Warning: Panda Stealer malware is stealing your cryptocurrency
Panda Stealer was deployed through fake spam emails requesting business quotes to lure inadvertent victims to open malicious Excel files. According to Trend Micro, two infection sequences have been identified: a .XLSM attachment containing macros that download a loader.
Then the downloader and takes the stealing; The second chain of infection involves an attached .XLS file containing an Excel formula that uses a PowerShell command to access paste.ee, a workaround for Pastebin, that accesses an encrypted PowerShell command a second time.
The .XLSM attachment contains macros that download a downloader.
The attached .XLS file contains a malicious Excel formula.
PowerShell script is encrypted and decoded from paste.ee URL.
The malware is an affiliate of Collector Stealer, sold on some private forums and Telegram.
Once installed, Panda Stealer can collect detailed information and records of past transactions from victims' various virtual wallets. In addition, it can steal login information from apps like NordVPN, Telegram, Discord, Steam and others. Not stopping there, it has the ability to take screenshots of the infected computer and retrieve data from browsers such as cookies, passwords and tags.
Trend Micro has identified an IP address they believe hackers used to attack crypto wallets. The IP address assigned to a virtual server (VPS) leased from Shock Hosting. Immediately after being notified, Shock Hosting confirmed that the server assigned with this IP address was suspended.
To help keep your PC and data protected, you should install anti-virus software.
You should read it
- Giant pandas may originate from Europe
- Enhance Windows security with Panda Gold Protection
- Virus collection of 2010 from Panda Labs
- China warned about Panda virus
- Download Advanced Panda Dome, antivirus software for $ 21.12, free
- Infographic of Google's Panda penalties
- How to play Baby Panda: Take care of animals, game of BabyBus
- Panda achieved 5 Star certification from PC Magazine
May be interested
- How to protect your phone from SparkKitty photo-stealing malwareunfortunately, malware is getting smarter and is now targeting sensitive information stored as photos, like the latest sparkkitty malware on phones.
- Enhance Windows security with Panda Gold Protectionpanda gold protection is a computer security program against viruses, malware or spyware. besides, with low and weak computers, panda gold protection can still be used.
- Panda launched antivirus software through the Webon may 24, at the interop conference in las vegas, antivirus software maker panda software announced a new web-based product that could detect malware that traditional security programs can't be done.
- 'Rootkit + Trojan = Increased danger'security firm sana security is currently warning users of a new type of programmed malware aimed at stealing usernames and passwords.
- Virus collection of 2010 from Panda Labspanda labs, panda security's security lab closed this year with an overview of the most remarkable and special viruses that have appeared in the past 12 months. the list of viruses is very long and varied, from 2010 ...
- Panda Software's Top 10 Most Dangerous Malware 2005panda software has just released a list of the top 10 most dangerous malware tools in 2005 ranked by the company.
- Download Advanced Panda Dome, antivirus software for $ 21.12, freeadvanced panda dome, powerful anti-virus software helps users not worry about viruses, spyware, rootkits, hackers, ... with real-time protection against the latest malware, computer systems and your devices will always be safe.
- Pi price drops by more than half, cryptocurrency exchange CEO continues to warn of scamsben zhou, ceo of cryptocurrency exchange bybit, reposted a warning about pi network amid a sharp drop in the price of this cryptocurrency after its 'network launch'.
- Online anti-malware toolyou may need to use a utility that can detect, update and process malware automatically. all are available in the latest malware radar system provided by security vendor panda.
- Things to know about Gauss malwarelast thursday, kaspersky labs announced the discovery of a new malware called gauss, which specialized in stealing information about bank accounts, finance, and connections to malicious codes like stuxnet and flame.