The blog post about Numando "Numando: Count once, code twice" is available on WeLiveSecurity at https://www.welivesecurity.com/2021/09/17/numando-latam-banking-trojan/.
SHA-1 | Description | ESET detection name |
---|---|---|
|
MSI downloader for "decoy ZIP" |
Win32/TrojanDownloader.Delf.CQR |
|
MSI installer |
Win32/Spy.Numando.BA |
|
Numando banking trojan |
Win32/Spy.Numando.E |
|
Numando banking trojan |
Win32/Spy.Numando.AL |
|
Numando banking trojan |
Win32/Spy.Numando.AO |
|
DLL with overlay window images |
Win32/Spy.Numando.P |
-
https://enjoyds.s3.us-east-2.amazonaws[.]com/H97FJNGD86R.zip
-
https://lksluthe.s3.us-east-2.amazonaws[.]com/B876DRFKEED.zip
-
https://procjdcals.s3.us-east-2.amazonaws[.]com/HN97YTYDFH.zip
-
https://rmber.s3.ap-southeast-2.amazonaws[.]com/B97TDKHJBS.zip
-
https://sucessmaker.s3.us-east-2.amazonaws[.]com/JKGHFD9807Y.zip
-
https://trbnjust.s3.us-east-2.amazonaws[.]com/B97T908ENLK.zip
-
https://webstrage.s3.us-east-2.amazonaws[.]com/G497TG7UDF.zip
Those IoCs are an annex to the session "LATAM financial cybercrime: competitors in crime sharing TTPs" to be presented at VB2020.
SHA-1 | Description | ESET detection name |
---|---|---|
|
Numando banking trojan |
Win32/Spy.Numando.L |
|
Numando banking trojan |
Win32/Spy.Numando.AN |
|
Numando banking trojan (protected by Themida) |
Win32/Spy.Numando.AO |
|
Numando banking trojan |
Win32/Spy.Numando.L |
SHA-1 | Description | ESET detection name |
---|---|---|
|
Numando downloader (MSI) |
Win32/Spy.Numando.L |
|
Numando downloader (MSI) |
Win32/Spy.Numando.AN |
|
Numando downloader (MSI) |
Win32/Spy.Numando.AO |
|
Numando downloader (MSI) |
Win32/TrojanDownloader.Agent.EQL |