A new configuration of #Raccoon#Stealer is being distributed with instructions to also steal data from the @signalapp Desktop clients.
The C&C server: 83.217.11[.]6
In the last two days (1-2 Feb) we noticed that #Ursnif is spreading the #IcedID#banker using its downloader function.
Decrypted samples (SHA256): 769ea924e2a1414ae02b466b3b2f6c52025bab40803ee011f3573efd25283077
b456dde5b0f8bad6686bec6bca49dd5f8de40058f655b1407492c261e16e9ddd
We discovered a new #RaccoonStealer V2 build, timestamp Aug 9, 2022. The authors finally started to encrypt their strings, but the C&C encryption is now weaker.
Sample hash: f126e199fc9f86af136520b60e27c62d2d00609210c02fec625073cae3d25abe
We published Q2 threat report where I wrote about Raccoon and Zloader. And today I found a new #RaccoonStealer build with crap instead of C&C encryption ;-)