Chanitor Downloader Actively Installing Vawtrak
ID: 78af0ce5-9d7f-51d0-9c52-279a185d1836
STIX ID: report--78af0ce5-9d7f-51d0-9c52-279a185d1836
Feed Name: Zscaler Security Research Blog
ThreatLabZ analysis of the Chanitor downloader campaign: attackers distribute phishing emails with malicious .scr attachments that install Chanitor (copies to C:\Users\AppData\Roaming\Windows\winlogin.exe), which beacons to C2 servers via tor2web over SSL and downloads a stage-2 dropper that installs a Vawtrak (NeverQuest) infostealer DLL. The report includes persistence and execution details, registry and file locations, C2 domains (tor2web gates), and recommended mitigation (block tor2web), along with example IOCs and timestamps from October 2014.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
