Evolution Of Upatre Trojan Downloader
ID: d0b88d51-c8ab-56d8-9c15-90e91c1ff542
STIX ID: report--d0b88d51-c8ab-56d8-9c15-90e91c1ff542
Feed Name: Zscaler Security Research Blog
**Executive Summary:** The report details the Upatre Trojan downloader campaign used to deliver banking malware (Dyreza, Zeus, Rovnix) via Cutwail spam and exploit kits, describing infection chains, evasion techniques (password-protected and nested attachments, randomized headers, encrypted downloads, SSL C2), C2 behavior (TCP port 40007), decryption routines, and network indicators including sample HTTP requests and hardcoded User-Agent strings (ENUPDATE, ONLYUPDATE, UPDATE).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
