"value":"During a security conference held on 4 April 2017, Kaspersky Lab revealed details of an attack in which attackers took control of dozens of domains owned by a Brazilian bank and leveraged this access to deliver malware and phishing pages to users. Our identification and analysis of the malware used in this campaign determined that it is a Java-based downloader that acquires and extracts a zip file from an IP address under the control of the attackers.\r\n\r\nThis zip contains several additional files, including a legitimate rootkit removal executable, a malicious DLL file, a text file used by the rootkit removal tool to delete antivirus programs, and a batch file used to leverage these files to install the malicious payload. Through further research, Cyber4Sight determined that this infection method dates back to at least 2009, but shared tools, techniques, and procedures (TTP) identified in other public sandbox reports suggest that the actor responsible for this attack likely continued their operations through April of this year.",
"comment":"Atualizar.jar\tFirst submitted to VirusTotal 22 October 2016.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1491665928",
"to_ids":true,
"type":"md5",
"uuid":"58e903ac-8d0c-47a8-8958-4e7b02de0b81",
"value":"95980f46ce76d862029b45908476532d"
},
{
"category":"Payload delivery",
"comment":"fatura11.vbs\t191.101.230.149 162.222.177.155 191.101.230.149\tFirst submitted to VirusTotal 22 December 2016. Second and third IP address comment out as a backup. Delivered via Dropbox links and from 181.215.114.231.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1491665928",
"to_ids":true,
"type":"md5",
"uuid":"58e903ad-a7c0-4abe-8bd8-453b02de0b81",
"value":"cdd5f47935a2a45afff20b222124177d"
},
{
"category":"Payload delivery",
"comment":"191.101.237.196\tDelivered via Dropbox links and from 181.215.114.231.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1491665928",
"to_ids":true,
"type":"md5",
"uuid":"58e903af-6394-4f04-9733-404302de0b81",
"value":"722050c1b3f110c0ac9f80bc80723407"
},
{
"category":"Payload delivery",
"comment":"f893nuf9sdyfewnI98SDAJN787DHH.zip\t181.215.97.223 162.222.177.155191.101.159.215208.113.128.118\tFirst submitted to VirusTotal 12 January 2017. Delivered via Bit.ly link. Additional IP addresses are commented out backups.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1491665928",
"to_ids":true,
"type":"md5",
"uuid":"58e903b0-c870-43b3-ac58-482902de0b81",
"value":"907466374f7ef3787e4b8f8232a9c52e"
},
{
"category":"Payload delivery",
"comment":"Planilha SAQUE FGTS INATIVO5.zip\t107.178.111.39\tFirst submitted 4 April 2017.Delivered via Bit.ly link.",
"comment":"f893nuf9sdyfewnI98SDAJN787DHH.zip\t181.215.97.223 162.222.177.155191.101.159.215208.113.128.118\tFirst submitted to VirusTotal 12 January 2017. Delivered via Bit.ly link. Additional IP addresses are commented out backups. - Xchecked via VT: 907466374f7ef3787e4b8f8232a9c52e",
"comment":"f893nuf9sdyfewnI98SDAJN787DHH.zip\t181.215.97.223 162.222.177.155191.101.159.215208.113.128.118\tFirst submitted to VirusTotal 12 January 2017. Delivered via Bit.ly link. Additional IP addresses are commented out backups. - Xchecked via VT: 907466374f7ef3787e4b8f8232a9c52e",
"comment":"f893nuf9sdyfewnI98SDAJN787DHH.zip\t181.215.97.223 162.222.177.155191.101.159.215208.113.128.118\tFirst submitted to VirusTotal 12 January 2017. Delivered via Bit.ly link. Additional IP addresses are commented out backups. - Xchecked via VT: 907466374f7ef3787e4b8f8232a9c52e",
"comment":"fatura11.vbs\t191.101.230.149 162.222.177.155 191.101.230.149\tFirst submitted to VirusTotal 22 December 2016. Second and third IP address comment out as a backup. Delivered via Dropbox links and from 181.215.114.231. - Xchecked via VT: cdd5f47935a2a45afff20b222124177d",
"comment":"fatura11.vbs\t191.101.230.149 162.222.177.155 191.101.230.149\tFirst submitted to VirusTotal 22 December 2016. Second and third IP address comment out as a backup. Delivered via Dropbox links and from 181.215.114.231. - Xchecked via VT: cdd5f47935a2a45afff20b222124177d",
"comment":"fatura11.vbs\t191.101.230.149 162.222.177.155 191.101.230.149\tFirst submitted to VirusTotal 22 December 2016. Second and third IP address comment out as a backup. Delivered via Dropbox links and from 181.215.114.231. - Xchecked via VT: cdd5f47935a2a45afff20b222124177d",