http://{BLOCKED}mmj.com/cfg.bin
Data de publicação: 10 setembro 2013
Data/Hora do bloqueio de URL: quarta-feira, 4 de setembro de 2013 11:01:00 GMT-8
Classificação: : Alto
Domínio: : ocsxxxmmj.com
Categoria : Disease Vector
Descrição:
TSPY_ZBOT.THX connects to this URL to download its configuration file. This is the Trend Micro detection for KINS Trojan, dubbed as the next ZeuS by media reports. Similar to ZeuS/ZBOT, it downloads configuration file and steals online banking credentials. However, it uses a different packer and has anti-debugging and anti-analysis routines.