ThreatLabz
ID: f7bb68be-fab4-5dbc-91ef-21b273f02c9d
STIX ID: report--f7bb68be-fab4-5dbc-91ef-21b273f02c9d
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes DanaBot, a malware-as-a-service info-stealer first seen in 2018 that steals credentials, session cookies, and account information for banking fraud, cryptocurrency theft, and espionage. It documents numerous obfuscation techniques (junk byte jumps, dynamic returns, stack strings, junk loops/strings) and presents a suite of IDA Python scripts to deobfuscate binaries, with a provided SHA256 IOC for a DanaBot sample.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
