Top Tweets for #Retefe
@tosscoinwitcher @James_inthe_box @pr0xylife @0xToxin @0n315 ... it has been dropping other bankers like: #Kronos, #Chthonic #Retefe #TrickBot and others, beside known #Stealer campaigns. This lead me to assess this is just another Setup of some TA.
I could be wrong of course which is why you could do a code comparison using e.g. #Intezer
The oldest, active malware distribution site is hosted at Affinity Internet Inc located in Chicago (USA 🇺🇸), spreading #Retefe for 2 1/2 years! 👎 Incredible... how ignorant can an internet service provider be?😕
👉 https://t.co/nhBxs5YQHI

Detect, prevent, and analyze ransomware #Retefe in seconds using OPSWAT #MetaDefender Cloud: https://t.co/GC9zNfN5m7
Before you open any suspicious files, scan it first through our #MetaDefender cloud: https://t.co/EIYJY98R6a
OPSWAT vs. #Retefe
Although Retefe only appeared infrequently in 2018, the banker returned to more regular attacks on Swiss and German victims in April of 2019 with both a Windows and macOS version.
See how OPSWAT helps to prevent Retefe ↓
OPSWAT vs. #Retefe
Although Retefe only appeared infrequently in 2018, the banker returned to more regular attacks on Swiss and German victims in April of 2019 with both a Windows and macOS version.
See how OPSWAT helps to prevent Retefe ↓
Recent #RETEFE samples we analyzed contain embedded, obfuscated JavaScript code, which uses tricks like utilizing "https://t.co/olknLz3Lgx" to generate attacks. RETEFE obtains a list of running processes to simulate a user clicking “Yes” on a certificate warning dialog box.

2019: The Return of #Retefe. https://t.co/kS098U72Zh via the Proofpoint @threatinsight research team.

2019: The Return of #Retefe. https://t.co/kS098U72Zh via the Proofpoint @threatinsight research team.

Seit April gibt es einen massiven Anstieg der Angriffe mit dem Online-Banking-Trojaner #Retefe. Im Fokus stehen vor allem deutsche und Schweizer Nutzer. https://t.co/glFfWvgsaS
@MalwarePatrol @Malwageddon @proofpoint @_odisseus @zlab_team @Marco_Ramilli @yoroisecurity #Retefe #Banking #Trojan resurfaces in the threat landscape with innovations
https://t.co/aW1OxVCot8
#securityaffairs #malware #hacking
@James_inthe_box @malwrhunterteam Confirmed #Retefe dropper.
The javascript payload extracted: https://t.co/1jHpcwGnSw
C&Cs:
hxxp://3bbbccvomp5uhznz.onion
hxxp://auybplpgam3c62tc.onion
hxxp://hiv3dylycjbvgrxr.onion
hxxp://m2pgzofn4w6ttgbb.onion
hxxp://n6g66hecwbnf7bg4.onion
A possible #retefe signed sample (via TTP's) found by @malwrhunterteam; drops socat, tor, 7zip, sadly fizzles out on execution.
hash a33080f16c9386a4fbe9e678cca13907d6ab141e698d05728681e6d7e94e213b just about everywhere by now.


#Retefe
> Low detected payload (8/70):
https://t.co/K8uAmab91L
> Number of C&C: ~5
> Conf:
/3bbbccvomp5uhznz.onion
/auybplpgam3c62tc.onion
/hiv3dylycjbvgrxr.onion
/m2pgzofn4w6ttgbb.onion
/n6g66hecwbnf7bg4.onion
@malwrhunterteam
Trends for you
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
108.9M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
86.8M followers

Taylor Swift 
@taylorswift13
80.6M followers

Lady Gaga 
@ladygaga
72.2M followers

Kim Kardashian 
@kimkardashian
69.4M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.6M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.1M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
59.9M followers







![F5Labs's tweet photo. [IN REVIEW] #Retefe uses special sandbox evasion techniques to avoid detection & prevent code from correctly executing when launched from somewhere other than the intended target. #Malware authors check if installed language is only en-US, Retefe exits without proper execution. https://t.co/L8te9eVl2o](https://pbs.twimg.com/media/ECgI09WXUAAN4sI.jpg)
![F5Labs's tweet photo. [IN REVIEW] Recent #Retefe samples contain embedded, obfuscated JavaScript code, which tries to retrieve confidential information from the infected computers. It then writes the log and uploads it to the suspicious server. #malware https://t.co/ZIRPwq9kPU](https://pbs.twimg.com/media/EB8RO6jWsAEjRXy.jpg)
![F5Labs's tweet photo. [IN REVIEW] Recent #Retefe samples contain embedded, obfuscated JavaScript code, which tries to retrieve confidential information from the infected computers. It then writes the log and uploads it to the suspicious server. #malware https://t.co/ZIRPwq9kPU](https://pbs.twimg.com/media/EB8ROx3XYAA61Rc.jpg)
![F5Labs's tweet photo. [IN REVIEW] Recent #Retefe samples contain embedded, obfuscated JavaScript code, which tries to retrieve confidential information from the infected computers. It then writes the log and uploads it to the suspicious server. #malware https://t.co/ZIRPwq9kPU](https://pbs.twimg.com/media/EB8ROq_XoAApFXR.jpg)
![F5Labs's tweet photo. [IN REVIEW] #Retefe sample contains an interesting author’s monologue inside the obfuscated and encoded function, which adds the fake certificate to the #Firefox browser. https://t.co/H7G5BSWKTj](https://pbs.twimg.com/media/EA6HQraX4AElGxp.jpg)









