Malvertising Targeting European Transit Users
ID: f37e34ec-a35c-5f66-ab4d-2b79f07432ff
STIX ID: report--f37e34ec-a35c-5f66-ab4d-2b79f07432ff
Feed Name: Zscaler Security Research Blog
Threat Score
ThreatLabZ identified a malvertising campaign targeting European transit users that deploys the KINS (Zeus-based) banking trojan; the report details redirection chains, example malicious URLs and ports, payload persistence locations, extensive registry modifications to disable security controls, network IOCs including a hard-coded User-Agent and POST to /common/link.php, decrypted C2 locations, and a listening TCP port (36139).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
