Fobber
Description
(GovCERT.ch) In the original sample, there was no sign of Man-in-the-Browser (MitB) aiming to stealbanking credentials but, since the malware has the capability to update itself, this posibilitycan be later added by the attackers.On our analysis, apart from the update feature, we only found the form-grabbing / cookie-stealing malicious feature.
Names
Name |
---|
Fobber |
Category
Malware
Type
- Banking trojan
- Backdoor
- Credential stealer
Information
- https://www.govcert.admin.ch/downloads/whitepapers/govcertch_fobber_analysis.pdf
- https://www.govcert.ch/blog/analysing-a-new-ebanking-trojan-called-fobber/
- https://blog.malwarebytes.com/threat-analysis/2015/06/elusive-hanjuan-ek-caught-in-new-malvertising-campaign/
- http://blog.wizche.ch/fobber/malware/analysis/2015/08/10/fobber-encryption.html
- http://byte-atlas.blogspot.ch/2015/08/knowledge-fragment-unwrapping-fobber.html
- https://searchfinancialsecurity.techtarget.com/news/4500249201/Fobber-Drive-by-financial-malware-returns-with-new-tricks
Malpedia
Alienvault Otx
Other Information
Uuid
4b157100-22c4-4c04-83eb-245052a43b69
Last Card Change
2020-05-24