Source |
Fortinet |
Identifiant |
366236 |
Date de publication |
2017-05-17 18:24:02 (vue: 2017-05-17 18:24:02) |
Titre |
New Loki Variant Being Spread via PDF File |
Texte |
The Loki Bot has been observed for years. As you may know, it is designed to steal credentials from installed software on a victim's machine, such as email clients, browsers, FTP clients, file management clients, and so on. FortiGuard Labs recently captured a PDF sample that is used to spread a new Loki variant. In this blog, we will analyze how this new variant works and what it steals.
The PDF sample
Figure 1. Content of the PDF sample
The PDF sample only contains one page, shown above, which includes some... |
Notes |
|
Envoyé |
Oui |
Condensat |
above analyze been being blog bot browsers captured clients contains content credentials designed email figure file fortiguard from ftp has how includes installed know labs loki machine management may new observed one only page pdf recently sample shown software some spread steal steals such used variant victim what which will works years |
Tags |
|
Stories |
|
Move |
|