Banking Malware Uses PAC File
ID: 72ac7691-cc54-5832-a301-d02d9df29412
STIX ID: report--72ac7691-cc54-5832-a301-d02d9df29412
Feed Name: Zscaler Security Research Blog
Threat Score
This report documents a malware sample that modifies the Windows registry Internet Settings AutoConfigURL to point to an attacker-controlled PAC file (http://dns.configdeskwork.com:8099/workwindows.pac). The PAC causes targeted banking and other traffic (including Brazilian sites and American Express) to be proxied to 208.64.66.170, enabling credential theft; the report includes the PAC content, registry key used, FQDN and resolved IP as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
