Dreambot banking Trojan which is a variant of Ursnif spreading via resume themed email, it is one of the most active banking trojans.Its activity on infected computers is very hard to detect at the network level and it communicates over Tor and Peer-to-peer.
It used to specifically target for financial organizations such as corporate and bank sectors to steal the sensitive banking information from organization employees.
Also New Futures has been embedded with it including anti-sandbox Technique to avoid Detection .It targets victim’s by sending personalized emails with the following message text
Hello, Here is my resume. Please consider it as soon as possible. Happy New Year. Greg Pettegrew Email: wakaba@car.ocn.ne.jp
The Email consist of zip file Greg resume.zip and the extracted file is CV_pettegrew.jse which then downloads the Dreambot executable. that has been encoded with base64.
A .jse file extension used for Script written in JScript, a programming language used for Windows and Microsoft Internet Explorer scripting; contains source code in a format similar to JavaScript, but the JScript specification is maintained by Microsoft.
Once user click and the file it used to send request to C&C Server over onion network using port 80 then download an orignial payload to infect the windows based machine.
31.11.33.145 port 80 – www.i-tony.net
31.11.33.145 port 80 – www.i-tony.net
164.132.120.220 port 80 – 164.132.120.220
198.105.244.228 port 80 – wdwefwefwwfewdefewfwefw.onion
198.105.244.228 port 80 – wdwefwefwwfewdefewfwefw.onion
According to malwaretrafficanalysis report.
Dream bot communicates over Tor network, due to the nature of onion sites taking down the C&C servers is difficult.The primary goal of the trojan is to steal the financial details from your computer. It has a persistent nature and sits in the windows registry.
SHA256 hash: 12bf51f905667a25261b55b7dd9e9812e09673617d79d267af749073d43b2cc3 (Greg resume.zip)
SHA256 hash: 67fdeb838110c94957d475841c4ff3827db59e4c6ef628dc57e9199aeb543512 (CV-Pettegrew.jse)
SHA256 hash: 1fa7952beab93e9522021fa7ed2231605a573f3fa3f68f1d5e609673a4321138 (devmprov.exe)
Recommended blocking the following domains.
hxxp://www.i-tony.net/images/rn.php
hxxp://164.132.120.220/view/ra64.css
wdwefwefwwfewdefewfwefw.onion
North Korean nationals have successfully infiltrated the employee ranks of major global corporations at a…
Security researchers have uncovered a sophisticated malware campaign utilizing fake CAPTCHA verification screens to deploy…
Global cybersecurity landscape is undergoing a significant transformation, as state-sponsored hacktivism gains traction amid ongoing…
Researchers have uncovered significant security vulnerabilities in NVIDIA Riva, a breakthrough AI speech technology platform…
Security researchers have recently discovered a sophisticated malware operation called the "Tsunami-Framework" that combines credential…
Check Point Research's latest AI Security Report 2025 reveals a rapidly evolving cybersecurity landscape where…