#Banking#Brazilian#malware maybe related with #Lampion.
By pdb: #KLBanker
Loader for W7 & W10
Antidebug
Banks: Santander, BBVA, BancoEstado
2 more samples related:
EncryptAndDecrypt: Used to enc/dec strings 3DES+CBC.
Clientes: Login for "Keylogger Banker"
#opendir IP contain 2 differnet malware C2
191.232.233.]32
/man/ is C2 of #MetaMorfo/#MeKotio
https://t.co/dz87YVmRkD
/Android/ folder is C2 of #BasBanke/#CoyBot Android malware(as the folder name suggests..)
https://t.co/im50gz8a3I
Both targeting Brazilian banks.π§π·
@JasonMilletary@koodous_project Thx! ye i've got that in mind also but the fact that its mamba in the domain and my emotions played a role lead me to the kobe directions.
I found a bunch of APKs uploaded yesterday to VT and @koodous_project which are #Anubis/#BankBot Android malware with C2 named mambanumber5.]top and also the key "mamb".
At first, I thought its tribute to Kobe Brayent and his 5 championship rings... 1/2