logo

SAS2019 Presentation

ID: c4a4ab2b-75e0-4379-bd31-4b5374e8df6d

STIX ID: report--c4a4ab2b-75e0-4379-bd31-4b5374e8df6d

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2019-04-12

Last Modified Date: 2019-04-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
A detailed presentation on the Dreambot banking Trojan botnet, its Gozi-based features (webinjects, keylogging, form grabbing), the criminal business model, and the multi-layer C2 infrastructure (including DGA, Brazzers Fast Flux, and Tor) with extensive victim data, geographic distribution, and client activity, highlighting ongoing fraud campaigns and the operators behind Dreambot.