InnfiRAT is aiming for cryptocurrency
ID: 773452fd-4a80-5ad1-9d4c-099b7be14d78
STIX ID: report--773452fd-4a80-5ad1-9d4c-099b7be14d78
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ analyzed InnfiRAT, a .NET remote-access trojan that establishes a duplex WCF channel to a C2 (tcp://62.210.142.219:17231/IVictim), performs anti-VM checks, persists via scheduled tasks, exfiltrates browser cookies, cryptocurrency wallets and desktop text files, captures screenshots, kills browser/process monitoring tools, and can download and execute additional payloads; the report includes an MD5, a download URL, and the C2 address as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
