The blog post about the Grandoreiro disruption operation is available on WeLiveSecurity at https://www.welivesecurity.com/en/eset-research/eset-takes-part-global-operation-disrupt-grandoreiro-banking-trojan/.
SHA-1 | Filename | Detection | Description |
---|---|---|---|
|
|
Win32/Spy.Grandoreiro.DB |
MSI downloader |
|
|
Win32/Spy.Grandoreiro.DB |
MSI downloader |
|
|
Win32/Spy.Grandoreiro.BM |
Grandoreiro |
|
|
Win32/Spy.Grandoreiro.BM |
Grandoreiro (with binary padding) |
IP | Domain | Hosting provider | First seen | Details |
---|---|---|---|---|
|
DGA-generated |
Azure |
2024-01-12 |
C&C server. |
|
DGA-generated |
Azure |
2024-01-16 |
C&C server. |
|
DGA-generated |
Azure |
2024-01-18 |
C&C server. |
|
DGA-generated |
OVH |
2024-01-02 |
C&C server. |
|
DGA-generated |
OVH |
2024-01-05 |
C&C server. |
|
DGA-generated |
OVH |
2024-01-09 |
C&C server. |
|
DGA-generated |
AWS |
2024-01-03 |
C&C server. |
|
DGA-generated |
AWS |
2024-01-09 |
C&C server. |
|
DGA-generated |
AWS |
2024-01-12 |
C&C server. |
|
DGA-generated |
VDSina |
2024-01-11 |
C&C server. |
|
DGA-generated |
Master da Web |
2024-01-02 |
C&C server. |
|
N/A |
VDSina |
2024-01-18 |
Distribution server. |
|
N/A |
Azure |
2024-01-10 |
Distribution server. |
The blog post about Grandoreiro "Grandoreiro: How engorged can an EXE get?" is available on WeLiveSecurity at https://www.welivesecurity.com/2020/04/28/grandoreiro-how-engorged-can-exe-get/.
SHA-1 | Description | ESET detection name |
---|---|---|
|
Old version of Grandoreiro (2017) |
Win32/Spy.Grandoreiro.A |
|
Grandoreiro |
Win32/Spy.Grandoreiro.AE |
|
Grandoreiro |
Win32/Spy.Grandoreiro.AJ |
SHA-1 | Description | ESET detection name |
---|---|---|
|
Grandoreiro downloader |
Win32/TrojanDownloader.Banload.YJR |
|
Grandoreiro downloader |
Win32/TrojanDownloader.Banload.YLZ |
|
Grandoreiro downloader |
Win32/TrojanDownloader.Banload.YJB |
|
Grandoreiro downloader |
Win32/TrojanDownloader.Banload.YMI |
-
%INSTALL_DIR%\
*-
MDL_YEL_01.dll
-
MDL_BLU_BR_02.dll
-
MDL_SIC_BR_03.dll
-
MDL_SANT_BR_04.dll
-
MDL_ITA_BR_05.dll
-
MDL_BRADA_BR_06.dll
-
MDL_SICCB_BR_07.dll
-
MDL_SAFRA_BR_08.dll
-
MDL_ORIGI_BR_09.dll
-
MDL_NORDES_BR_10.dll
-
MDL_BANEST_BR_11.dll
-
MDL_BANEZE_BR_12.dll
-
MDL_AMAZON_BR_13.dll
-
MDL_UNICRE_BR_14.dll
-
MDL_BRB_BR_15.dll
-
MDL_WUPDATE_BR_001.dll
-
%INSTALL_DIR%
is the path where Grandoreiro is installed
-