SYMBOLCOMMON_NAMEaka. SYNONYMS
win.zacinlo (Back to overview)

Zacinlo

aka: s5mark

Bitdefender describes the primary features of the family as follows: Presence of a rootkit driver that protects itself as well as its other components, presence of man-in-the-browser capabilities that intercepts and decrypts SSL communications, and presence of an adware cleanup routine used to remove potential competition in the adware space. It also communicates with its C&C server, sending environment information such as installed AV and other applications. The malware also takes screenshots and does browser redirects, potentially manipulating the DOM tree. It also creates traffic in hidden windows, likely causing adfraud. The malware is generally very configurable and internally makes use of Lua scripts.

References
2018-06-18BitdefenderAndrei Ardelean, Claudiu Cobliș, Cornel Punga, Cristian Istrate
Six Years and Counting: Inside the Complex Zacinlo Ad Fraud Operation
Zacinlo

There is no Yara-Signature yet.