Signed Dridex Campaign
ID: f500eba5-919c-58b6-8ac4-1002e2b88d83
STIX ID: report--f500eba5-919c-58b6-8ac4-1002e2b88d83
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ analyzed a Dridex banking Trojan campaign in which malicious Office attachments download Dridex samples that are signed with COMODO-issued code-signing certificates (including a certificate issued to "Private Person Parobii Yuri Romanovich") and packed with a custom .NET packer. The report documents download URLs, numerous sample hashes, C2 IP addresses and embedded configuration details, describes the packer behavior and Delphi dropper, and notes that the malware collects system information (computer name, user name, Windows version, botnet ID) and attempts to connect to a list of command-and-control servers; Zscaler is monitoring the campaign and ensuring detection coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
