscaler Security Research Blog
This report documents analysis of a Windows backdoor/infostealer that persists via the Startup folder and collects sensitive data through multiple modules: a clipboard clipper (clippa.dan), browser credential/cookie stealers (cdck.bin, bdck.bin targeting Chrome and Yandex), a keylogger (Kebba.dan), and a grabber that exfiltrates documents (grb.bin). The analysis lists artifacts, filesystem paths, a configuration file (Winkeyjet.ini) containing device and C2 information, and notes decoy dropped files used by the malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
