Analisado por: Jerowin Santillan

 Data/Hora do bloqueio de URL: quarta-feira, 4 de setembro de 2013 11:01:00 GMT-8
 Classifica??o: : Alto
 Dom¨ªnio: : ocsxxxmmj.com
 Categoria : Disease Vector
 Descri??o:

TSPY_ZBOT.THX connects to this URL to download its configuration file. This is the live casino online detection for KINS Trojan, dubbed as the next ZeuS by media reports. Similar to ZeuS/ZBOT, it downloads configuration file and steals online banking credentials. However, it uses a different packer and has anti-debugging and anti-analysis routines.

Arquivo correspondente