Analysis of Latin American Bot (Vadokrist) : Part I - Mechanism & Dropper
EXECUTIVE SUMMARY
Vadokrist Trojan aims to steal credentials from victims’ machines and to create banking overlay windows when the victim visits their home banking portals. Here is the list of known Latin American banking Trojans
• Grandoreiro
• URSA
• Javali
• Vadokrist (aka) Mispadu
DISTRIBUTION
Vadokrist is propagated via social engineering schemas – namely, phishing/malscam campaigns
TECHNICAL ANALYSIS
Abusing MSI (Windows Installer) was one of the growing threat in cyber industry. In this sample the msi file acts as a dropper for VadoKrist Trojan
Here we can see the obfuscated JS code Binded into Windows Installer (MSI) which drop a zip file and extracts Vadokrist Trojan
Here is the Full obfuscated code of the dropper