A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #19646  by p4r4n0id
 Fri Jun 14, 2013 3:10 pm
Hi,

Old bankers ( ~5 years ago ) used to inject html code ( MITB ) if the browser's title text was one of their triggers. for example, if the user browse to citibank.com the browser title changes to "Citibank - Banking , Credit Cards..." which will trigger the injection.

Any chance u got a sample that uses this tech.? AFAIR, it was very common with Brazilian bankers......

Thx guys,

p4r4n0id
 #19679  by EP_X0FF
 Tue Jun 18, 2013 5:49 am
Hello,

without any hash I doubt someone can help you. This was too long time ago and if someone still have this, it is only in collections.
The only close description I can find it is http://www.microsoft.com/security/porta ... 2%2FScar.O, but sample is wasted.
https://www.virustotal.com/en/file/84be ... /analysis/