ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta

Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites

mediumMalware exploited in the wildimportance 48
AI summary · glm-5.3

Fortinet details Casbaneiro banking Trojan campaign hitting Latin American bank customers via invoice-themed PDF phishing, with AutoIt loading, RegSvcs.exe injection, and bank-site-triggered activation.

Fortinet identified an August 2026 Casbaneiro banking Trojan campaign targeting users in Argentina, Peru, Colombia, and Mexico through phishing PDFs styled as urgent invoices or legal notices. The staged chain uses IP-based geo-filtering, a Base64-encoded ZIP, an HTA file, and a legitimate AutoIt interpreter before injecting into RegSvcs.exe or mobsync.exe and persisting via a Startup shortcut. The Trojan exfiltrates address book and Outlook data unencrypted, stays dormant until victims visit targeted bank sites, then accepts commands for keyboard control, clipboard pasting, file execution, and command execution. It uses an expected HTTP 403 response from a second server and malformed HTTP requests to complicate network analysis.

  • Phishing PDFs posing as invoices and legal notices target bank users in Argentina, Peru, Colombia, Mexico.
  • Geo-filtering redirects non-target IPs to Google or YouTube to evade researchers.
  • AutoIt loader injects into RegSvcs.exe/mobsync.exe and persists via Startup shortcut.
  • Activates only on targeted bank sites, enabling keyboard, clipboard, and command control.
  • Expected HTTP 403 responses and malformed requests complicate network analysis.

Indicators of compromiseAll →

TypeIndicatorContext
domain115.201.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[
domain116.181.62.50.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.
domain128.200.178.68.host.secureserver.neta0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.
domain129.202.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]
domain13.189.202.64.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.
domain135.201.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]
domain162.201.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[
domain181.202.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[
domain48.178.169.192.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[
domain76.180.62.50.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]co
domain85.182.62.50.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[
domaingexwalltool.com[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]c
domainx-wolverine.servebbs.comure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 C
sha2560849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a Malicious PDF lure Email SHA-256 debe871710268e7bb770b72c67
sha2560b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd
sha2561b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed4a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e
sha2561f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2eb
sha25640d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd64f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877
sha2564302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e691504489eb6b87bb0 2f0bd59d565 Phishing email artifact HTA SHA-256 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d119
sha2564540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be
sha25647d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5
sha25651503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c3b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba2
sha2565a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95ef537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1
sha2565b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 HTA downloader HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f
sha25662ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5badab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f
sha2566547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b09302b1b25b78e5f3707e81bad5054cf4e8 HTA downloader HTA SHA-256 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88
sha2566bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73compromise (IoCs):- Type Indicator Description PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40
sha2566e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4aff294f5250c2eed406765032cb68756 HTA downloader HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002f
sha256711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859ff91c829d87f566bee453d715280 Malicious PDF lure PDF SHA-256 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 Malicious PDF lure PDF SHA-256 d910e08a11a4f6f764e7495f4602
sha25671dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b7170018382cbc362343db63717d0ff02 HTA downloader HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secures
sha2567de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc85d7407ba AutoIt loader component Casbaneiro payload SHA-256 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 Casbaneiro payload Cryptocurrency address 0xb4c12078448fdef
sha2567e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e82abf7f72ef093292c86c1e9e7c2be456 HTA downloader HTA SHA-256 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 HTA downloader HTA SHA-256 6547736c31dabb5bef2a290b32a72bf6
sha2568092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 HTA downloader HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a
sha25685767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f50c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f HTA downloader HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775
sha256875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b395403d6a3df9d8da179f3cd5faf81b1 HTA downloader HTA SHA-256 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541
sha25692a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9cadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c HTA downloader HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099ce
sha256943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d7152809f4a7d6ac2e0385472298f384fc8 Malicious PDF lure PDF SHA-256 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 Malicious PDF lure PDF SHA-256 711c0aa8cde078aa349fb329e3e4
sha25699fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1c00dae6812c03bba019edf9c059ece33 HTA downloader HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 HTA downloader HTA SHA-256 875e8d4137e1016b4be869e36e00a941
sha256a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456761071655fa585b64eed3bd78fc28e01 HTA downloader HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 HTA downloader HTA SHA-256 7e04e86c07213fed7bebccd9953818b1
sha256bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e014e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 HTA downloader HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee41356
sha256bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc896feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure PDF SHA-256 943d63ace373ee50d074daf84d35
sha256c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756485688b5958d82fcb072a837e27e246b HTA downloader HTA SHA-256 c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 HTA downloader HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9
sha256c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77efae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f8
sha256d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure PDF SHA-256 d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca
sha256d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d851a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure PDF SHA-256 d04f68079ca90c65223a907f23fa
sha256d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b88157436566a5e651ad8a64893c76a725c859 Malicious PDF lure PDF SHA-256 d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadb
sha256e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add3d7e90e38a0e38083181f8c3312adc9c HTA downloader HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207
sha256ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15
sha256f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b8857308b3a1185e6f4ebc4164db8584f HTA downloader HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b HTA downloader HTA SHA-256 c477bdfae91e3df9be29e9eeba785467
sha256f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407bab07b25cc7d910 AutoIt loader component AutoIt script SHA-256 f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba AutoIt loader component Casbaneiro payload SHA-256 7de63753
sha256fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d91099[.]188[.]28 Campaign infrastructure AutoIt script SHA-256 fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 AutoIt loader component AutoIt script SHA-256 f76d09cbd455c
Full article1,081 words · extracted from cybersecuritynews.com · click to collapse

Casbaneiro is targeting online banking users in Latin America through phishing messages that look like urgent invoices or legal notices.

The campaign uses personalised PDF lures to push recipients toward a malicious download chain, putting email data, banking activity and system details at risk.

The Windows-focused operation is designed to stay quiet until it matters most. After gaining a foothold, it waits for a victim to browse a targeted bank site, then contacts its command infrastructure and can begin actions intended to support fraud.

Fortinet researchers identified the activity in August 2026 and tracked victims in Argentina, Peru, Colombia and Mexico. The findings show how regional filtering, staged downloads and timed network traffic can make a banking Trojan harder to spot in routine security reviews.

Fortinet said in a report shared with Cyber Security News (CSN) that the campaign sends stolen information to separate servers and uses a deliberately expected HTTP 403 response to confuse analysis.

The approach creates a risk beyond one compromised account, because harvested contacts and email details can support later attacks.

Hackers Deploy Casbaneiro Banking Trojan

The attack begins with an email and PDF that creates urgency around an invoice or supposed legal proceeding. The documents may display the recipient’s email address, a simple trick that adds credibility.

Similar deception appears in reports on weaponized PDF threats, where a familiar document becomes the first step toward malware delivery.

Attack flow (Source - Fortinet)
Attack flow (Source – Fortinet)

A link first checks the visitor’s IP address. Visitors outside the selected countries are redirected to legitimate sites such as Google or YouTube, while targets are served a page that silently downloads a Base64-encoded ZIP archive.

That location check limits exposure and reduces the chance that researchers will receive the same malicious content.

Inside the archive, an HTA file fetches further script content and checks the device for analysis environments and approved operating-system languages.

If the system passes, it downloads a legitimate AutoIt interpreter, a compiled script and a compressed component separately. This staged approach resembles the delivery patterns described in AutoIt loader abuse, which can help malware hide its combined purpose.

The loader shows a fake Windows service window, extracts the final program and injects it into RegSvcs.exe or, when unavailable, mobsync.exe.

It also creates a Startup shortcut for persistence. These steps can leave an infected user unaware that the visible service prompt is a decoy rather than a system task.

Data Theft and Evasion

Once active, Casbaneiro decrypts its configuration, collects address-book entries and Outlook sender and recipient details, and transmits the information without encryption.

It builds an identifier from the computer name, user name and executable name, then uses a hash of that value to track activity and avoid repeating some actions.

Phishing PDF files (Source - Fortinet)
Phishing PDF files (Source – Fortinet)

The Trojan does not immediately use its main command channel. It waits until the victim visits one of the targeted bank websites, then sends system information and accepts commands for keyboard control, clipboard pasting, file execution and command execution.

Its fake-window functions can also target specified banks, increasing the danger during an active online banking session.

A second server returns HTTP 403 when it receives Base64-encoded victim data. Rather than signalling failure, that response is part of the process; any other status makes the malware retry.

The campaign also sends different information to different servers and uses malformed HTTP requests, complicating network investigations. Its bank-triggered behaviour echoes Ousaban banking malware activity, another campaign that waits for victims to open selected banking sites.

Organisations should treat unexpected invoice and legal-notice PDFs as suspicious, verify requests through a separate channel and block execution of downloaded HTA files where possible.

Security teams should monitor for unusual AutoIt use, Startup-folder shortcuts, browser-triggered outbound traffic and failed-looking 403 communications.

Employee training and prompt reporting remain important, particularly for messages designed to create urgency. Readers can review banking Trojan campaign tactics to recognise related warning signs.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
PDF SHA-2566bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73Malicious PDF lure
PDF SHA-25640d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1ddMalicious PDF lure
PDF SHA-256bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8Malicious PDF lure
PDF SHA-256943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280Malicious PDF lure
PDF SHA-256711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859Malicious PDF lure
PDF SHA-256d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365Malicious PDF lure
PDF SHA-25647d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95Malicious PDF lure
PDF SHA-256d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85Malicious PDF lure
PDF SHA-256d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2cMalicious PDF lure
PDF SHA-2561b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8edMalicious PDF lure
PDF SHA-25662ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5Malicious PDF lure
PDF SHA-2561f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491Malicious PDF lure
PDF SHA-256ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3Malicious PDF lure
PDF SHA-2560b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5Malicious PDF lure
PDF SHA-256c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77eMalicious PDF lure
PDF SHA-2560849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735aMalicious PDF lure
Email SHA-256debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556ea ba2d71057Phishing email artifact
Email SHA-256eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6 057244390Phishing email artifact
Email SHA-256995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5 e861fac457Phishing email artifact
Email SHA-256918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d04 3d08844f62Phishing email artifact
Email SHA-256be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06c a0f3c056Phishing email artifact
Email SHA-256dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb0 2f0bd59d565Phishing email artifact
HTA SHA-2564302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044HTA downloader
HTA SHA-25685767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584fHTA downloader
HTA SHA-256f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246bHTA downloader
HTA SHA-256c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756HTA downloader
HTA SHA-2566e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4HTA downloader
HTA SHA-2564540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697HTA downloader
HTA SHA-25692a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9cHTA downloader
HTA SHA-256e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65addHTA downloader
HTA SHA-2565a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95eHTA downloader
HTA SHA-2568092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33HTA downloader
HTA SHA-25699fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1HTA downloader
HTA SHA-256875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8bHTA downloader
HTA SHA-256bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01HTA downloader
HTA SHA-256a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456HTA downloader
HTA SHA-2567e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8HTA downloader
HTA SHA-2566547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093HTA downloader
HTA SHA-25651503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64cHTA downloader
HTA SHA-2565b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02HTA downloader
HTA SHA-25671dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52bHTA downloader
Domain128[.]200[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain13[.]189[.]202[.]64[.]host[.]secureserver[.]netCampaign infrastructure
Domain116[.]181[.]62[.]50[.]host[.]secureserver[.]netCampaign infrastructure
Domain48[.]178[.]169[.]192[.]host[.]secureserver[.]netCampaign infrastructure
Domain115[.]201[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain181[.]202[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain135[.]201[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain85[.]182[.]62[.]50[.]host[.]secureserver[.]netCampaign infrastructure
Domain162[.]201[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain129[.]202[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain76[.]180[.]62[.]50[.]host[.]secureserver[.]netCampaign infrastructure
Domaingexwalltool[.]comCampaign infrastructure
Domainx-wolverine[.]servebbs[.]comCampaign infrastructure
IP address72[.]167[.]48[.]63Campaign infrastructure
IP address209[.]99[.]188[.]28Campaign infrastructure
AutoIt script SHA-256fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910AutoIt loader component
AutoIt script SHA-256f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407baAutoIt loader component
Casbaneiro payload SHA-2567de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8Casbaneiro payload
Cryptocurrency address0xb4c12078448fdef1f8881a55aab5c81fa194095cEmbedded cryptocurrency address
Cryptocurrency addressbc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6Embedded cryptocurrency address

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/casbaneiro-banking-trojan/