当前位置:首页 >英文主页 >中英对照 > 报告详情

2020年拉美金融网络犯罪:犯罪分子共享TTPS - ESET(英文版)(19页).pdf

上传人: Me****y 编号:21624 2020-10-26 19页 2.81MB

1、LATAM FINANCIAL CYBERCRIME: COMPETITORS-IN-CRIME SHARING TTPS ESET Research white papers Authors: Jakub Souek Martin Jirkal TLP: WHITE LATAM financial cybercrime: Competitors-in-crime sharing TTPs1 TLP: WHITE CONTENTS ABSTRACT 2 INTRODUCTION 2 IMPLEMENTATION 3 Core of a typical Latin American bankin

2、g trojans implementation 3 Implementation detail similarities 4 String encryption and obfuscation 4 Common enemy: Protection software 4 Binary obfuscation 5 DISTRIBUTION 5 Typical Latin American banking trojan distribution chains 5 Sharing the chains 6 The first link in the chain 6 Script obfuscatio

3、n 7 Targeted countries 7 EXECUTION 7 Method 1: Direct execution 8 Method 2: Using the AutoIt interpreter 8 Method 3: DLL side-loading 8 Method 4: DLL side-loading combined with injector 9 Legitimate applications being abused 9 FAKE POP-UP WINDOWS 10 MITTRE ATT both powerful binary obfuscation tools

4、Similarly, many of them globally switched their initial download method to using Windows Installer (MSI) over the period of just a few months Finally, some TTPs seem to stay strongly rooted deep inside the region These include heavily utilizing ZIP archives and using DLL side-loading as the favored

5、execution method Even though sharing knowledge between cybercriminals is not unusual, seeing so many examples of it in region-specific malware families with the same focus caught our attention Our presentation will cover all the common characteristics we have discovered and include a timeline illust

6、rating the evolution of these banking trojans We will draw conclusions about which families are most closely interlinked and how the modus operandi of Latin American banking trojans is different from banking trojans in the rest of the world INTRODUCTION Dominating crimeware in the region, Latin Amer

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要研究了拉丁美洲的金融网络犯罪,特别是银行木马。文章指出,尽管通常被视为一个家族,但至少有11个不同的恶意软件家族在拉丁美洲活跃。这些家族在实现、分发、执行和伪装等方面有显著的相似性,表明它们之间存在合作和知识共享。例如,它们大多使用Delphi编写,具有相似的核心功能,如注册、监控窗口标题和显示假冒的弹出窗口。在分发方面,它们通常使用多阶段下载链,包括使用ZIP存档和DLL侧加载等方法。在执行方面,它们倾向于使用合法应用程序来执行木马。这些家族还共享一些加密和混淆技术。文章还指出,这些木马正在向欧洲扩张,特别是西班牙和葡萄牙。总的来说,这些木马家族之间的紧密合作是前所未有的,表明它们之间存在某种形式的协调和合作。
拉丁美洲银行木马如何运作? 银行木马作者之间有何联系? 银行木马如何逃避安全软件?
客服
商务合作
小程序
服务号
折叠