Analysé par: Jerowin Santillan

 Date/heure du blocage de l'URL: mercredi 4 septembre 2013 11:01:00 GMT-8
 Évaluation: : Élevé
 Domaine: : ocsxxxmmj.com
 Catégorie: Disease Vector
 Description:

TSPY_ZBOT.THX connects to this URL to download its configuration file. This is the Trend Micro detection for KINS Trojan, dubbed as the next ZeuS by media reports. Similar to ZeuS/ZBOT, it downloads configuration file and steals online banking credentials. However, it uses a different packer and has anti-debugging and anti-analysis routines.

Fichier associé