live casino online

http://{BLOCKED}mmj.com/cfg.bin

September 10, 2013
 Analysis by: Jerowin Santillan

 URL BLOCKING DATE/TIME: 04 Sep 2013 11:01:00 AM GMT-8
 RATING: HIGH
 DOMAIN: ocsxxxmmj.com
 CATEGORY: Disease Vector
 DESCRIPTION:

TSPY_ZBOT.THX connects to this URL to download its configuration file. This is the live casino online detection for KINS Trojan, dubbed as the next ZeuS by media reports. Similar to ZeuS/ZBOT, it downloads configuration file and steals online banking credentials. However, it uses a different packer and has anti-debugging and anti-analysis routines.

Related Malware