Banking Trojan Attempts To Steal Brazillion$ http://dlvr.it/Pr3jMc pic.twitter.com/NubIPgaeDg
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
We weren’t entirely sure. The final payload is packed with Themida so we couldn’t confirm everything we wanted.
Hoping to take a look at some point, adding to my ever-growing to-check list :D
Hi guys, this is not the first case. Here another example using an old version of a banking plugin https://researchcenter.paloaltonetworks.com/2017/07/unit42-malspam-targeting-brazil-continues-evolve/ …
Yeah @r00tbsd and I looked at this also :) we thought maybe same family but then we think it’s not related.
Only by fact of attacking Brazil. We had no Powershell in ours. Java and Delphi *shudder* packed with Themida :(
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.