SAS2019 Presentation
ID: c4a4ab2b-75e0-4379-bd31-4b5374e8df6d
STIX ID: report--c4a4ab2b-75e0-4379-bd31-4b5374e8df6d
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2019-04-12
Last Modified Date: 2019-04-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
A detailed presentation on the Dreambot banking Trojan botnet, its Gozi-based features (webinjects, keylogging, form grabbing), the criminal business model, and the multi-layer C2 infrastructure (including DGA, Brazzers Fast Flux, and Tor) with extensive victim data, geographic distribution, and client activity, highlighting ongoing fraud campaigns and the operators behind Dreambot.
